Skip to content
ductby Tensflare
Features
Use cases
Team knowledge baseEvery company document, one search away. LegalThe clause, the precedent and the page. Finance and auditThe evidence behind every number. Research and academiaThe paper, the page and the quote. Public recordsScanned records, searchable inside your walls. NGOs and developmentKeep knowledge when people move on. Bids and proposalsYour best past answers, ready. DevelopersSearch for your app, documents included.
Developers Pricing Blog Docs GitHub Download

Legal

Security

Duct’s first security measure is its design: your documents are read and searched where they already are, so there is nothing of yours on our servers to lose.

Last updated: 8 October 2026

Local by default

  • Indexing, search, OCR and the document viewer run on your own computer or server, with no internet connection needed.
  • API keys you enter for AI providers are encrypted with your system’s keychain in the desktop app, and kept only in memory on a server. They are never written to disk in plain text.
  • A Duct server only answers on your own machine unless you give it an access token. It rejects requests from other websites (DNS rebinding and cross-site requests) and sends a strict Content Security Policy.
  • Duct is open source, so anyone can review exactly what it does, including what it sends and when.

Accounts

  • Sign-in uses one-time codes sent by email, OAuth 2.0 with PKCE and your system browser. Duct never sees a password, because there isn’t one.
  • Sign-in codes are stored only as keyed hashes for 10 minutes, and lock after five wrong attempts.
  • Refresh tokens are stored only as hashes and change every time they are used. If an old one is reused, the device is signed out at once.
  • Your plan is confirmed by a token signed with Ed25519, which Duct checks offline. A tampered token is rejected.
  • Account and usage-count data are kept in separate databases, and IP addresses are never stored.

Developer API

  • API keys are shown once and stored only as hashes. Each key has scopes (search, write, admin), can be limited to some collections, and is rate limited.
  • Each collection is a separate index, so one tenant’s documents can’t appear in another’s results.

Report a vulnerability

If you believe you’ve found a security problem in Duct or Tensflare’s services, please email security@tensflare.com with the details and steps to reproduce it. We will:

  • acknowledge your report within three working days;
  • keep you informed while we fix it;
  • credit you, if you’d like, once it’s fixed.

Please give us reasonable time to fix the problem before disclosing it. Don’t access or change other people’s data, and don’t degrade the services. We won’t take legal action against good-faith research that follows these guidelines.

ductby Tensflare

Search you can verify. Open source, private by design, and built to work offline.

Product

FeaturesDownloadPricingDevelopersDocumentationWhat Duct sends

Use cases

Team knowledge baseLegalFinance and auditResearch and academiaPublic recordsNGOs and developmentBids and proposalsDevelopers

Company

AboutBlogPress kitTensflareContactGitHub

Legal

PrivacyTermsRefundsCookiesSecurityWhat Duct sends
© 2026 Tensflare Ltd. The Duct app is open source under the Apache 2.0 licence; team server features are source-available under the Elastic License 2.0.