Skip to content

A desktop tool that keeps client footage off the network entirely

A native desktop tool for organizing and pre-processing raw client footage entirely on-device, with a signed installer for Windows and macOS so editors never have to upload sensitive footage to a server first.

Rushbay
The Low TideDay 14Card A014
No network in the path EDIT-07 · Windows 11
Day 14 · Card A014Shot 15/09/2026 · 12 clips · 202.67 GB on disk Search 38,412 clips
All 12Circle take 6Harbour ext 6Kitchen int 3Lane ext 3Sorted by timecode
00:00:38:00
A014_C00141/1
Proxy
00:01:11:00
A014_C00241/2
ProxyCircle take
00:02:14:00
A014_C00342/1
ProxyCircle take
00:01:36:00
A014_C00442/2
Proxy
00:00:52:00
A014_C00542/3
ProxyCircle take
00:01:58:00
A014_C00643/1
Proxy
00:00:44:00
A014_C00743/2
Proxy
00:01:27:00
A014_C00843/3
ProxyCircle take
00:01:03:00
A014_C00944/1
Proxy
00:02:29:00
A014_C01044/2
ProxyCircle take
00:00:29:00
A014_C01144/3
Proxy
00:01:15:00
A014_C01245/1
ProxyCircle take
Card B014 · ingested 10:129 clips · 150.94 GB copied to this workstation1 rendering8 queued
B014_C00161%FFmpeg on this machine · no upload step
Proxies12 of 211 rendering8 queuedMEDIA-01 (M:)1.84 TB free of 4 TBCatalogue38,412 clips · localSent today0 B footage

The brief, in specifics

Industry
Media & Publishing
Duration
8 weeks
Cooperation model
Fixed price
Services
Desktop app buildLocal processing pipelineSigned installer
Integrations
HubSpotDocuSignXeroGoogle Workspace
Technologies
ElectronTypeScriptReactFFmpegSQLiteCode signing & notarization
Team
1 Project lead2 Frontend engineers1 Backend engineer

Client name withheld under NDA. Engagement details are shown to the extent our agreement permits.

01

Nothing leaves the machine

Organizing, tagging, and proxy generation all run on-device with no network dependency.

Ingest, tagging and proxy generation all run on the workstation, with no network call in the path. The studio's footage is under embargo, and a tool that uploaded to think would have been unusable however well it worked. The catalog is a local SQLite database, so search over tens of thousands of clips is instant and doesn't depend on anyone's connection.

What shipped
  • Ingest, tagging and proxies all on-device, no network in the path
  • Local SQLite catalog: instant search over tens of thousands of clips
  • Nothing leaves the machine until the studio chooses to deliver
Rushbay
The Low TideNetwork policy
No network in the path EDIT-07 · Windows 11
What can leave this machineEDIT-07 · Wed 16/09/2026 · policy set by The Low Tide's confidentiality termsFootage has no network path
Each step, and where its data goes
Card ingestCopied to MEDIA-01 on this workstationNo network
Catalogue and searchcatalogue.sqlite on the system driveNo network
TaggingWritten to the local catalogNo network
Proxy generationFFmpeg, beside the originalsNo network
Delivery packageOnly when the studio exports, to a driveDrive only
Update check-inBuild version and workstation name, no mediaMetadata
Footage sent today0 Bno upload path exists
Update check-ins45.6 KB out · no media
Delivered by drive1LowTide_D14_Selects · 14:26
This is not a switch. Ingest, tagging and proxies have no network call in their path, so there is nothing here to turn on. Footage leaves only as a delivery the studio writes to a drive.
Today's network logWed 16/09/2026
TimeEventWent toOut
06:00Update check-inUpdate channel1.4 KB
08:57Ingest card A014 · 12 clipsNo network0 B
09:00Update check-inUpdate channel1.4 KB
09:31Proxy jobs A014 · 12 queuedNo network0 B
10:12Ingest card B014 · 9 clipsNo network0 B
11:40Tagged 12 clips · A014No network0 B
12:00Update check-inUpdate channel1.4 KB
13:18Catalogue search · Circle takeNo network0 B
14:26Delivery LowTide_D14_SelectsDrive E:0 B
15:00Update check-inUpdate channel1.4 KB
16:05Proxy jobs B014 · 9 queuedNo network0 B
16:41Proxy render B014_C001No network0 B
Footage bytes sent0 BMetadata5.6 KB
Proxies12 of 211 rendering8 queuedMEDIA-01 (M:)1.84 TB free of 4 TBCatalogue38,412 clips · localSent today0 B footage
On screen

