KWIP

KWIP Technology

Digest runtime documentation

Deployment, runtime boundaries, image access, and licensing.

Digest is a private, self-hosted API for extracting normalized text and metadata from business documents, images, PDFs, and archives.

The customer runs the container inside their network. Customer documents are not routed through the Kwip platform and are not stored by Kwip.

Positioning

The product is the commercially maintained integration boundary around mature open-source tools: stable API, Docker distribution, compatibility tests, security updates, release documentation, and support.

Platform Boundary

The Kwip platform should treat Digest as a control-plane product:

The Kwip platform must not proxy extraction requests or receive customer documents. Extraction traffic remains local to the customer's data plane.

Pricing Model

Digest pricing reflects maintenance and distribution rights, not page volume. Customers provide the compute, so page-based pricing would be artificial.

The correct economic claim is near-zero marginal compute cost and no customer-document storage cost. Do not claim zero cost; Kwip still bears registry transfer, build infrastructure, security scanning, signing, provenance, dependency update, support, documentation, and compliance costs.

The standard paid pilot is $2,500 for 90 days. It covers one organization and up to two deployments, with two onboarding sessions, eight support hours, and release security documentation. The full pilot fee is credited toward the first $6,000 annual Business term when signed within 30 days after pilot completion.

Runtime Status

The MVP runtime supports text, markup, PDF native text and OCR fallback, office formats, image OCR, and opt-in ZIP archive extraction. Release-candidate controls include PDF page limits, read-only runtime verification, SBOM generation, license inventory, vulnerability scanner wrapper, and a release checklist.

Current Image

ghcr.io/kwip-info/digest:0.1.0

Private registry access is the entitlement gate. The container keeps running after a subscription expires; expiration only removes access to new images, patches, and support.

Customer pull test:

docker login ghcr.io
docker pull ghcr.io/kwip-info/digest:0.1.0
docker run --rm \
  --read-only \
  --tmpfs /tmp:rw,noexec,nosuid,size=1g \
  --cap-drop ALL \
  --security-opt no-new-privileges:true \
  -p 8080:8080 \
  --env-file .env.example \
  ghcr.io/kwip-info/digest:0.1.0

Use immutable digests for production deployments. Moving tags are for release-channel discovery.

Download Markdown