Skip to main content
Orilami

Security Architecture

How Orilami is built to keep your files private: a local execution model, a zero-log architecture, and client-side verification you can check yourself.

Orilami's privacy isn't a policy you have to trust — it's an architecture you can verify. Every tool is designed so your files are processed on your own device and never uploaded. This page explains the three pillars that make that true.

Local Execution Model

All file processing happens in your browser, on your machine. When you open a tool and load a file, the bytes are read into memory locally and never sent to a server.

  • Heavy work runs in Web Workers so your file is handled off the main thread and the page stays responsive.
  • Documents, images, audio and video are read, rewritten and re-encoded entirely client-side.
  • Because there is no upload, there is no server-side copy to store, cache, log, or leak.

The strongest privacy guarantee is not "we delete your data" — it's "we never receive it."

Zero-Log Architecture

We can't log what we never see. Since your files are never transmitted, there are no file contents, no filenames, and no derived data sitting in server logs or analytics.

  • Your documents and images are not part of any request to our servers.
  • Account features (sign-in and your token balance) are the only things that talk to a backend, and they never carry the files you process.
  • Nothing about the content of your work is recorded on our side.

Client-Side Verification

You don't have to take any of this on faith. Because everything happens in the browser, you can confirm it yourself:

Verifiability is the point. A promise you can check is worth more than one you can't.

How it's built, honestly

We'd rather tell you exactly how the tools work than hide behind buzzwords:

  • Plain client-side JavaScript and Web Workers. The processing runs as JavaScript in your browser, with the heavy work moved into Web Workers. We don't claim exotic technology we don't use.
  • A strict content security policy. The site tells your browser which servers it is allowed to talk to. This limits where any data could go, and you can read the policy in the response headers yourself.
  • The paywall is honest about what it can do. When a tool costs tokens, the charge is checked on our server by deducting from your balance — not by trying to lock the file inside your browser. A file your browser can open is a file you can save, and we won't pretend otherwise. What you pay for is the processing, not a lock we can't really enforce.

Where accounts fit in

Orilami has optional accounts for your token balance so it follows you across devices. Signing in and topping up communicate with a backend — but your files never do. The two are kept strictly separate: the tools work the same whether or not you're signed in, and processing always stays on your device.

To be concrete about what does leave your device when you use an account:

  • Only your sign-in and token balance. Accounts run on a managed database provider (Supabase). The backend stores your email and your token count — nothing about the files you process.
  • The files never travel with it. Loading a file, processing it, and downloading the result are entirely separate from any account request. One does not touch the other.
  • You can use the tools signed out. Accounts exist for billing and syncing your balance, not for the tools to work.

Who this matters for

Keeping files on your own device isn't a nice-to-have for everyone — for some work it's a duty:

  • Lawyers and notaries handling case files, contracts and client records under confidentiality rules.
  • Doctors and clinics working with patient documents and photos they can't upload to a random service.
  • Accountants and finance teams with statements, tax files and account numbers.
  • Journalists and their sources who can't risk a sensitive document touching a third-party server.
  • HR and recruiters processing resumes, IDs and personal data for many people.
  • Government and legal filing where ID photos and documents must stay private while being prepared.

For all of them, "the file never left my device" isn't marketing — it's the reason the tool is safe to use at all.

Want to see it in action? Start with the Metadata & EXIF Privacy Scrubber or the Auto-Redaction tool, or browse all tools.