This product has charges associated with it for hardening, security configuration, and support.
Paperless-ngx is an open-source document management system that scans, OCRs, and archives your documents. This Lynxroute build is security baked in: Nginx TLS reverse proxy, admin credentials generated at first boot, PostgreSQL and Redis bound to localhost only, and CIS Level 1 hardened Ubuntu 24.04 LTS base.
GPL-3.0 license - fully auditable, no vendor lock-in.
This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.
WHAT IS PAPERLESS-NGX
Paperless-ngx is a self-hosted document management system that scans, OCRs and archives your paper trail into a fully searchable digital archive - a Django web application with a Celery worker for background OCR jobs, Redis for the task queue, and Tika + Gotenberg sidecars for parsing complex office documents. Documents are auto-classified into correspondents, document types and tags via a trainable Bayesian model; full-text search runs over the OCR output. The consume folder accepts uploads via the web UI, REST API, drag-and-drop, IMAP email ingestion and rsync drop. Persists documents, metadata and the search index in PostgreSQL with originals on the local filesystem. GPL-3.0 license - community-maintained fork of the original paperless project, no commercial vendor and no lock-in.
WHAT THIS AMI ADDS
Security hardening:
Admin credentials generated at first boot - unique per instance
Nginx reverse proxy with TLS - granian ASGI server bound to localhost only
PostgreSQL and Redis bound to 127.0.0.1 - no external DB exposure
UFW firewall - ports 22, 80, 443 only
fail2ban, IMDSv2 enforced
CVE scan - every image is scanned for vulnerabilities before release
OS hardening (CIS Level 1):
CIS Ubuntu 24.04 LTS Level 1 benchmark applied via ansible-lockdown
auditd, SSH hardening, kernel hardening
Compliance artifacts:
SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
CIS Conformance Report at /etc/lynxroute/cis-report.html
CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
Highlights
Paperless-ngx secure by default: Nginx TLS proxy, admin credentials unique per instance, PostgreSQL and Redis localhost-only - unlike bare deployments that expose the database to the network.
CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.
Full document management stack: OCR with Tesseract, Django web UI, Celery async processing, PostgreSQL storage. GPL-3.0 license - free and open-source forever.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Paperless-ngx - Hardened Document Management with OCR
You pay by the hour for the software image running on your chosen Amazon EC2 instance size. Five instance options are available. The t3.small, t3.medium, and t3.large run on burstable instances, which suit variable or lighter workloads. The m6i.large and m6i.xlarge run on general-purpose instances built for steadier demand. Pricing scales with the size and capacity of the instance you pick. Each dimension delivers the same hardened, pre-configured document management image; you choose the size that fits your workload. Billing is handled through AWS.
Top-of-mind questions for buyers
What resources do I get with each instance size, and how are the hours counted?
Each dimension maps to one Amazon EC2 instance type. The t3.small, t3.medium, and t3.large are burstable instances that vary in CPU and memory. The m6i.large and m6i.xlarge are general-purpose instances. You are billed per hour the instance runs, tracked by AWS.
Am I charged the software fee when my instance is stopped or powered off?
The hourly software fee meters running time only. A stopped or powered-off instance does not accrue software charges. Note that AWS may still charge for attached storage while the instance is stopped, but that is separate from the software fee.
Is this pay-as-you-go, and can I switch instance sizes as my workload changes?
Yes, billing is usage-based with no upfront commitment. You pay only for the hours each instance runs. To change size, you deploy the image on a different instance type. Your hourly rate then reflects the new size you select.
lynxroute.com
Helpful?
Vendor refund policy
We do not offer refunds for this product. If you experience technical issues, please contact us at https://lynxroute.com before requesting a refund.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Paperless-ngx v3.0.2
Updated to Paperless-ngx 3.0.2 (patch on the 3.0.0 major release; fixes a broken 3.0.1 database migration - built fresh, so migrations run clean)
New Tantivy full-text search backend replaces Whoosh - faster indexing and search
Optional AI / LLM / semantic-search features are included but shipped DISABLED by default - no model downloads and no external calls; opt in with PAPERLESS_AI_ENABLED
Document checksums now use SHA256
Legacy API v1 removed - use API v2 or later
Certbot pre-installed - enable HTTPS with one command: sudo certbot --nginx -d yourdomain.com
Rebuilt on the latest CIS Level 1 hardened Ubuntu 24.04 LTS base
Additional details
Usage instructions
Launch instance (t3.medium recommended for OCR workloads)
Open Security Group - allow TCP 443 and TCP 80 from your IP
Wait 5-10 minutes after first launch for first-boot setup to complete
Open https://<PUBLIC_IP> - accept the self-signed certificate warning
Log in with credentials from the credentials file
The startup page auto-refreshes every 15 seconds while first-boot is running.
Credentials are saved to /root/paperless-ngx-credentials.txt at first boot.
Replace the self-signed TLS certificate with a CA-signed certificate for production use.
To ingest documents:
Upload via the web UI
Drop files into /opt/paperless-ngx/consume/ on the instance
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for Websoft9 support. Pre-configured, web-based, cloud-native, secure, one-click to deploy Websoft9 Applications Hosting Platform on AWS. Websoft9 is a lightweight, self-hosting PaaS that allows you to deploy multiple applications on your own cloud infrastructure.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.