Option A — Zero-Egress Render
Confidential content never leaves your network — and never touches any AI model.
The promise
Your analysts author the content. DocMark — running entirely on a box inside your network — renders it into a branded, client-ready deliverable and verifies it locally. No AI, no cloud, no internet anywhere in the pipeline. That is not a configuration choice that someone could flip; it is how this tier is built, and it is verified at installation on your box.
How it works
- An analyst drops a content file into a shared intake folder — that’s the whole integration.
- The DocMark box (a managed appliance) picks it up and renders it in a no-network sandbox, applying your committed brand specification and logos.
- The local visual-QA gate renders every page and pixel-checks it.
- Pass: a verified branded deliverable appears in the results folder, carrying its
zero-egresslabel and a brand-provenance record. Fail: a plain-language reason appears in the failed folder instead — the deliverable is withheld.
Who it’s for
Legal teams, valuation and M&A groups, and anyone whose content is client-confidential enough that “we have a DPA” is not an acceptable answer. If your security review starts with “nothing may leave the building,” this is your tier.
Proof, not promises
- End-to-end verification runs offline — disconnect the box and it still works.
- At handover, our installation checklist runs on your machine, with your team watching.
- Every artifact carries a machine-written egress-class label; the
zero-egressclaim is enforced by the pipeline, not by policy documents.