What is allowed to leave this workstation, step by step: ingest, catalogue, tagging and proxies have no network path, delivery goes only to a drive, and update check-ins carry build metadata. Beside it, the day's network log showing no footage sent.

Rushbay
The Low TideProxy queue
No network in the path EDIT-07 · Windows 11
Proxy queueFFmpeg on EDIT-07 · ProRes Proxy · 1920×1080 · written beside the originals1 rendering8 queued12 done todayPause queue
00:01:06:00
Rendering nowScene 41 · take 2 · camera B
B014_C001ProRes 4444 XQ · 4.5K ProRes Proxy · 1920×1080
61%
Frame 966 of 1,584 M:\LowTide\Day14\B014\Proxy\B014_C001.mov
Yielding to the editing suite
The suite has the foreground, so the queue holds 4 of 16 cores. With the suite idle it takes 12.
Proxy queue Suite and systemIllustrative split
#ClipSc / tkDurationSourceProxyOutput folderState
1B014_C00141 / 200:01:06:0013.99 GB370 MB…\Day14\B014\Proxy\Rendering
2B014_C00242 / 100:01:52:0023.74 GB627 MB…\Day14\B014\Proxy\Queued
3B014_C00342 / 300:00:41:008.69 GB230 MB…\Day14\B014\Proxy\Queued
4B014_C00443 / 100:01:33:0019.72 GB521 MB…\Day14\B014\Proxy\Queued
5B014_C00543 / 300:00:58:0012.30 GB325 MB…\Day14\B014\Proxy\Queued
6B014_C00644 / 200:02:07:0026.92 GB711 MB…\Day14\B014\Proxy\Queued
7B014_C00744 / 300:00:34:007.21 GB190 MB…\Day14\B014\Proxy\Queued
8B014_C00845 / 100:01:20:0016.96 GB448 MB…\Day14\B014\Proxy\Queued
9B014_C00945 / 200:01:41:0021.41 GB566 MB…\Day14\B014\Proxy\Queued
12 proxies from card A014 already on disk, in the folder structure the editing suite expects No transcode farm, no round trip
Proxies12 of 211 rendering8 queuedMEDIA-01 (M:)1.84 TB free of 4 TBCatalogue38,412 clips · localSent today0 B footage
On screen

Eight proxy jobs queued and one rendering, all on the editor's own machine: FFmpeg writing the proxy beside the original, and the queue holding back cores while the editing suite has the foreground.

02

Editing proxies locally

Proxies generated on the workstation, so an editor can start work before anything is uploaded.

FFmpeg generates edit-ready proxies on the workstation, using its available cores with a job queue that yields to the foreground so the machine stays usable while a card ingests. Proxies are written beside the originals in the structure the NLE expects, so an editor can cut immediately, with no transcode farm and no round trip.

