Product family
RedactGuardOne privacy workflow. Two local execution boundaries.
PRODUCT · ANDROID · HARNEXExperimental Android consumer proof

RedactGuard Android

Protect sensitive documents on Android while keeping the document workflow in the app and local AI runtime ownership behind Harnex.

Android appHarnex backboneFail-closed
RedactGuard Android review flow with masked findings and explicit redaction decisions
Import → detect → review → redactAndroid · Harnex
The mobile problem

Privacy-sensitive AI is harder when the runtime lives inside the app.

A useful Android product has to manage documents, lifecycle, resource pressure and user recovery without turning every consumer app into an LLM runtime project.

01

Sensitive files should not need cloud detours

The document should remain inside the chosen local boundary unless the user explicitly chooses otherwise.

02

The app should not own model infrastructure

Bundling models, llama.cpp, scheduling and residency into every app creates duplicated infrastructure and tighter coupling.

03

Mobile failures must remain understandable

Runtime availability, Binder loss and local-AI setup need product-level recovery instead of hidden fallback behavior.

The architectural question: can a real Android app consume local AI without becoming the runtime host itself?
The Android solution

Keep the workflow in RedactGuard.
Move runtime ownership to Harnex.

RedactGuard owns PDF or text ingestion, PII policy, masked review, redaction and export. Harnex owns model and runtime infrastructure behind its Consumer Android SDK and Binder boundary.

The separation makes the trust model explicit: when local AI is unavailable, RedactGuard surfaces recovery and does not silently send the source document to cloud inference.

1
ImportAdd a PDF or paste text inside the Android app.
2
DetectRequest local analysis through the Harnex consumer boundary.
3
ReviewSensitive values stay hidden by default while decisions remain human-controlled.
4
ExportCreate a protected PDF only after the review state is complete.
Product workflow

Import. Protect. Review. Export.

The implemented Android journey keeps local-AI status and recovery visible while preserving human control over every redaction decision.

RedactGuard — Start with a PDF or text
1 · IMPORT

Start with a PDF or text

Choose the source, then select built-in or custom PII definitions before analysis can start.

RedactGuard — Review masked findings
2 · REVIEW

Review masked findings

Sensitive values stay hidden by default while the user confirms or rejects each proposed redaction.

RedactGuard — Save the protected PDF
3 · EXPORT

Save the protected PDF

Export remains fail-closed until the review state is complete, then uses Android's system file flow.

Who owns what

The app owns the workflow. Harnex owns local AI infrastructure.

The Android variant is a concrete consumer of Harnex: application workflow stays inside RedactGuard, while the Consumer SDK and Binder boundary connect it to Harnex runtime ownership.

The app owns the workflow. Harnex owns local AI infrastructure. — RedactGuard architecture

RedactGuard Android

Owns document ingestion, PII policy, human review, deterministic redaction and export.

Consumer SDK + Binder

Defines the explicit contract between the consumer application and Harnex host.

Harnex

Owns model selection, runtime lifecycle, scheduling, residency and the local inference backend.

Explore the architecture on GitHub ↗

RedactGuard Android reduces unnecessary exposure; it is not a compliance guarantee. OCR and VLM document understanding remain out of scope, and local model findings still require human review.

EVIDENCE & LIMITS

The consumer boundary is implemented. Broader device claims stay separate.

RedactGuard Android proves the product journey and the Harnex consumer contract. Emulator and integration evidence do not automatically become claims about every device, OEM, thermal condition or model-quality regime.

EVIDENCE BOUNDARY

The Harnex consumer path is implemented; device claims stay narrow.

The current Android product supports PDF and text ingestion, configurable PII selection, local analysis through Harnex, masked review, fail-closed redaction/export and explicit local-AI recovery. Broader representative-device evidence remains a separate gate.

Supported today

  • PDF and pasted-text ingestion with built-in or custom PII selection
  • Harnex Consumer Android SDK and Binder integration
  • Masked human review and fail-closed redaction/export
  • Explicit recovery instead of silent cloud fallback

Not claimed here

  • OCR or VLM document understanding
  • Universal production performance, thermal or OEM reliability claims

CONNECTED SYSTEM

Where this project fits

RedactGuard · Android

One privacy workflow. A mobile execution boundary.

RedactGuard Android is the consumer proof for Harnex: a real privacy-sensitive application using on-device AI without owning the model runtime itself.

Explore Android ↗