Production Package Doctor / Data boundary

Privacy & Security

Case-content processing and authorization traffic are described separately, in specific terms.

The product is local and read-only. That does not mean the workstation is entirely offline.

Two different data paths

Case contents stay here. Authorization remains limited.

Keeping these paths separate prevents “local processing” from being misread as an absolute no-network claim.

Local case-content path

Selected package contents and reports

The desktop application does not upload DAT, OPT, image, text, native, report, or derived case content.

  • Processing occurs on the operator’s Windows computer.
  • Reports remain in an operator-selected local folder.
  • Source-package contents are not sent to a browser or remote processing service.

Limited network path

Authorization and opaque Pilot state

Limited authorization, lease refresh, device lifecycle, and opaque Pilot accounting data may be exchanged.

  • No DAT, OPT, image, text, native, report, or derived case content is part of that path.
  • Seven-day offline access is a cached authorization refresh window.
  • The refresh window is separate from the 30-day Pilot duration.

Source handling

Read the package. Write the evidence elsewhere.

Production Package Doctor reads the selected source package and writes reports to a separate operator-selected location; it does not repair or rewrite the source package.

Review the full public evidence

Security claims should be inspectable.

Open the public privacy guide, interface captures, sample reports, manifest, and checksums before discussing Pilot access.