# What External Services Does IPED Depend On?

> Discover IPED's external service dependencies. Learn how IPED's offline-first design keeps external services optional and disabled by default for enhanced security.

- Repository: [Serviço de Perícias em Informática/IPED](https://github.com/sepinf-inc/IPED)
- Tags: internals
- Published: 2026-03-11

---

**IPED functions as an offline-first forensic platform where every external service—from Discord API calls to remote processing endpoints—remains strictly optional and disabled by default.**

The sepinf-inc/IPED repository hosts a digital forensics engine designed to process evidence without mandatory internet connectivity. While the core analysis pipeline operates entirely on local resources, the platform can optionally reach out to web services for report enrichment or distributed computing. Understanding these external dependencies allows examiners to deploy IPED in secure air-gapped environments while selectively enabling cloud features only when required.

## Discord API and CDN Integration

When analyzing Discord exports, IPED can contact Discord's REST API to resolve user metadata for HTML report generation. The [`DiscordParser.java`](https://github.com/sepinf-inc/IPED/blob/main/DiscordParser.java) class constructs a request to `https://discord.com/api/v9/users/@me` to fetch the current user's profile identifier.

```java
// DiscordParser.java executes this request during parsing
private static final String ME_URL = "https://discord.com/api/v9/users/@me";

```

This call occurs at line 84 of [`iped-parsers/iped-parsers-impl/src/main/java/iped/parsers/discord/DiscordParser.java`](https://github.com/sepinf-inc/IPED/blob/main/iped-parsers/iped-parsers-impl/src/main/java/iped/parsers/discord/DiscordParser.java). Following metadata retrieval, the parser builds avatar URLs pointing to **Discord CDN** endpoints:

```java
// Avatar URL construction for the HTML report
String avatarUrl = "https://cdn.discordapp.com/avatars/" + userId + "/" + avatarHash + ".png";

```

The avatar download logic resides at line 226 of the same file.

## Mapping and Geolocation Services

IPED supports interactive map rendering through two optional providers, configured via the graphical interface.

### Google Maps JavaScript API

To enable Google Maps visualization, users must supply an API key in the IPED UI. The [`MapCanvasOpenStreet.java`](https://github.com/sepinf-inc/IPED/blob/main/MapCanvasOpenStreet.java) class injects this key into the map initialization script at line 257:

```java
html = html.replace("{{googlemaps_scripts}}",
    "<script id=\"mapsapi\" src=\"https://maps.googleapis.com/maps/api/js?key=" + apikey + "\" async defer></script>\n"
    + "<script src=\"https://unpkg.com/leaflet.gridlayer.googlemutant@latest/dist/Leaflet.GoogleMutant.js\"></script>");

```

### OpenStreetMap Tile Server

When the Google Maps option is disabled, IPED falls back to **OpenStreetMap** tile servers. The [`JMapOptionsPane.java`](https://github.com/sepinf-inc/IPED/blob/main/JMapOptionsPane.java) file defines the default tile URL at line 50:

```

https://tile.openstreetmap.org/{z}/{x}/{y}.png

```

## Remote Processing Endpoints

For compute-intensive tasks, IPED can offload processing to user-defined HTTP services rather than consuming local resources.

### Remote Image Classification

The [`RemoteImageClassifierTask.java`](https://github.com/sepinf-inc/IPED/blob/main/RemoteImageClassifierTask.java) component sends image data to a configurable remote endpoint. When enabled, the task constructs POST requests to user-specified hosts:

```java
// URLs built from the GUI configuration
urlZip = "https://" + config.getUrl() + "/zip";
urlVersion = "https://" + config.getUrl() + "/version";

```

This implementation at line 268 of [`iped-engine/src/main/java/iped/engine/task/RemoteImageClassifierTask.java`](https://github.com/sepinf-inc/IPED/blob/main/iped-engine/src/main/java/iped/engine/task/RemoteImageClassifierTask.java) requires explicit activation through **Menu → Options → Remote Image Classifier**.

### Remote Speech-to-Text Transcription

Similarly, audio transcription can delegate to external services via [`RemoteTranscriptionService.java`](https://github.com/sepinf-inc/IPED/blob/main/RemoteTranscriptionService.java). Located at line 40 of [`iped-engine/src/main/java/iped/engine/task/transcript/RemoteTranscriptionService.java`](https://github.com/sepinf-inc/IPED/blob/main/iped-engine/src/main/java/iped/engine/task/transcript/RemoteTranscriptionService.java), this class manages HTTP communication with remote transcription servers configured under **Menu → Options → Remote Transcription**.

## Report Rendering CDN Dependencies

Discord HTML reports incorporate animated elements via the **Lottie-player library** loaded from a CDN. The [`DiscordHTMLReport.java`](https://github.com/sepinf-inc/IPED/blob/main/DiscordHTMLReport.java) class includes this dependency at line 84:

```java
// Script tag generation for Lottie animations
"https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js"

```

This external reference only affects report aesthetics and does not impact forensic processing.

## Test-Only Network References

Certain test utilities access external repositories for build dependencies. The [`RepoToolDownloader.java`](https://github.com/sepinf-inc/IPED/blob/main/RepoToolDownloader.java) test class downloads Maven artifacts from GitHub or GitLab URLs during unit test execution. These calls occur exclusively in the test suite and do not influence normal case analysis or the runtime behavior of the forensic engine.

## Summary

- **Core functionality requires no internet**: The IPED analysis engine processes all evidence formats without external connectivity.
- **Discord integration**: Optional API calls to `discord.com` and CDN fetches from `cdn.discordapp.com` occur only when parsing Discord exports.
- **Mapping flexibility**: Users choose between Google Maps (requires API key) or OpenStreetMap tiles, or disable maps entirely.
- **Configurable remote processing**: Image classification and transcription services only activate when administrators explicitly set remote endpoints in the GUI.
- **Test isolation**: Network calls in [`RepoToolDownloader.java`](https://github.com/sepinf-inc/IPED/blob/main/RepoToolDownloader.java) remain confined to the testing framework.

## Frequently Asked Questions

### Can IPED run completely offline?

Yes. The forensic analysis engine operates entirely on local resources. All external service calls—including Discord API lookups, mapping tiles, and remote processing—are opt-in features disabled by default. You can process cases, generate reports, and perform indexing without any network connectivity.

### Is Discord data extraction mandatory when parsing Discord exports?

No. While [`DiscordParser.java`](https://github.com/sepinf-inc/IPED/blob/main/DiscordParser.java) contains code to query the Discord API and fetch avatars from the Discord CDN, these calls enhance report aesthetics rather than extract evidence. If the workstation lacks internet access, the parser continues processing chat data normally, simply omitting the user's avatar and display name resolution.

### How do I configure remote image classification?

Navigate to **Menu → Options → Remote Image Classifier** in the IPED GUI. Enter the HTTPS URL of your compatible classification service (e.g., `https://classifier.example.com`). The `RemoteImageClassifierTask` will then POST image data to `https://<host>/zip` and check service availability at `https://<host>/version` before processing begins.

### Are there privacy concerns with the mapping services?

Only if enabled. **Google Maps** requires an API key tied to your Google account and sends geolocation coordinates to Google's servers. **OpenStreetMap** tile requests expose approximate geographic regions to the tile server operators. For sensitive cases, disable both options in `JMapOptionsPane` to keep geolocation data strictly local.