What shipped
  • FFmpeg proxies generated locally on a yielding job queue
  • Machine stays usable while a card ingests
  • Written in the structure the NLE expects: cut immediately
Rushbay
The Low TideUpdates
No network in the path EDIT-07 · Windows 11
Update channelStable · 3.4.2 released 14/09/2026 · one codebase, two platformsAll workstations currentStage next build
Current build18 of 18every workstation on 3.4.2
Windows11signed installer
macOS7notarised app
Last check-ins15:00from the channel itself
WorkstationRolePlatformBuildSeen
EDIT-01EditorWindows · signed3.4.215:00
EDIT-02EditorWindows · signed3.4.215:00
EDIT-03EditorWindows · signed3.4.215:01
EDIT-04EditorWindows · signed3.4.215:00
EDIT-05EditorWindows · signed3.4.214:59
EDIT-06EditorWindows · signed3.4.215:00
EDIT-07Editor · this machineWindows · signed3.4.215:00
EDIT-08EditorWindows · signed3.4.215:02
EDIT-09EditorWindows · signed3.4.215:00
ASSIST-01Assistant editorWindows · signed3.4.215:00
ASSIST-02Assistant editorWindows · signed3.4.215:01
EDIT-10EditormacOS · notarised3.4.215:00
EDIT-11EditormacOS · notarised3.4.215:00
EDIT-12EditormacOS · notarised3.4.215:01
COLOUR-01ColouristmacOS · notarised3.4.215:00
COLOUR-02ColouristmacOS · notarised3.4.215:00
CONFORM-01ConformmacOS · notarised3.4.214:58
VFX-01VFX prepmacOS · notarised3.4.215:00
ReleasesBoth platforms, same day
3.4.2Proxy queue hands cores back as soon as the editing suite takes focus14/09/2026 · Windows signed · macOS notarisedCurrent
3.4.1Tag vocabulary counts update while a card is still ingesting02/09/2026 · Windows signed · macOS notarised
3.4.0Delivery packages list what was deliberately left out25/08/2026 · Windows signed · macOS notarised
3.3.0Proxies written beside originals in the suite's folder structure04/08/2026 · Windows signed · macOS notarised
0.9.2Channel test: rollback drill, no functional change12/06/2026 · Windows signed · macOS notarisedTest
0.9.1Channel test: trivial release, no functional change05/06/2026 · Windows signed · macOS notarisedTest
Where the platforms differ3 modules
ModuleWindowsmacOS
File pathsM:\LowTide\Day14/Volumes/MEDIA-01/LowTide/Day14
Media stackFFmpeg · Windows buildFFmpeg · macOS build
Update channelSigned installerNotarised app
Proxies12 of 211 rendering8 queuedMEDIA-01 (M:)1.84 TB free of 4 TBCatalogue38,412 clips · localSent today0 B footage
03

Cross-platform parity

On screen

The update channel: eighteen workstations current, signed on Windows and notarized on macOS, releases shipped to both platforms together (including the early trivial test releases), and the three modules where the platforms differ.

Signed installers for Windows and macOS from one codebase, behaving the same on both.

One codebase produces signed Windows and notarized macOS builds, with the platform differences confined to file paths, the media stack and the update channel. Nothing else in the application knows which platform it's on. Both were tested on the studio's actual hardware, because parity claimed from a CI matrix and parity observed on a colorist's workstation are different claims.

What shipped
  • One codebase; platform differences confined to three modules
  • Signed Windows and notarized macOS builds
  • Parity verified on the studio's own workstations
Introduction

What we were brought in to do

Editors were uploading raw client footage to a web tool for organizing and proxy generation before every project could even start, which was slow and made clients understandably nervous about unreleased footage sitting on a server.

A post-production studio whose projects began with an upload: raw camera cards to a web tool that organized, tagged and transcoded them. On a feature-length shoot that upload ran for most of a working day before an editor could open anything. Two clients had contracts that prohibited footage leaving studio machines before delivery, which made the existing workflow worse than slow for them. It was unusable.

Desktop Engineering

Where the old way broke

  1. 01

    Raw footage files were large enough that uploads ate hours of a project's timeline, and several clients' contracts explicitly prohibited footage leaving the studio's own machines before delivery.

    The upload wasn't overhead around the work; it was shaping the work. Editors batched card ingests to overnight, which meant a shoot that wrapped at six wasn't cuttable until the following afternoon, and a re-shoot discovered on day two cost another cycle. The confidentiality clause turned the same delay into a hard block for the studio's two largest clients.

    We built a native desktop tool that organizes, tags, and generates editing proxies entirely on-device, packaged as signed installers for Windows and macOS with an auto-update channel, so nothing leaves the editor's machine until the studio chooses to deliver it.

