Printora
Security Whitepaper

Printora Security Architecture

A technical breakdown of our transport encryption, certificate fingerprint verification, device authentication, sliding-window rate limiting, and temporary file sanitization.

1. Security Philosophy: Local-First Isolation

Unlike traditional cloud print services that require routing confidential documents through multi-tenant cloud storage, Printora treats the local Windows computer as the authoritative print host.

✓ Local-First Fast Path:
Phone (Client) ──[ Direct TLS / Pinning ]──> Windows Host ──> Local Windows Spooler

At no point in the local printing path do unencrypted bytes leave your local private network.

2. TLS & SHA-256 Certificate Fingerprint Pinning

Local network discovery services (mDNS and UDP beacons) broadcast the server's connection endpoint. Because local-area network hostnames typically lack public CA signed certificates, Printora generates a self-signed X.509 certificate on the Windows host and exports its SHA-256 fingerprint into the pairing QR code and discovery payload.

  • Android App: Enforces certificate fingerprint verification on every TLS handshake via custom TrustManager implementations, preventing man-in-the-middle (MITM) attacks on shared Wi-Fi networks.
  • Zero Plaintext HTTP: All local-network REST and WebSocket API endpoints require TLS.

3. Device Authentication, Pairing & Host Approvals

The Windows desktop server maintains an internal device registry. When an unknown client requests a print connection:

Rotating 6-Digit PIN

A rotating connection PIN is displayed on the Windows host UI. Submitting an incorrect PIN triggers an anti-brute-force lockout.

Administrator Approval Toast

The desktop host displays a native Windows approval notification for newly discovered devices, allowing the operator to approve or block the client permanently.

4. Web Print Anti-Abuse Defenses

To prevent paper and toner exhaustion when exposing the Web Print Studio to browsers or guest devices, the server enforces multi-layer sliding-window protection:

Rate Limit Per IP:2 print jobs / minute, 15 / hour
Brute-Force Lockout:5 failed attempts = 5-minute lockout
Default Web Copies Limit:Max 3 copies per submission
Default Page Ceiling:Max 30 PDF pages per job
Session Token Lifetime:2-hour HMAC-SHA256 signed cookie/header

5. Automatic Temporary File Sanitization

When a mobile client uploads a document, the server streams the file to an isolated staging directory under the local user profile. If format conversion is required (such as rendering DOCX to PDF or preparing high-DPI raster layers for the spooler), temporary working files are tracked in the job execution context.

Sanitization Lifecycle: Once the Windows print spooler signals job completion, all staged uploaded files and intermediate converted artifacts are automatically deleted from the disk. Original personal documents outside the staging folder remain unaffected.

6. Realistic Threat Model & System Limitations

We do not make unverified claims such as "100% unbreakable" or "zero data exists anywhere." Understanding boundaries is the cornerstone of professional security:

  • Physical Host Security: Security guarantees depend on the Windows host operating system being properly updated and secured. An attacker with administrative control over the host PC can observe spooler memory.
  • Hardware Spooler Logging: Certain enterprise printer hardware features internal hard drives that log print job accounting metadata independently of Printora.
  • Remote Path Relays: While Cloudflare Tunnel provides transport encryption without open inbound ports, tunnel infrastructure operates under Cloudflare's published edge security policies.