Self-hosted · Zero-knowledge · White-label

Collect sensitive documents without surrendering them.

Fetcher is the document-collection platform that runs entirely on your infrastructure — on-premises or air-gapped — and encrypts every file so even your own servers can't read it. For organizations that legally, contractually, or constitutionally cannot put citizen and client documents on someone else's cloud.

Runs on your servers Keys never leave your org Fully white-label Air-gap ready
Live security posture

Encryption

In-browser, end-to-end

Where data lives

Your infrastructure only

Operator access to files

None — ciphertext only

Scroll
0
Keys on our servers
Requests · users · workspaces
0
Deployment modes
0
On your infrastructure

The problem with the cloud

Some documents can never live on a vendor's server.

Case files, citizen records, financial disclosures, sealed filings, privileged material. For the organizations that hold them, "trust us, it's encrypted on our cloud" is not an answer a regulator, a court, or a constituent will accept.

  • A SaaS vendor's breach becomes your breach — and your disclosure obligation.
  • A subpoena to the vendor can compel your clients' data without your knowledge.
  • Data-residency and sovereignty rules forbid storage outside your jurisdiction or network.
  • "We can decrypt it for support" means the vendor can decrypt it for anyone.
The Fetcher principle If we can't read your documents, we can't lose them, leak them, or be compelled to hand them over. Neither can anyone who breaches us — because there is no "us" in the path.

How zero-knowledge works

Encrypted before it ever leaves the sender's browser.

Your clients and constituents upload through a simple link — no account, no app. The encryption happens on their device, sealed to a key only your team holds.

Sealed at the source

Each file is encrypted in the uploader's browser using your organization's public key — before a single byte is transmitted.

Stored as ciphertext

Your server (and any storage you choose) only ever holds encrypted blobs. There is no key on the server that can open them.

Opened only by your team

Authorized members decrypt in their own browser with a passphrase that is never sent to any server — yours or ours.

Stated honestly. Zero-knowledge protects your documents at rest and against breach, infrastructure subpoena, and administrative access — no key in the storage path can decrypt them. Because the upload page is served software, a truly hostile operator could in principle alter it; this is inherent to any browser-based collection (the same boundary every product in this category shares). Self-hosting closes even that gap: when you serve the software, there is no third-party operator at all.

The platform

Everything you need to collect, review, and retain — under your own roof.

Zero-knowledge encryption

End-to-end, browser-side encryption keyed to your team. The server stores only ciphertext.

Total white-label

Your name, your domain, your branding end to end. Fetcher is invisible to your clients and staff.

Self-hosted, no limits

Unlimited requests, documents, users, and workspaces. It's your server — there are no SaaS meters.

Chain-of-custody audit log

Every request, upload, view, approval, and decline is timestamped and retained for defensible records.

Checklists & review workflow

Smart per-matter checklists, automated reminders, and an approve/decline review queue — bilingual.

Integrations & SSO

Connects to your DMS, CRM, e-sign, and identity provider. Scoped to your environment during onboarding.

Deployment

Wherever your rules say it has to run.

Fetcher installs into a WordPress environment you control — so it inherits your hosting, your network boundary, and your access policy.

Option 01

Your private cloud

Deploy in your own AWS, Azure, GCP, or sovereign-cloud tenancy, in the region your residency rules require.

Option 02

On-premises

Run it in your own data center, behind your firewall, under your existing controls and monitoring.

Option 03

Air-gapped

Fully offline operation with signed, file-based licensing — no phone-home, for the most restricted networks.

Built for

Organizations that answer to regulators, courts, and the public.

Government & public sector

Legal & law firms

Financial & accounting

Real estate & title

Healthcare & insurance

Editions

Licensed annually. Priced to your scale.

Every edition is self-hosted, white-label, and uncapped. They differ by deployment reach, security posture, and the level of hands-on support. Pricing below is a starting point — every engagement is scoped and quoted.

Corporate

From $18,000/yr

+ one-time implementation

A single firm that needs full ownership and white-label, on its own infrastructure.

  • Self-hosted & fully white-label
  • Unlimited requests, users & workspaces
  • Chain-of-custody audit log
  • Zero-knowledge encryption (add-on)
  • Standard onboarding & support
Request a quote
Enterprise

From $48,000/yr

+ scoped implementation

Multi-office and multi-department operations needing integrations and white-glove rollout.

  • Everything in Corporate
  • White-glove implementation & training
  • Priority SLA & dedicated success manager
  • Custom integrations (DMS, CRM, e-sign, SSO)
  • Zero-knowledge encryption (add-on)
Request a quote
Sovereign

Custom

typically $75,000+/yr

Government, regulated, and security-first bodies with the strictest deployment and data rules.

  • Everything in Enterprise
  • Zero-knowledge encryption included
  • On-prem / air-gapped / sovereign cloud
  • Security-review & documentation support
  • Source-escrow option · 24/7 support
Talk to us

No public checkout. Every deployment begins with a demo and a scoping conversation.

Security & compliance posture

Designed to fit inside your control framework — not replace it.

  • Runs entirely on infrastructure you own and govern
  • Zero-knowledge encryption at rest; encrypted in transit
  • Full, timestamped chain-of-custody audit log
  • Role-based access, SSO, and your own identity provider
  • Data residency by deployment region of your choosing
  • Security-review support and architecture documentation for your assessors
  • Source-escrow available for continuity requirements

Said plainly

Because Fetcher runs on your systems, your existing controls and certifications extend to it — it is built to support your HIPAA, CJIS, StateRAMP, or SOC 2 program, not to substitute a certification of ours. We provide the architecture, encryption design, and documentation your security team and auditors need to evaluate and approve it within your own framework.

How we engage

From first call to live, with your security team in the room.

Demo

A private walkthrough against your actual use case and constraints.

Scope

We map deployment, integrations, security review, and residency requirements.

Deploy

Installed into your environment, branded, integrated, and validated with your team.

Support

SLA-backed support, updates, and a named contact for the life of the contract.

Request a demo

See it run on infrastructure you'd actually trust.

Tell us a little about your organization and what you need to collect. We'll arrange a private demo and a scoping conversation — no sales floor, no obligation.

Prefer email? enterprise@fetcher.llc
Government procurement: gov@fetcher.llc
Contact Form Demo (#3)