What we built together

  • Scoped which processing steps genuinely needed to run on-device and which could go to the cloud

    Each processing step was assessed for whether it genuinely needed a machine the studio didn't own, and in this workflow none of them did.

  • Built local proxy generation and tagging with no network dependency

    Proxies are generated on the workstation by FFmpeg on a job queue that yields to the foreground, written in the structure the editing suite expects.

  • Packaged signed, notarized installers for Windows and macOS

    Notarization was set up in week two, not at the end, because Apple's review timing is unpredictable and it's the one step that can't be hurried.

  • Set up an auto-update channel so every workstation stays current

    The update channel keeps every workstation current, tested by shipping deliberately trivial releases before anything important depended on it.

Process

Phase by phase

  1. Phase 1: Draw the line

    On-device versus cloud

    Scoped which processing genuinely had to run locally for confidentiality, and which could be optional.

    • Processing matrix
    • Confidentiality boundary
  2. Phase 2: Build local

    Proxies and tagging offline

    Built proxy generation and tagging with no network calls in the path.

    • Proxy pipeline
    • Tagging model
  3. Phase 3: Package

    Two platforms, one behaviour

    Packaged signed, notarized installers for Windows and macOS and reconciled the platform differences.

    • Signed installers
    • Platform parity notes
  4. Phase 4: Update

    Keeping suites current

    Set up an auto-update channel so every workstation stays on the current build.

    • Update channel
    • Rollback procedure
Rushbay
The Low TideDay 14Tags
No network in the path EDIT-07 · Windows 11
Tagging · Day 14 · Card A01412 clips · written to C:\Rushbay\catalogue.sqlite as you tagCircle tApply to 1 clip
ClipSc / tkDurationTagsProxy
A014_C00141 / 100:00:38:00Harbour extWideProxy on disk
A014_C00241 / 200:01:11:00Harbour extWideCircle takeProxy on disk
A014_C00342 / 100:02:14:00Harbour extWideCircle takeProxy on disk
A014_C00442 / 200:01:36:00Harbour extClose-upFocus softProxy on disk
A014_C00542 / 300:00:52:00Harbour extClose-upCircle takeProxy on disk
A014_C00643 / 100:01:58:00Kitchen intWideProxy on disk
A014_C00743 / 200:00:44:00Kitchen intWideSound issueProxy on disk
A014_C00843 / 300:01:27:00Kitchen intClose-upCircle takeProxy on disk
A014_C00944 / 100:01:03:00Lane extInsertProxy on disk
A014_C01044 / 200:02:29:00Lane extWideCircle takeVFX plateProxy on disk
A014_C01144 / 300:00:29:00Lane extInsertPick-upProxy on disk
A014_C01245 / 100:01:15:00Harbour extWideCircle takeProxy on disk
Bin vocabulary · Day 14counts across all 21 clips on both cards Local catalogue
SelectsCircle take6Pick-up2VFX plate2
ShotWide8Close-up8Insert5
LocationHarbour ext11Kitchen int5Lane ext5
NotesFocus soft1Sound issue1
Proxies12 of 211 rendering8 queuedMEDIA-01 (M:)1.84 TB free of 4 TBCatalogue38,412 clips · localSent today0 B footage
On screen

Tagging a day's clips: card A014's twelve takes with their tags, one clip selected, and the bin's whole tag vocabulary with its counts underneath, all written to the local catalog.

Operational results after launch

−4 hrs avg

Project start time

0

Footage leaving studio machines pre-delivery

100%

Editor workstations covered

Project start time is the change in elapsed time from card insertion to an editor opening a cuttable timeline, averaged across the first quarter's projects. Footage leaving studio machines is a policy claim, not a measurement: there's no network path in the tool for it to leave by. Workstation coverage is from the update channel's own check-ins.

Client name withheld under NDA. Figures are approximate, drawn from the engagement’s own reporting.

