Jadwal Sholat

Memuat jadwal sholat…

Computer Science editorial

Open AccessOA2026

The Web-CLI: Verifiable Privacy for Tools, Models, and Inference Engines in the Browser

A zero-install, offline-capable architecture that makes data locality a technical guarantee rather than a policy promise
Tejaswi Gowda· 2026· DOI 10.48550/arXiv.2608.28950

The core problem

Web-based applications that process sensitive user data—medical records, legal documents, journalistic sources, or personal media—typically rely on server-side computation. This exposes data to third parties and makes privacy a matter of policy rather than technical guarantee. The Web-CLI introduces an alternative: a browser application architecture that deploys powerful computational capabilities as zero-install, offline-capable tools that preserve full underlying capability while executing entirely on the client.

The architecture is defined by four properties: **fidelity** (the browser tool matches native capability), **progressive disclosure** (complex interfaces are revealed gradually to non-technical users), **offline-first** (functionality without network access), and **zero egress** (no user data leaves the device). Together, these properties yield a verifiable privacy guarantee by construction. The authors argue that for applications processing sensitive data, the Web-CLI should be the default architecture, as it makes data locality an independently verifiable technical property rather than a policy promise.

Innovation

The four reference implementations demonstrate that the Web-CLI pattern generalizes across deterministic media processing, neural speech recognition, LLM inference, and geometry processing with a physical output. The primary implementation, ffmpeg-webCLI, is evaluated against native FFmpeg on performance and feature parity, though specific quantitative results are not detailed in the abstract. Early anecdotal evidence indicates independent reuse by third-party tools, suggesting the pattern extends beyond the original reference implementations.

The architecture achieves zero egress: no user data is transmitted to external servers. This is a binary property—either data leaves the device or it does not—and can be independently verified through network monitoring. The progressive disclosure property is argued to lower the barrier for non-technical users, though no user studies are reported in the abstract.

Formally, the privacy guarantee can be expressed as:

where egress is the volume of user data transmitted outside the client device. The Web-CLI enforces by

Web-based applications that process sensitive user data—medical records, legal documents, journalistic sources, or personal media—typically rely on server-side computation. This exposes data to third parties and makes privacy a matter of policy rather than technical guarantee. The Web-CLI introduces an alternative: a browser application architecture that deploys powerful computational capabilities as zero-install, offline-capable tools that preserve full underlying capability while executing entirely on the client.
The architecture is defined by four properties: **fidelity** (the browser tool matches native capability), **progressive disclosure** (complex interfaces are revealed gradually to non-technical users), **offline-first** (functionality without network access), and **zero egress** (no user data leaves the device). Together, these properties yield a verifiable privacy guarantee by construction. The authors argue that for applications processing sensitive data, the Web-CLI should be the default architecture, as it makes data locality an independently verifiable technical property rather than a policy promise.

Why it matters

The Web-CLI shifts privacy from a policy promise to a technical property. In conventional server-side architectures, privacy depends on the service provider's policies, which may change, be breached, or be subject to legal compulsion. In the Web-CLI, privacy is a consequence of the execution model: if computation occurs entirely on the client and no data is transmitted, then data locality is independently verifiable by the user through network inspection.

This has profound implications for domains handling sensitive data. For medical applications, patient records never leave the clinician's device. For legal tools, attorney-client privileged documents remain privileged by construction. For journalism, source protection becomes a technical guarantee rather than an operational security challenge. For personal media, users retain full control over their data.

The pattern also enables offline-first functionality, which is critical in environments with unreliable or censored network access. By compiling tools to WebAssembly and using client-side inference runtimes, the Web-CLI preserves full capability without requiring installation or network connectivity.

The authors outline an extension to AI-native interfaces where a local language model becomes the command surface itself. In this vision, users interact with the system through natural language, and the model orchestrates local tools—all without data egress. This represents a convergence of the Web-CLI pattern with the growing capabilities of on-device AI.

While the abstract reports only early, anecdotal signs of independent reuse, the four reference implementations provide a strong proof of concept. Future work should include rigorous performance benchmarks, user studies on progressive disclosure, and formal verification of the zero-egress property. Nevertheless, the Web-CLI offers a compelling default architecture for privacy-sensitive applications, making data locality a verifiable technical property rather than a policy promise.

Who should read this

CS practitioners and researchers

Opening member content…