AADITHYA VIMAL

Security · 2026 · Live demo · Open source · 2026

Draftoryn

A professional cybersecurity document studio generating 30 canonical offensive security, DFIR, threat intel, and GRC deliverables with a Zero Hallucination Guarantee and AES-256 encrypted export.

My role
Designed and built the cross-platform Expo studio, deterministic document engine, Hono API on Cloudflare Workers, and AES-256 ZIP packaging.
Status
Live demo · Open source · 2026
Category
Security · Cybersecurity document studio
Live demoSource on GitHub

Live demo · interactive

🔒draftoryn.pages.dev
CONNECTING TO DRAFTORYN...

Embedded for convenience — if it doesn’t load here, open the full site directly.

01

Understand

Why it exists. Security practitioners lose hundreds of hours formatting deliverables or battling risky chatbot hallucinations. Draftoryn pairs canonical structural templates with strictly bounded AI synthesis.

What I built. Cross-platform document studio deployed as an Expo / React Native Web SPA on Cloudflare Pages, backed by a hardened Hono API running on Cloudflare Workers, serverless Neon PostgreSQL, and Clerk authentication.

The problem it solves. Penetration testers, security consultants, and GRC teams spend dozens of hours battling fragile Word templates or risky chatbot copy-pasting, resulting in inconsistent deliverables and dangerous hallucinations of target IPs, credentials, or findings.

What it does

  • 30 canonical cybersecurity documents across 6 domains (Offensive Security, DFIR, Threat Intel, Architecture, Risk/GRC, Resilience)
  • Zero Hallucination Guarantee: missing parameters become explicit placeholders rather than fabricated facts
  • Publication-ready multi-format exports: PDF, DOCX, Markdown, HTML, JSON, XML, YAML
  • Client-side password-protected AES-256 encrypted ZIP delivery for confidential deliverables
02

Technical depth

Architecture. Dual-engine document pipeline: a deterministic structural engine generates 30 canonical cybersecurity documents across 6 core domains (Offensive Security, DFIR, Threat Intel, Security Architecture, Risk/GRC, Resilience), combined with optional context-validated AI synthesis (OpenAI, Anthropic, Groq, Gemini). Outputs to PDF, DOCX, Markdown, HTML, JSON, XML, and YAML, complete with on-device AES-256 password-protected ZIP delivery.

Security model. Zero Hallucination Guarantee: strict operational boundaries prevent AI from fabricating IPs, testing windows, or authorizations — missing parameters remain explicit placeholders. Enforces fail-closed auth, owner-scoped Neon queries (WHERE owner_id = clerk_id), strict CORS, and sanitized XSS-safe exporters.

Tradeoff. Enforcing strict input boundaries and requiring explicit operator review before export avoids liability and hallucinated findings.

  • Expo
  • React Native Web
  • Hono
  • Neon PostgreSQL
  • Clerk Auth
  • Cloudflare Workers
  • AES-256 ZIP
How it works, step by step

Dual-engine document pipeline: a deterministic structural engine generates 30 canonical cybersecurity documents across 6 core domains (Offensive Security, DFIR, Threat Intel, Security Architecture, Risk/GRC, Resilience), combined with optional context-validated AI synthesis (OpenAI, Anthropic, Groq, Gemini). Outputs to PDF, DOCX, Markdown, HTML, JSON, XML, and YAML, complete with on-device AES-256 password-protected ZIP delivery.

Security notes

Zero Hallucination Guarantee: strict operational boundaries prevent AI from fabricating IPs, testing windows, or authorizations — missing parameters remain explicit placeholders. Enforces fail-closed auth, owner-scoped Neon queries (WHERE owner_id = clerk_id), strict CORS, and sanitized XSS-safe exporters.

Security