Security
Version 2.0 Effective 10 October 2026
Scope
RenderCheck and the free image-to-text tool are in beta. This page lists what is in place today. It does not claim any certification, such as SOC 2 or ISO 27001.
How images are handled
Text recognition runs in your browser, using Tesseract.js and WebAssembly. The recognition engine and the English language data are served from this site's own address, under /ocr/, and not from a third party.
An automated test in the project repository runs recognition on a sample image. It fails if the browser makes any request to another address, or any request other than a plain page or file download, while recognition runs.
Architecture
Two surfaces share one rule: an image is read on the machine that holds it. The full write-up, with a table linking each claim to its test, is in docs/ARCHITECTURE.md.
connect-src 'self') is what blocks requests to other servers. Source: docs/ARCHITECTURE.md.- React app: src/core/ocr/engineClient.ts
- OCR Web Worker: src/core/ocr/engine.worker.ts
- Network proof: src/core/privacy/networkProof.ts
- toShowText matcher: packages/rendercheck/src/playwright/matcher.ts
- verifyText: packages/rendercheck/src/core/verify.ts
- Failure report: packages/rendercheck/src/core/failures.ts
Verify it yourself
- Open the image-to-text tool and open your browser's developer tools on the Network tab.
- Choose an image. The tool shows a live count of requests and bytes sent while it reads the image.
- In the Network tab, check that no request carries your image. Only the page's own files load.
The count in the tool only covers the page itself. The Content Security Policy below is what stops the recognition worker from reaching any other address.
Security headers
The site sets these response headers (see vercel.json in the repository):
- A Content Security Policy that limits scripts, workers, images and network connections to this site.
- Strict-Transport-Security, so browsers use HTTPS.
- X-Frame-Options: DENY, so other sites cannot embed these pages.
- X-Content-Type-Options: nosniff.
- A Permissions-Policy that turns off camera, microphone and location access.
Third-party requests
There are none. Fonts, scripts and the OCR engine are served from this site, and the Content-Security-Policy blocks requests to any other origin.
Reporting a vulnerability
Please email rajasekaran.parthiban7@gmail.com with the steps to reproduce the problem. Please do not open a public issue for a security problem.