This product has charges associated with it for hardening, security configuration, and support.
Paperless-ngx is an open-source document management system that scans, OCRs, and archives your documents. This Lynxroute build is security baked in: Nginx TLS reverse proxy, admin credentials generated at first boot, PostgreSQL and Redis bound to localhost only, and CIS Level 1 hardened Ubuntu 24.04 LTS base.
GPL-3.0 license - fully auditable, no vendor lock-in.
This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.
WHAT IS PAPERLESS-NGX
Paperless-ngx is a self-hosted document management system that scans, OCRs and archives your paper trail into a fully searchable digital archive - a Django web application with a Celery worker for background OCR jobs, Redis for the task queue, and Tika + Gotenberg sidecars for parsing complex office documents. Documents are auto-classified into correspondents, document types and tags via a trainable Bayesian model; full-text search runs over the OCR output. The consume folder accepts uploads via the web UI, REST API, drag-and-drop, IMAP email ingestion and rsync drop. Persists documents, metadata and the search index in PostgreSQL with originals on the local filesystem. GPL-3.0 license - community-maintained fork of the original paperless project, no commercial vendor and no lock-in.
WHAT THIS AMI ADDS
Security hardening:
Admin credentials generated at first boot - unique per instance
Nginx reverse proxy with TLS - granian ASGI server bound to localhost only
PostgreSQL and Redis bound to 127.0.0.1 - no external DB exposure
UFW firewall - ports 22, 80, 443 only
fail2ban, IMDSv2 enforced
CVE scan - every image is scanned for vulnerabilities before release
OS hardening (CIS Level 1):
CIS Ubuntu 24.04 LTS Level 1 benchmark applied via ansible-lockdown
auditd, SSH hardening, kernel hardening
Compliance artifacts:
SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
CIS Conformance Report at /etc/lynxroute/cis-report.html
CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
Highlights
Paperless-ngx secure by default: Nginx TLS proxy, admin credentials unique per instance, PostgreSQL and Redis localhost-only - unlike bare deployments that expose the database to the network.
CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.
Full document management stack: OCR with Tesseract, Django web UI, Celery async processing, PostgreSQL storage. GPL-3.0 license - free and open-source forever.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Paperless-ngx - Hardened Document Management with OCR
You pay by the hour based on the EC2 instance size you launch. Five options let you match compute capacity to your workload. The t3.small, t3.medium, and t3.large run on burstable instances that suit lighter or variable use. The m6i.large and m6i.xlarge use general-purpose instances for steadier, heavier processing. Larger instances carry higher hourly rates. All five deliver the same hardened document management software; only the underlying compute size and hourly price change. You add standard AWS infrastructure charges separately.
Top-of-mind questions for buyers
What does the hourly rate cover, and what other charges should I expect?
The hourly rate covers the Paperless-ngx software image, hardened to CIS Level 1 with OCR document management. You pay standard AWS infrastructure charges separately, including compute, storage, and data transfer. All billing runs through AWS Marketplace; the vendor does not process payments.
Am I charged when the instance is stopped?
Software charges meter running instance-hours. A fully stopped instance stops accruing hourly software charges. You may still pay AWS storage fees for attached volumes while the instance is stopped. Charges resume when you start the instance again.
Should I pick a t3 or an m6i instance for my workload?
The t3.small, t3.medium, and t3.large are burstable instances built for lighter or variable document processing. The m6i.large and m6i.xlarge are general-purpose instances for steadier, heavier OCR and indexing loads. All five run the same software; you match the size to your expected activity.
lynxroute.com
Helpful?
Vendor refund policy
We do not offer refunds for this product. If you experience technical issues, please contact us at https://lynxroute.com before requesting a refund.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Paperless-ngx v3.0.2
Updated to Paperless-ngx 3.0.2 (patch on the 3.0.0 major release; fixes a broken 3.0.1 database migration - built fresh, so migrations run clean)
New Tantivy full-text search backend replaces Whoosh - faster indexing and search
Optional AI / LLM / semantic-search features are included but shipped DISABLED by default - no model downloads and no external calls; opt in with PAPERLESS_AI_ENABLED
Document checksums now use SHA256
Legacy API v1 removed - use API v2 or later
Certbot pre-installed - enable HTTPS with one command: sudo certbot --nginx -d yourdomain.com
Rebuilt on the latest CIS Level 1 hardened Ubuntu 24.04 LTS base
Additional details
Usage instructions
Launch instance (t3.medium recommended for OCR workloads)
Open Security Group - allow TCP 443 and TCP 80 from your IP
Wait 5-10 minutes after first launch for first-boot setup to complete
Open https://<PUBLIC_IP> - accept the self-signed certificate warning
Log in with credentials from the credentials file
The startup page auto-refreshes every 15 seconds while first-boot is running.
Credentials are saved to /root/paperless-ngx-credentials.txt at first boot.
Replace the self-signed TLS certificate with a CA-signed certificate for production use.
To ingest documents:
Upload via the web UI
Drop files into /opt/paperless-ngx/consume/ on the instance
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for Websoft9 support. Pre-configured, web-based, cloud-native, secure, one-click to deploy Websoft9 Applications Hosting Platform on AWS. Websoft9 is a lightweight, self-hosting PaaS that allows you to deploy multiple applications on your own cloud infrastructure.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.