About our collaboration

A cross-functional team of 3 worked on a fixed price basis over 8 weeks, covering Desktop app build, Local processing pipeline, Signed installer. We ran two-week increments, each one shippable, reviewed with them before it merged. Decisions were recorded as they were made, so the reasoning survived the people who made it.

Eight weeks, fixed price, and the first decision was which steps genuinely needed a machine the studio didn't own. In this workflow, the answer turned out to be none of them. Builds were tested on the studio's own colorist and editor workstations as well as CI, because parity claimed from a build log and parity observed on a real machine are different claims.

What it settled

What we'd carry into the next one

The confidentiality requirement decided the architecture. It was never a feature layered on top.

The contract clause wasn't a constraint on the design; it was the design. Any architecture with an upload in it fails the requirement, however fast the upload is.

Local proxy generation removed the upload wait that had been shaping the whole edit workflow.

Removing the wait changed the schedule more than the stopwatch: editors stopped batching ingests overnight, which is where the four hours actually came from.

One codebase across both platforms only held up because the platform differences were reconciled deliberately.

One codebase held because the differences were named and confined to three modules. Treating them as incidental is how cross-platform desktop tools usually diverge.

One clip, four stages

From camera card to delivery drive, the network lane reads zero.

Follow A014_C003, a harbor wide from day fourteen, through ingest, proxy render, tagging and export on one editor's workstation. Each stage lights what it writes to. Switch tabs, or use the arrow keys once one is focused.

The card is read on the editor's own workstation and the clip is copied to its media volume. The catalog that makes it searchable is a SQLite file on the same machine.

EDIT-07 · the editor’s workstation
Camera card A014card reader
MEDIA-01 (M:)A014_C003.mov
Proxy folder…\A014\Proxy\
Local cataloguecatalogue.sqlite
DELIVERY-SSD-03 (E:)attached by the studio
Networkfootage sent this stage0 B
  1. Card A014 mounted on EDIT-07
  2. Copy A014_C003 to MEDIA-01 (M:)
  3. Add it to the local catalogue
A014_C003 · after this stage
fromCard A014 · camera A
written toM:\LowTide\Day14\A014\A014_C003.mov
size28.41 GB
catalogue1 row added · local file
Stayed on this workstation · network 0 B

Why the lane stays at zero: no stage has a network call in its path, so there is no upload to make faster or to switch off. Step timing in the replay is illustrative.

Architecture

From camera card to delivery, on one machine

Electron, React and TypeScript around FFmpeg and SQLite. Four stages run on the editor’s workstation with no network dependency; the fifth is the studio’s own decision to deliver.

  1. 01 · Source
    Camera card on the workstationRaw footage is read where the editor sits. There is no upload step before a project can start.
  2. 02 · Ingest
    Organised and tagged on-deviceIngest and tagging run on the workstation with no network call in the path.
  3. 03 · Engine
    FFmpeg proxy job queueProxies render locally on a queue that yields to the foreground, written in the structure the NLE expects.
  4. 04 · State
    Local SQLite catalogueSearch over tens of thousands of clips is instant and doesn't depend on anyone's connection.
  5. 05 · Delivery
    Delivered when the studio choosesNothing leaves the editor's machine until the studio decides to deliver it.
On the workstation, no network in the path Leaves only when the studio delivers

Unreleased footage, under contract

The confidentiality clause decided the architecture

No path for footage to leave by

Ingest, tagging and proxy generation run on the workstation with no network call in the path. Zero footage leaving studio machines before delivery is a property of the design, not a setting someone could change.

Delivery is the studio's decision

Nothing leaves the editor's machine until the studio chooses to deliver it. Any architecture with an upload in it would have failed the contract clause, however fast the upload was.

Signed builds, every workstation current

Signed Windows and notarized macOS installers from one codebase, on an auto-update channel with a rollback procedure. Coverage is read from the channel's own check-ins.

Need a desktop tool for files that contractually can’t leave the building? Scope your build in 3 minutes.

Scope your build
Have a project?

Let's talk

Running a large platform, shaping a first MVP, or getting a product ready for a funding round? Tell us where you are. We'll shape the process around it, and stay with you after launch.