Skip to main content

How Your Files Stay On Your Device

"Your files never leave your browser" is a strong claim to make to someone with malpractice exposure. This page explains exactly how it works — and shows you how to verify it yourself instead of taking our word for it.

Key facts at a glance
  • All PDF processing in ExhibitPrep runs client-side in the browser using the open-source pdf-lib and pdf.js libraries; documents are never uploaded.
  • ExhibitPrep servers handle exactly two things: Stripe payment processing and license key validation — requests that contain no document data.
  • The no-upload claim is verifiable by any user: open the browser DevTools Network tab while stamping and observe that no request carries file content.
  • Stamped files download directly from browser memory to your computer; ExhibitPrep has no copy to retain, breach, or subpoena.
  • Payments are processed by Stripe; ExhibitPrep never sees or stores credit card numbers.
  • Because processing is local, ExhibitPrep works on confidential, sealed, and HIPAA-sensitive documents without a Business Associate Agreement — the documents never reach a third party.

What happens when you stamp a document

1. Your file opens in your browser's memory

When you select a PDF, your browser reads it from your disk into its own memory. There is no upload step — the "upload" button is a file picker, not a file transmitter.

2. Stamps are applied locally with open-source libraries

Stamping, combining, slipsheets, and tables of contents are generated by pdf-lib and Mozilla's pdf.js — the same auditable open-source libraries used across the industry — running entirely on your machine.

3. The only server traffic is payment and licensing

When you pay, your browser talks to Stripe (card processing) and to our license server (to validate your license key). Those requests carry payment metadata and a license identifier — never document bytes, file names, or case information from your exhibits.

4. Downloads come from your own memory

Your stamped files are assembled in browser memory and saved straight to your computer. We never have a copy — which means there is nothing on our side to breach, retain, or subpoena.

Don't trust us — verify it in 30 seconds

Every modern browser ships with a network inspector that shows every byte your browser sends. Use it to audit us:

  1. 1Open the stamping tool and press F12 (or Cmd+Option+I on Mac), then click the Network tab.
  2. 2Add your PDFs, apply stamps, preview, and download — a full working session.
  3. 3Watch the request list: you will see the app's own code and assets load, and (if you pay) calls to stripe.com and our license endpoint. What you will never see is a request transmitting your document — no multi-megabyte POST, no file payloads.

Tip: sort by request size. Your 5 MB exhibit can't secretly leave your machine without showing up as 5 MB of outbound traffic.

What this means for confidential matters

  • Sealed filings, discovery under protective order, and privileged documents never touch a third-party server.
  • Medical records and HIPAA-sensitive exhibits are processed without any disclosure to us — there is no vendor to sign a BAA with because no PHI is transmitted.
  • Closing your browser tab destroys the working copies in memory. Nothing persists on our side, because nothing ever arrived on our side.

For the formal details, see our Privacy Policy. Firm-wide security questionnaires and vendor diligence: contact us and a human will answer.

See it for yourself

Open the tool with your Network tab open. Free to preview — pay only when you download.

Start stamping