How Tukanu keeps files on the computer.
Written for IT and security teams: what runs where, what the app sends, and how to lock it down further.
Files are never uploaded
Every conversion and tool runs on the user’s PC. The engines (LibreOffice, qpdf, PDFium and an image library) are bundled with the app and read local files only. The image library is locked to plain raster formats, with its network features disabled. Results are written as new files; originals are never modified.
Documents can’t call out while converting
Office files and web pages can reference outside servers through linked images, remote templates and external data. Two independent layers stop them:
- Clean copy. Every DOCX, PPTX, XLSX, ODT, ODP, ODS and HTML file is converted from a private copy with remote references removed, including web addresses and network-share paths that could leak Windows credentials. Clickable hyperlinks are kept and never fetched.
- Locked engine profile. The document engine runs with macros off, remote content blocked, link updates off, no update check, no crash upload, and every HTTP, HTTPS and FTP request routed to a closed local port. Legacy DOC, PPT and XLS files are covered by this layer.
An automated test converts documents full of remote links while local listeners stand in for outside servers, and fails on any connection. It also turns the clean copy off to prove the engine profile alone keeps requests on the machine.
Where the app connects
Tukanu checks the subscription at https://tukanuapp.com/api/app on port 443, through the system proxy, at launch and every few hours. A license lasts 72 hours, so short outages don’t interrupt work.
- Sent: a device ID, the computer’s name and the app version.
- Never sent: file names, folders or file contents.
- Problem reports: sent only when the user chooses Report a problem, to the same domain. The app shows the report before sending it, and file names are replaced with [file].
- Updates: downloaded from Cloudflare R2 (
*.r2.cloudflarestorage.com) through links that tukanuapp.com signs for paying computers and that expire after 15 minutes. Each file is checked against its SHA-256 before it’s installed. Blocking this host stops updates, not the app.
Firewall rules for the engines
As defense in depth, block outbound traffic for the bundled engines. Tukanu works exactly the same with these rules. Run as Administrator, adjusting the install folder, or deploy the same rules through Group Policy or Intune:
$app = "C:\Users\<user>\AppData\Local\TukanuApp\current"
Get-ChildItem "$app\engines" -Recurse -Include *.exe, *.bin, *.com | ForEach-Object {
New-NetFirewallRule -DisplayName "Tukanu engine - block outbound ($($_.Name))" -Direction Outbound -Action Block -Program $_.FullName
}