Trust
Air-gapped installs
For a site whose servers have no route to the internet, or whose security team wants to be able to prove they have none that matters. A default Draughtsman makes no outbound network connection. This page says what to carry across, what can call out if an administrator switches it on, and how to check it on your own machine.
The checks in the last section were run by us on the current build on a Mac. The statements about Docker with no network, the image tarball and the software bill of materials come from Overpass's own run on 2 October 2026 and from the guide that ships in the archive; we did not run Docker for this page. Anything neither of us ran is marked unverified.
What to carry across
Fetch these on a connected machine, check them there, and move them on whatever media your site allows. Downloads are provided to licensed customers; see Licensing.
| File | What it is | Needed |
|---|---|---|
The release archive (.tar.gz or .zip) for your platform | The server, the web app, the Node runtime for layout and the guides: one self-contained folder. | One of these or the container image supplied with your licence |
SHA256SUMS | Checksums of the archives and of the software bill of materials. | Yes: check what you carried |
The software bill of materials (.cdx.json; the same file is inside every archive as SBOM.cdx.json) | A CycloneDX 1.5 list of every package shipped, for your security review. | For your review |
| Your licence file | Signed, verified offline. | Optional: without one it runs as a full evaluation |
| A browser on the server | Only for server-side PDF, which is optional. | No: File, Export PDF prints from the person's own browser |
Nothing else: no .NET runtime, no Node, no package manager, no container registry and no database server. No container image is published; the one supplied with your licence is a file you carry across and load (docker load), which Overpass's guide describes and which we did not run.
Install, licence, PDF, backup and upgrade with no network
- Install. Check the checksum, unpack, and follow Install. The archive downloads nothing at first run or later: the layout runtime is inside it, SQLite is inside the executable, and the web app's fonts, scripts and styles are served from the same folder. The archives are not yet code-signed, so the first run on macOS or Windows is stopped by Gatekeeper or SmartScreen exactly as on a connected machine.
- Licence. A signed file you carry across and put in the data folder; the server re-reads it with no restart. Whether a build is covered depends on the date the build was made, never on the server's clock, so a drifting clock on an air-gapped host cannot expire anything. (No production verification key is built in yet; see Licensing.)
- PDF. The editor's File, Export PDF… draws the diagram in the browser and opens the browser's print dialog; nothing is installed and nothing is sent to the server. Server-side PDF, for scripts and agents, needs a Chrome, Chromium or Edge on the server; the server never downloads one. See PDF.
- Backups are local files:
draughtsman backupwrites one zip wherever you point it. See Backup, restore and upgrading. - Upgrades are a new file carried across, then
draughtsman config checkwith the new program, then the same procedure as anywhere. See Upgrading safely. Nothing is fetched during an upgrade.
What leaves your network, and when
| What | When | Where it goes | Off by default? |
|---|---|---|---|
| Nothing | A default install, any time: sign-in, create, save, layout, export, backups | n/a | n/a |
| The browser's requests | Loading and using the app | Only to your Draughtsman server. No web fonts, CDN, analytics or error reporter; the Content-Security-Policy is default-src 'self' with connect-src 'self' | Yes |
| An AI model | A person uses the AI panel, or an administrator presses Test connection | The endpoint the administrator typed: your own Ollama host, or a cloud provider only if you name one. The prompt and, when updating, the open diagram go there. Where the endpoint may point | Yes: no provider is set and the panel is hidden |
| Outgoing email | A password-reset email, or a test message | The mail server the administrator named | Yes |
| A web page's CSS, for a draft theme | An administrator presses Fetch and read colours | The one address typed, https only, plus up to 8 stylesheets it names. From a website | Yes: themes.fetchFromUrl.enabled is false |
| Postgres | Always, once chosen | The database server you run | Yes: SQLite in the data folder |
| The server-side PDF browser's download | Once, when an administrator runs the install command by hand | Playwright's download hosts, from the machine running the command, never from the server | Yes |
| Help, Documentation; the support contact | A person clicks | In the archive, the server's own copy of the guides; the contact is a mailto: link | On a click only |
| Your reverse proxy | Its own certificate renewal | Not Draughtsman: Caddy's automatic HTTPS and any ACME client call out | Your proxy's setting |
No licence check, update check, usage telemetry or crash reporter. The layout process (the Node sidecar) is a child of the server that talks over a pipe and opens no socket.
Check it on your own machine
Do not take this page's word. These are the checks we ran on the current build, with their real output.
Scan what ships to a browser and to the layout process. Overpass's build-time checker (it runs on every release build and is not part of the archive) fails on any external host or network module in the built web app or the sidecar bundle:
Run for real$ check-offline-bundles all (Overpass's build-time check; not shipped) check-offline-bundles: web: no external host, no network module check-offline-bundles: sidecar: no external host, no network module [exit 0]Look at the sockets while the server is running. One listening socket, and the layout process has none; the layout process can load only
Run for realnode:cryptoandnode:readline:$ lsof -nP -a -p <server pid> -i COMMAND NODE NAME draughtsm TCP 127.0.0.1:58941 (LISTEN) $ lsof -nP -a -p <sidecar pid> -i (the layout process, a child of the server) 0 lines of output (no sockets) $ grep -oE 'require\("[^"]+"\)' sidecar.js | sort -u require("node:crypto") require("node:readline")Read the policy that stops the browser.
curl -sI http://localhost:5180/ | grep -i content-security-policyprints a policy whoseconnect-srcis'self', so a request to any other origin is blocked by the browser itself. We read it from the running server above, and the Security page shows the browser's own request list (every request to the server's own origin).Block it and see. Put the host behind a default-deny egress firewall for a day. Nothing changes. We did not run this one.
Overpass also runs, on every build, a test that listens inside the server process to every name lookup, connection and handshake the runtime announces while it is driven through a day's work, and a run of the Docker image with --network none. We read about these in the guide and did not repeat them; they are not a substitute for the checks above on your own machine.
The software bill of materials
Every release carries a CycloneDX 1.5 list of the NuGet packages of the server, the npm packages bundled into the web app and the layout process, and the bundled Node runtime, each with its version, licence and package URL. It is inside every archive, beside the archives, and checked as not hollow by the release scripts. It is a flat list; it leaves out the .NET runtime (its notices are in each archive), the container's base layers and the optional Chromium. Overpass validated it once against CycloneDX's own schema; we did not run any SBOM consumer.
What this does not prove
- The in-process test sees the server only. The layout process and, when enabled, Chromium are other processes, covered by a static check and by being off by default, not by a packet capture.
- A default configuration. An administrator who sets an AI endpoint, a mail server or a Postgres connection has chosen to reach that host.
- Anything outside the product: the operating system's own update services, browser extensions, the build tooling, the reverse proxy.
- A connection from a default Draughtsman to anything but a client of yours is a bug. Tell us, with what
lsofshowed and the version from About: draughtsman@overpass.co.uk (see Reporting a vulnerability).