Security
Duct’s first security measure is its design: your documents are read and searched where they already are, so there is nothing of yours on our servers to lose.
Last updated: 8 October 2026
Local by default
- Indexing, search, OCR and the document viewer run on your own computer or server, with no internet connection needed.
- API keys you enter for AI providers are encrypted with your system’s keychain in the desktop app, and kept only in memory on a server. They are never written to disk in plain text.
- A Duct server only answers on your own machine unless you give it an access token. It rejects requests from other websites (DNS rebinding and cross-site requests) and sends a strict Content Security Policy.
- Duct is open source, so anyone can review exactly what it does, including what it sends and when.
Accounts
- Sign-in uses one-time codes sent by email, OAuth 2.0 with PKCE and your system browser. Duct never sees a password, because there isn’t one.
- Sign-in codes are stored only as keyed hashes for 10 minutes, and lock after five wrong attempts.
- Refresh tokens are stored only as hashes and change every time they are used. If an old one is reused, the device is signed out at once.
- Your plan is confirmed by a token signed with Ed25519, which Duct checks offline. A tampered token is rejected.
- Account and usage-count data are kept in separate databases, and IP addresses are never stored.
Developer API
- API keys are shown once and stored only as hashes. Each key has scopes (search, write, admin), can be limited to some collections, and is rate limited.
- Each collection is a separate index, so one tenant’s documents can’t appear in another’s results.
Report a vulnerability
If you believe you’ve found a security problem in Duct or Tensflare’s services, please email security@tensflare.com with the details and steps to reproduce it. We will:
- acknowledge your report within three working days;
- keep you informed while we fix it;
- credit you, if you’d like, once it’s fixed.
Please give us reasonable time to fix the problem before disclosing it. Don’t access or change other people’s data, and don’t degrade the services. We won’t take legal action against good-faith research that follows these guidelines.