Start a Project
Start a Project
Skip to tools content

Essential Tools · Version 1.0.0

What happens
to your work.

Your documents, plans and processes are handled in your browser. This page explains the limits of that design and the checks behind the release.

Local by default

Editing, calculations, diagram rendering, logo processing and file exports run locally. Tool inputs are not sent to pdfme Cloud, Mermaid rendering services, an AI service or an Essential Designs document database.

As with any website, your browser requests the page and its static assets from the hosting provider. Those requests may produce standard server access logs, such as the requested path and IP address. Your tool data is not placed in those paths or query strings.

Marketing pixels, tag management, call tracking and form-capture scripts are disabled on these Tools pages. No tool usage analytics is sent in V1. We have not enabled session recording or a new analytics provider.

Saving and clearing

Your working draft stays in memory by default. “Remember this draft on this device” is optional and starts off. Browser storage is not an encrypted vault and can be read by someone with access to your browser profile.

Use the draft controls to remove saved data. Clearing browser site data also removes it. Files you download remain wherever you save them; deleting a browser draft does not delete those files.

Save JSON for later editing. Import checks run before the current draft is replaced, and replacing or clearing work requires confirmation. Unsupported versions and damaged files do not silently replace your draft.

Exports and untrusted input

  • Business documents use trusted templates and an embedded Noto Sans font. Uploaded logos must be local PNG or JPEG files and are reencoded before use.
  • Financial calculations use decimal arithmetic with explicit rounding. Tax rates, hours, rates and estimates remain your responsibility to check.
  • Project dependencies reject missing tasks, self-references and cycles. The timeline is isolated in a sandboxed frame; an editable task list provides the same information without dragging.
  • Process diagrams use a restricted Mermaid subset and an SVG allowlist. The visible preview is an image of sanitized output. Mermaid parsing runs in the page; the preview is not a separate parser sandbox.
  • Complexity and file limits reduce accidental overload. They do not promise that every large diagram will render quickly on every device.

Upstream versions

FoundationVersionUse
pdfme6.1.12Document Builder
Frappe Gantt1.2.2Project Planner
Mermaid11.17.2Process Mapper

Supporting dependencies include DOMPurify 3.4.14, decimal.js 10.6.0, Zod 4.5.4 and PDF.js 6.3.289. The source archive contains the full locked dependency and licence inventory. No runtime dependency is loaded from an unversioned CDN.

Review scope

Version 1.0.0 was checked on 6 September 2026. Passing checks cover independently calculated examples, date rules, document pagination, process rendering, import/export round trips, malicious inputs and a clean source-kit installation. Browser checks cover Chromium, Firefox and WebKit, keyboard controls, responsive layouts, accessibility scans and the absence of external requests during tool use.

There has been no independent security audit. Automated accessibility checks supplement keyboard and visual review; they do not establish complete WCAG conformance or real-device Safari testing.

Source archive checksum · Release and capability manifest · Developer documentation

Known limits

These tools do not provide accounting, legal or tax advice, resource scheduling, process execution or automatic integration with your business systems. PDF and diagram text support depends on the included font; unsupported characters produce an actionable error rather than a silently broken export.

The existing contact page is a separate company service. Following a custom-solution link sends only a fixed tool identifier. Any enquiry details you choose to enter are handled by that contact flow, with its own privacy notice. End-to-end message delivery is a separate integration check.

Report a problem

Use the existing Essential Designs contact page to report unexpected calculations, confusing wording, export problems or a suspected vulnerability. Include the tool name, release version and steps to reproduce using fictional data. Avoid sending confidential documents or passwords.

Contact Essential Designs ↗