Secure by construction.
Purple Hammer runs entirely on the machine that opens your files. Your project data never leaves your network. Not as a policy we promise to keep — as a consequence of how the software is built.
Does Purple Hammer upload my project data?
No. Purple Hammer is a desktop application. It opens files from your own disk or your own file share, works on them locally, and writes results back to the same place. There is no server-side copy of any of it — not a cache, not a thumbnail, not a temporary upload for processing.
Your project data means everything you put into Purple Hammer and everything it produces: drawings, files, markups, measurements, calculations, formulas, databases, usage — all of it. It is separate from your account — the email and device name your licence is issued against, which is the only thing that ever reaches us.
Because we never receive your project data, a breach of our servers cannot expose it.
What does leave your machine?
Every connection Purple Hammer makes. None of them carries your project data.
- Licence check
- Roughly once every 24 hours while the app is open: account email, device name, connecting IP address, and check-in timestamps. None of your project data.
- Updates
- The app checks for and downloads its own updates. What goes out is a version query; what comes back is the installer. No project data in either direction.
- AI features
- Off by default. If you turn them on, your content goes from your device directly to the AI provider you choose — your own model, your own key. It does not pass through our servers and we never receive it.
Diagnostics stay on your machine. Purple Hammer writes diagnostic and usage information locally so a problem can be debugged. It is not transmitted. If you hit a technical issue and want our help, you generate a zip from inside the app and send it to us — a deliberate act, by you, with a file you can open and read first.
Does it need an internet connection?
Purple Hammer needs a valid, current licence to run, and keeping it current takes an occasional connection. If the software cannot establish a licence, it shuts down. We would rather state that plainly than imply an offline mode we do not offer.
What it does not need is a connection while you work. Your files open, render, measure and price entirely on your own machine, and a small grace period covers the ordinary case of losing signal for a while.
Updates need a connection too, including security updates. A disconnected machine carries on working, but it stops receiving them — on a segregated network that is worth planning for.
For sensitive and remote projects we issue long-standing keys. If your deployment cannot reach the internet on a normal cycle — a secured network, a remote site, a segregated environment — tell us what the project requires and we will licence it to match.
A naturally secure architecture
- Desktop, local
- The work happens on your machine. There is no server holding your project data to attack.
- No bundled browser
- Purple Hammer uses the web view your operating system already provides — WebView2 on Windows, WKWebView on macOS — rather than shipping its own copy the way Electron applications do. Browser-engine vulnerabilities are closed by your normal OS patch cycle, by Microsoft and Apple, rather than waiting for us to ship a release.
- Rust core
- The application core is written in Rust. Memory-safety bugs — the largest class of native vulnerability — are eliminated by the language itself, not caught by review.
Who builds it
Purple Hammer is built by SHAPEDO Ltd. For the last decade ShapeDo has made design-change management software for large-scale construction, and it is used on the kind of project where a security review happens before a purchase order.
ShapeDo's software has been deployed on transport infrastructure, hospitals, airports, metro systems and military bases, across multiple countries, and has passed the security review of multiple government agencies.
ShapeDo maintains a SOC 2 Type II report, available on request.
What we hold, and where
We hold account and licence records — your email, your seats, your devices' names, and their check-in history — and nothing else. This infrastructure runs on Amazon Web Services in the EU (Ireland).
Sign-in uses an emailed link, or your existing Google or Microsoft account. We never store a password of yours, so there is no password for us to lose.
Every third party involved in running Purple Hammer is named in our privacy policy and sub-processor list, with its role and its location. AI providers are deliberately not on that list, because your content never reaches us to pass on.
Full detail — mechanisms, boundaries, and what we do not claim
"Never leaves your network" — the exact scope
Your project data means everything you put into Purple Hammer and everything it produces: drawings, files, markups, measurements, calculations, formulas, databases and usage. All of it is read from, and written to, storage you control — a local disk or a network share on your own infrastructure. Purple Hammer has no upload path for any of it.
What the claim does not cover is your account and licence identity — email, device name, IP, check-in times — which is listed in full above and leaves the machine by design.
Local processing — where the work happens
Rendering, measurement, revision comparison and worksheet solving all execute on the endpoint. File size and project scale therefore cost you local CPU and RAM, never bandwidth, and never our compute.
Licence connectivity — the mechanism
Purple Hammer requires a valid, current licence to operate. The licence is refreshed whenever the application has connectivity, and a small grace period absorbs ordinary gaps. If a licence cannot be established, the software stops.
No connection is required while you work: rendering, measurement, comparison and worksheet solving all run locally and none of them contacts us.
Deployments that cannot meet a normal refresh cycle are licensed differently — long-standing keys are issued for sensitive and remote projects. That is a licensing decision, not a separate build of the software.
Browser engine — why we mention the OS web view
Applications that bundle their own browser engine carry that engine's vulnerabilities until the vendor ships an application update. Purple Hammer uses the operating system's web view, so that class of fix arrives through the OS update process your organisation already runs.
Diagnostics — generated locally, sent by hand
Diagnostic and usage information is written to the local machine so that faults can be diagnosed. There is no telemetry channel and no automatic upload. Sending it is a manual export to a zip file, initiated by the user, readable by the user before it is sent.
Send this page to your IT team.
It is written to make a vendor security review faster, not to replace one. Anything it does not cover, ask us.