FileNestCalm file work
SECOND ECOSYSTEM · DOCUMENT ASSURANCE

Drop files once. Clean items run to verified delivery; only exceptions ask for you.

Turn repetitive delivery checks into one Assurance Run: drop files once, automate checks and secure reconstruction, review only exceptions, then deliver verified outputs with reusable evidence.

Exception-driven, not button-driven Rebuilt delivery PDF, not black-box overlays Per-file + batch evidence
Open advanced side-by-side compare Verify a single FileNest receipt Verify a complete batch delivery ZIP Verify a Trusted Folder delivery
PRIMARY PATH · ASSURANCE RUN

Drop → Auto-check → Exception review → Secure rebuild → Re-verify → Deliver → Reuse

The primary path is for people repeatedly preparing many final PDFs. PDF contents are not uploaded to FileNest servers for these steps; the browser downloads a pinned PDF runtime as needed and processes files locally. FileNest never treats 'scanner found nothing' as absolute safety and never auto-deletes suspected sensitive content.

Assurance Run · drop once, intervene only on exceptions Delivery only after PDF + receipt SHA-256 binding
1. Drop this batch of final PDFs once

FileNest runs privacy candidate scan → authorized rule handling → secure reconstruction → post-generation risk verification → PDF SHA-256 → processing-receipt SHA-256 for each file. It pauses only for uncovered exceptions; with automatic delivery enabled, it continues to the selected delivery destination after every file is verified. Keep this page open while the browser-local run is active.

constrained device: up to 120 files and 96.0 MB total source bytes per run. Files are processed sequentially; unsafe items are isolated instead of forced through.
Purpose routine library · configure once, reuse

Save the current Assurance policy as a purpose-named routine. Purpose labels organize, select and identify batch evidence; they never silently change redaction rules. A default routine automatically reloads its processing and delivery mode so repeated work can start by dropping files.

No named routines yet. Configure the policy below to a setup you genuinely reuse, then save it here.Up to 8 routines per device. The library stores only names, purpose labels, processing policy, delivery mode and a random destination reference; the actual trusted-folder handle stays separately in this browser's IndexedDB. It never stores directory paths, source files, filenames, candidate text, hashes or delivery packs.
2. Reusable run policy

Only processing preferences and a local delivery-destination reference are reusable; source files, scanned content and directory paths are never stored. Auto-redaction and auto-delivery are off by default and must be explicitly enabled; policy locks when a batch starts.

Auto-redact deterministic candidatesApplies only to built-in categories explicitly detected by the scanner. Custom candidates and unchecked categories always enter exception review and are never auto-deleted.
Browsers may block downloads that were not triggered by a direct click. FileNest therefore prepares the delivery pack, whole-pack SHA-256 and detached seal together in page memory; if the automatic ZIP download is blocked, one click below downloads the same pack without rescanning, rebuilding, repackaging or rehashing. The seal remains a separate explicit download to avoid multi-download blocking.
Delivery destination

Browser ZIP has the broadest compatibility. Browsers with File System Access can authorize a local folder once so later default runs write the complete assured delivery ZIP and delivery manifest directly after full verification. The ZIP still contains each final PDF and its receipt. Directory paths are never stored in routine JSON or manifests.

Current: browser ZIP
Safety boundary: the folder grant stays in this browser's site storage; FileNest does not upload the directory handle, path or file contents. Automatic direct write requires the prior grant to remain granted. If the browser requires renewed permission, the batch falls back instead of opening an unpredictable mid-run permission prompt.
DETAILED MODE · VERSION REVIEW & MANUAL REDACTION

Use the detailed workspace when you have original/revised versions or need manual redaction regions.

This keeps the proven text + visible-pixel comparison, explicit human review, privacy candidate decisions, manual regions, secure reconstruction, SHA-256 receipt and post-delivery verification. It remains the deep tool behind Assurance Run rather than the mandatory path for every routine batch.

Local compare, scan, redact and secure reconstruction SHA-256 processing receipt included
1. Original version

Used as the older version for comparison, or alone for privacy cleanup.

2. Revised version (optional)

When a revised file is added, every detected change must be reviewed before assured delivery can continue.

Stage A · Document Compare & Review

Checks text, page dimensions and visible pixels, not just file size or hashes.

Single-file mode · comparison not required
Stage B · Privacy Scan & Redaction Review

Automatic candidates are suggestions only. Every candidate requires an explicit Redact or Keep decision.

Stage C · Secure Redact, Sanitize & Verify

The final PDF is rendered and rebuilt page by page. Original text objects, scripts, attachments, annotations, forms and hidden layers are not copied into the delivery PDF.

Security tradeoff: this mode prioritizes not carrying original underlying content into the delivery copy. The final PDF does not preserve selectable source text, form behavior, annotations or hidden layers. Keep the original for future editing.
Device safety envelopeCurrent device: constrained. Recommended source working set up to 96.0 MB; compare up to 90 pages; privacy scan up to 120; secure rebuild up to 60 pages. FileNest stops at safety boundaries instead of risking browser crashes or partial output.
POST-DELIVERY BATCH RE-VERIFICATION

Delivery is not the end. ZIP and Trusted Folder deliveries both have recipient-side verification paths.

ZIP delivery can start with a detached whole-pack SHA-256 seal, then verify capacity, CRC32, the manifest, PDFs and processing receipts. Trusted Folder delivery needs no repackaging: recipients can directly verify the completion marker, deterministic folder ledger, original relative paths, per-file exact bytes and SHA-256 values, then cross-check the manifest, PDFs, receipts and page-reviewability evidence.

Open ZIP batch verifier Open Trusted Folder verifier
SECURITY BOUNDARY

The final delivery copy prioritizes safety instead of pretending to remain an editable original.

Secure reconstruction renders every page and builds a new PDF, so selectable source text, scripts, attachments, annotations, forms and hidden layers are not directly copied into the delivery file. Keep the original for future editing. Risk scanning supports delivery triage and verification; it is not malware detection, legal certification or compliance certification. The batch evidence manifest is workflow evidence, not a digital signature.