Drop files once. Clean items run to verified delivery; only exceptions ask for you.
Turn repetitive delivery checks into one Assurance Run: drop files once, automate checks and secure reconstruction, review only exceptions, then deliver verified outputs with reusable evidence.
Drop → Auto-check → Exception review → Secure rebuild → Re-verify → Deliver → Reuse
The primary path is for people repeatedly preparing many final PDFs. PDF contents are not uploaded to FileNest servers for these steps; the browser downloads a pinned PDF runtime as needed and processes files locally. FileNest never treats 'scanner found nothing' as absolute safety and never auto-deletes suspected sensitive content.
FileNest runs privacy candidate scan → authorized rule handling → secure reconstruction → post-generation risk verification → PDF SHA-256 → processing-receipt SHA-256 for each file. It pauses only for uncovered exceptions; with automatic delivery enabled, it continues to the selected delivery destination after every file is verified. Keep this page open while the browser-local run is active.
Save the current Assurance policy as a purpose-named routine. Purpose labels organize, select and identify batch evidence; they never silently change redaction rules. A default routine automatically reloads its processing and delivery mode so repeated work can start by dropping files.
Only processing preferences and a local delivery-destination reference are reusable; source files, scanned content and directory paths are never stored. Auto-redaction and auto-delivery are off by default and must be explicitly enabled; policy locks when a batch starts.
Browser ZIP has the broadest compatibility. Browsers with File System Access can authorize a local folder once so later default runs write the complete assured delivery ZIP and delivery manifest directly after full verification. The ZIP still contains each final PDF and its receipt. Directory paths are never stored in routine JSON or manifests.
Use the detailed workspace when you have original/revised versions or need manual redaction regions.
This keeps the proven text + visible-pixel comparison, explicit human review, privacy candidate decisions, manual regions, secure reconstruction, SHA-256 receipt and post-delivery verification. It remains the deep tool behind Assurance Run rather than the mandatory path for every routine batch.
Used as the older version for comparison, or alone for privacy cleanup.
When a revised file is added, every detected change must be reviewed before assured delivery can continue.
Checks text, page dimensions and visible pixels, not just file size or hashes.
Automatic candidates are suggestions only. Every candidate requires an explicit Redact or Keep decision.
The final PDF is rendered and rebuilt page by page. Original text objects, scripts, attachments, annotations, forms and hidden layers are not copied into the delivery PDF.
Delivery is not the end. ZIP and Trusted Folder deliveries both have recipient-side verification paths.
ZIP delivery can start with a detached whole-pack SHA-256 seal, then verify capacity, CRC32, the manifest, PDFs and processing receipts. Trusted Folder delivery needs no repackaging: recipients can directly verify the completion marker, deterministic folder ledger, original relative paths, per-file exact bytes and SHA-256 values, then cross-check the manifest, PDFs, receipts and page-reviewability evidence.
The final delivery copy prioritizes safety instead of pretending to remain an editable original.
Secure reconstruction renders every page and builds a new PDF, so selectable source text, scripts, attachments, annotations, forms and hidden layers are not directly copied into the delivery file. Keep the original for future editing. Risk scanning supports delivery triage and verification; it is not malware detection, legal certification or compliance certification. The batch evidence manifest is workflow evidence, not a digital signature.