Local browser work where the destination and every crossing must be inspectable.
Product mode
Pack / local utility
Operational confidence through explicit local custody and permission scope.
Sequential custody proof · LocalArtifactFlow with receiptCharacter and boundary
Trace custody from the portal response to a user-controlled file.
Credentials, session cookies, and downloaded files do not transfer to ComplyEaze.
Dominant synthetic proof object
- 01
GST Portal session
The user signs in and opens a supported filed return on the government portal.
Credentials remain on GST Portal- Custodian / location
- User in the GST Portal browser tab
- Data / action
- Credentials and the selected filed-return request
- Crosses
- The request and response stay within the portal session
- Never crosses
- Credentials or session cookies to ComplyEaze
- Source
- Current supported GST Portal page
- Result
- Supported portal response ready for the browser action
- 02
Pack local browser action
The extension initiates the supported download inside the user's browser session.
Session and cookies are not handed to ComplyEaze- Custodian / location
- User's browser and local Pack extension
- Data / action
- Supported portal response and local download instruction
- Crosses
- A supported request goes only to the GST Portal destination
- Never crosses
- Session cookies, credentials, or file content to ComplyEaze
- Source
- Public Pack source and the active portal response
- Result
- Browser-managed download begins
- 03
Chrome Downloads
The browser saves the returned file into the user's Downloads on this device.
File remains user-controlled and local- Custodian / location
- User on this device in Chrome Downloads
- Data / action
- The supported filed-return artifact
- Crosses
- The file moves from the portal response into local Downloads
- Never crosses
- The downloaded file to ComplyEaze
- Source
- Browser download receipt and public Pack release evidence
- Result
- User-controlled local file
- State
- Local only · destination: user-controlled Chrome Downloads · no handoff to ComplyEaze
- Current custodian
- User on this device
- What moves
- Supported portal response into Chrome Downloads
- What never moves
- Credentials, session cookies, or downloaded file to ComplyEaze
- Credentials / session
- Remain in the GST Portal browser session
- Local destination
- User-controlled Chrome Downloads
- Source / release
- Public source and selected release remain inspectable
- User control
- User chooses permission, destination, and later file handling
- Claim
- Supported portal response to a local file
- Source / release
- Repository: public Pack source · release artifact selected by consumer
- Status / checked
- Current synthetic reference · 14 July 2026 · package validator
- Reference / limitation
- Checksum comes from the selected release artifact; runtime proof is a separate gate
Meaningful edge state
The state remains visible in text, preserves source or fallback, and never advances a consequential action without the named owner.
Relevant package patterns
Confirm custody at each stage before allowing a portal response to become a local artifact.
pack-local-utilityPermissionExplainerUnderstand a permission's purpose, scope, affected data, denial behavior, and fallback before deciding.
pack-local-utilityCustodyBoundaryVerify who controls each sensitive element, what crosses, what never crosses, and how the user retains control.
Use and avoid
Cloud language, workspace assumptions, or hidden file handoffs.