Case study — secure document vault

The document stays protected.
The work keeps moving.

A secure, auditable vault for sensitive documents — designed to turn protected evidence into the minimum operational signal an authorised team needs to act.

Independent document systemEncrypted evidenceControlled processingAudit trail

01 — The requirement

Sensitive documents cannot be ordinary uploads.

The brief was to build an independent system for receiving and managing highly sensitive documents. The existing workflow could move information, but it could not provide the control, privacy, or accountability this kind of material requires.

  • Control Sensitive material stays inside a bounded system.
  • Privacy Raw document contents do not spread through operations.
  • Accountability Every handling action can be traced.
Four engineering principles

How the vault keeps sensitive documents protected.

01

Audit every sensitive action.

Every interaction with sensitive material becomes an attributable, auditable event.

02

Confirm before you commit.

A request is confirmed before commit, leaving a durable handling record.

03

Encrypt at rest and in transit.

Each stored record has a distinct key, and every transfer stays encrypted.

04

Process inside the boundary.

OCR and QR detection run in controlled infrastructure; outputs and logs stay inside.

03 — The protected lifecycle

A document enters protected. It stays that way.

From encrypted intake to durable commit, controlled processing, and expiry, each stage preserves the boundary.

The protected lifecycle

Protection persists across every stage.

Entry and commit

  1. 01Encrypt before intake.

    A document is protected before it enters the system.

  2. 02Commit under a durable key.

    At commit, it is re-encrypted under its own stored-record key.

Inside the protected boundary

  1. 03Process inside the boundary.

    Document processing runs without sending sensitive material outside the system.

  2. 04Expire working copies.

    Temporary intake copies are removed once their purpose is complete.

04 — Audited access

A protected document can be accessed—but never silently.

Access is an authorised action, not a background permission.

  • An authorised person requests access to protected material.

  • The action is confirmed before material is made available.

  • The approved action and actor become part of the audit trail.

Access is a sensitive operation. So it leaves a trace.
05 — Controlled processing

Two readers, working inside one boundary.

QR detection and OCR each see documents differently. Together, they create a bounded operational signal without exporting sensitive material.

QR + OCR processing boundary

Protected evidence stays within the system.

01 · Protected document

Encrypted evidence enters QR + OCR processing.

It is made available only to the controlled processing system.

Independent processing paths

02a · QR detection

Try multiple ways to read the pattern.

OpenCV applies contrast enhancement, denoising, scaling, and multiple detection paths within a time budget.

Evidence boundary

Strongest usable signal.

Signals are evaluated as evidence tiers, not an identity claim.

02b · OCR extraction

Try multiple ways to read the text.

Grayscale, contrast, and threshold normalisation passes are paired with reading modes and ranked for usable structure.

Minimum necessary output

03 · Bounded operations signal

Status, not raw content.

The authorised workflow receives the status needed to act. Extracted fields—such as a name, date, and reference value—remain protected inside the system.

Processing results remain protected no external egress
06 — Operational signal

Give operations the signal, not the document.

Raw document contents stay in the vault. Authorised teams receive only the minimum status needed to identify a submission that needs attention and follow up appropriately.

This keeps operational work moving without turning the wider stack into another store of sensitive evidence.

Protected inside the vault

The document and its extracted fields stay here.

  • Original document evidence
  • Extracted structured fields
  • Protected processing results

Minimum necessary signal

Authorised operations

A status that tells the team what needs attention.

Submission needs follow-up

Example signals

QR-based number identification failed

OCR number detection passed; checksum failed

Teams can use the status to request a new upload or begin another approved follow-up, without copying sensitive evidence into the wider operational stack.

Operational work keeps moving sensitive evidence does not spread
07 — Technology stack

A pragmatic stack for a strict boundary.

Each layer is chosen to make sensitive-document handling inspectable, controlled, and maintainable.

Deployment coordination

One monorepo. One Wrangler configuration.

The application, data, storage, Durable Objects, workflows, queues, and containerised processing are defined and deployed as one coordinated system.

Application

SvelteKit

Admin and operations interface.

Storage

Cloudflare R2

Separated transient and durable object storage.

Data

Cloudflare D1

Transactional records and bounded operational state.

Durable coordination

Durable Objects + workflows + queues

Durable processing, retries, state, and expiry handling.

Document processing

Cloudflare Containers + FastAPI

Controlled Python service boundary for document analysis.

Open-source readers

OpenCV + Tesseract

QR detection and OCR without exporting documents.

Let's find the work AI should be doing in your organization.

Whether you are exploring an idea or improving a system already in use, we’ll help you decide what is worth doing next.

Prefer to start async?

hello@thoughtfulrobots.ai

Hyderabad · Remote

Questions before you book?

Read the FAQ

Follow along

START A CONVERSATION

Tell us about the work.

A few lines about your product and where AI might belong. We usually reply within one business day.