Sensitive files should not need cloud detours
The document should remain inside the chosen local boundary unless the user explicitly chooses otherwise.
Protect sensitive documents on Android while keeping the document workflow in the app and local AI runtime ownership behind Harnex.
A useful Android product has to manage documents, lifecycle, resource pressure and user recovery without turning every consumer app into an LLM runtime project.
The document should remain inside the chosen local boundary unless the user explicitly chooses otherwise.
Bundling models, llama.cpp, scheduling and residency into every app creates duplicated infrastructure and tighter coupling.
Runtime availability, Binder loss and local-AI setup need product-level recovery instead of hidden fallback behavior.
RedactGuard owns PDF or text ingestion, PII policy, masked review, redaction and export. Harnex owns model and runtime infrastructure behind its Consumer Android SDK and Binder boundary.
The separation makes the trust model explicit: when local AI is unavailable, RedactGuard surfaces recovery and does not silently send the source document to cloud inference.
The implemented Android journey keeps local-AI status and recovery visible while preserving human control over every redaction decision.
Choose the source, then select built-in or custom PII definitions before analysis can start.
Sensitive values stay hidden by default while the user confirms or rejects each proposed redaction.
Export remains fail-closed until the review state is complete, then uses Android's system file flow.
The Android variant is a concrete consumer of Harnex: application workflow stays inside RedactGuard, while the Consumer SDK and Binder boundary connect it to Harnex runtime ownership.
Owns document ingestion, PII policy, human review, deterministic redaction and export.
Defines the explicit contract between the consumer application and Harnex host.
Owns model selection, runtime lifecycle, scheduling, residency and the local inference backend.
RedactGuard Android reduces unnecessary exposure; it is not a compliance guarantee. OCR and VLM document understanding remain out of scope, and local model findings still require human review.
EVIDENCE & LIMITS
RedactGuard Android proves the product journey and the Harnex consumer contract. Emulator and integration evidence do not automatically become claims about every device, OEM, thermal condition or model-quality regime.
EVIDENCE BOUNDARY
The Harnex consumer path is implemented; device claims stay narrow.
The current Android product supports PDF and text ingestion, configurable PII selection, local analysis through Harnex, masked review, fail-closed redaction/export and explicit local-AI recovery. Broader representative-device evidence remains a separate gate.
Supported today
Not claimed here
CONNECTED SYSTEM
RedactGuard Android is the consumer proof for Harnex: a real privacy-sensitive application using on-device AI without owning the model runtime itself.