Security

Security posture for offline-first payroll execution.

DocSmith prioritizes local processing boundaries, minimal external interactions, and predictable operational controls.

Core security boundary

  • Payroll row processing remains in local browser context by default.
  • Hosted interactions focus on licensing and payment workflows only.
  • No default cloud payroll-row storage in the normal product path.

Threat model flow

Local endpoint

User device, browser profile, and local file handling controls.

DocSmith runtime

Validation and SIF generation workflow executed in local context.

Licensing boundary

Only entitlement and payment metadata leave the device when required.

Operational trust controls

  • Validation tiers expose issues before submission and reduce hidden defects.
  • Controlled templates reduce structural data drift.
  • Support workflows enforce evidence-based issue handling.

Related resources