Mode 1 — On-prem
DocMark runs on your own hardware, inside your own network. As we install and hand it over, it runs no AI: your analysts write the content, and DocMark renders, brands and checks it on the box without sending it anywhere. Once installed, it needs no internet connection.
The promise
Your analysts author the content. DocMark — running entirely on your own hardware, inside your own network — renders it into a branded, client-ready deliverable and verifies it locally. As we install and hand it over, there is no AI, no cloud and no internet anywhere in the pipeline, and once installed the box needs no internet connection. At handover, our installation checklist runs on your box and shows a deck rendering with no AI or cloud credentials present and the render step cut off from the network.
In this mode, zero-egress means exactly that: DocMark sends nothing off the box — no model call, no DocMark telemetry. Keeping the box off the internet is your network’s control. (DocMark’s managed cloud uses the phrase differently — there it means no PII reaches the execution plane. Both are real; they are not the same thing. See the comparison.)
How it works
- An analyst drops a content file into a shared intake folder — that’s the whole integration.
- The DocMark box (a managed appliance on your hardware) picks it up and renders it, applying your committed brand specification and logos. When the render sandbox is on, the render step runs in a container with no network access; the sandbox is an operator setting on the box, so ask for it to be confirmed at handover.
- The local verification gate checks it: the deck itself is read first, and any slide carrying nothing a reader could see withholds it; then it is rendered slide by slide and checked for blank slides and low-contrast text; documents and workbooks get structural checks (deeper visual checks are on the roadmap). The deck gate is on by default on the box; an operator can turn it off, but that takes a second, deliberate override as well — named in your handover documentation, so ask for its state to be confirmed at handover (what it checks, and its limits).
- Pass: a verified branded deliverable appears in the results folder, carrying its
zero-egresslabel and a brand-provenance record. Fail: a plain-language reason appears in the failed folder instead — the deliverable is withheld.
Who it’s for
Legal teams, valuation and M&A groups, and anyone whose content is client-confidential enough that “we have a DPA” is not an acceptable answer. If your security review starts with “nothing may leave the building,” this is your mode.
Proof, not promises
- End-to-end verification runs offline — disconnect the box and it still works.
- At handover, our installation checklist runs on your machine, with your team watching.
- Every deck from the watched folder carries a machine-written egress-class label, written by the pipeline
from the engine that ran the job; the pipeline never labels a deck from an AI engine
zero-egress. Keeping the box off the internet is your network’s control; DocMark’s render path needs no network to work.