FileNestCalm file work
TRUST CENTER · MANUALLY REVIEWED AUG 26, 2026

Trust should explain the boundaries, not just say “you’re safe.”

This page explains how FileNest currently handles files, the safeguards we can verify, what is already live, what is still in R&D, and how you can influence the next improvements.

See data handling Security baseline Send feedback
CURRENT PRODUCTION

What is live right now

Only capabilities available on the production site are listed as live. The OCR system under R&D is not counted as a production feature.

Batch rename

Guests can use core batch renaming; accounts and Pro add more advanced rules, templates and history.

Image processing

Conversion, resize, compression and enhancement primarily run in the browser. Image tools currently support up to 50 files per Pro batch after tool-specific capacity testing.

PDF and data

PDF merge/split/images-to-PDF and CSV/TSV/JSON conversion primarily process in the browser.

Duplicate detection

Files are prefiltered by byte size and then compared with browser-computed SHA-256 fingerprints. FileNest does not automatically delete files.

Text to document

Turn entered text into DOCX, PDF, TXT, Markdown or HTML within the current browser workflow.

Current OCR

The production site currently separates transient High Accuracy cloud OCR from Local Privacy OCR. Both require users to review recognition results.

DATA HANDLING MATRIX

Where each workflow runs and whether file content is uploaded

This turns local-first into specific, checkable paths. Account quota, job and billing metadata are different from file contents; local processing does not mean the server has no account-level usage records.

WorkflowProcessing locationIs file content uploaded?What may be stored server-side
Batch renameIn your browserFile contents are not uploadedSigned-in features can save rule templates and account-level quota/job/download metadata; these records are not file copies.
Image convert / resize / compress / enhanceIn your browserSource images are not uploaded for these operationsSigned-in accounts can create quota/job usage metadata; processed images are downloaded on your device.
PDF and CSV / TSV / JSONIn your browserDocument contents are not uploaded for these operationsSigned-in accounts can create quota/job usage metadata; outputs are generated in the current browser workflow.
Duplicate finderIn your browserFile contents are not uploadedByte-size prefiltering and SHA-256 fingerprints are computed on-device. FileNest does not delete files for you.
Text to documentIn your browserEntered text is not uploaded for document generationDOCX / PDF / TXT / Markdown / HTML outputs are generated in the current browser workflow.
OCR · Local PrivacyIn your browserRecognition images are not uploadedThe browser may download OCR language assets on first use; account quota/job metadata may still be recorded.
OCR · High AccuracyTransient cloud processingSelected images are temporarily submitted for recognitionThe production flow states that FileNest does not retain the source image; returned OCR text still requires human review.
Account and billingServer / StripeWork files are not requiredAccount, membership, quota, job and billing state must be stored server-side. Stripe handles full card numbers; FileNest does not store them.
The important exception: High Accuracy OCR temporarily sends selected images to cloud recognition.If an image must not leave the device, use Local Privacy OCR. Neither OCR mode is 100% accurate, so review before export.
HOW FILENEST COMPETES

Not by making the longest feature list

FileNest differentiates through data flow, reviewable results, tested capacity, release gates and a feedback loop rather than unprovable superlatives.

Local-first instead of upload-first

File work that can safely run in the browser stays on-device where practical; cloud-required paths are disclosed separately.

Preview and review before execution

Rename, conversion and OCR workflows prioritize visible results and limits before destructive-looking batch actions are confirmed.

Capacity claims follow validation

Each tool has its own file-size and batch safety cap. Untested numbers do not become marketing promises.

R&D must pass gates before production

The next-generation OCR work is validated for language quality, runtime behavior and stability before it can be presented as a live capability.

Security boundaries are explained

Browser protections, sessions, server authorization, database access boundaries and disclosure routes are published alongside what FileNest does not provide.

User friction feeds the roadmap

Feedback is categorized by feature, workflow, bugs, privacy/security and usability so repeated needs can guide product decisions.

VERIFIABLE SECURITY BASELINE

Turn implemented safeguards into understandable evidence

These are safeguards that can be checked in the current code and deployment, not a claim of absolute security.

Browser response protections

Static and dynamic responses enforce HTTPS, block external framing, disable MIME sniffing and restrict unnecessary browser permissions.

Protected account sessions

Session tokens use HttpOnly cookies; production cookies are Secure and use SameSite controls to reduce cross-site exposure.

Origin checks on sensitive writes

Signup, authenticated mutations, billing and other important write requests validate same-origin context. API responses are not cached.

Server-side entitlement checks

Quota, membership, OCR jobs and billing state are revalidated on the server rather than trusting the browser alone.

Row-level database boundaries

Account, membership, quota, job and download data use Row Level Security. The public client does not bundle service-role or Stripe secrets.

Payments handled by Stripe

FileNest does not store full card numbers. Pro access is granted only after server-confirmed payment state.

Dependency and regression checks

The repository monitors dependency updates and includes automated regression checks for security baselines, access control, OCR and core product behavior.

Responsible disclosure

A public security.txt provides a dedicated route for reporting security issues.

Three things we do not overclaim1. FileNest is not currently ISO 27001 certified, so we do not present it as certified.2. FileNest is not antivirus software and does not claim malware scanning. Local processing, narrow supported formats and non-execution reduce exposure, but do not replace dedicated malware protection.3. No internet service can honestly guarantee it can never be breached. Our approach is to reduce attack surface, validate in layers, keep dependencies current and provide a disclosure route.
Full privacy policy Service transparency security.txt
PUBLIC PROGRESS

Live, R&D and planned work stay clearly separated

The roadmap is not a release-date promise. Work moves to Live only after real testing and production validation pass.

LIVE

Trust center and product feedback

Privacy, security, current capabilities, progress and improvement feedback now share one public home.

LIVE

Local-first file workflows

Batch rename, image, PDF, data, duplicate and text-document tasks continue to prioritize browser-local processing.

R&D

Next-generation FileNest OCR runtime

Research and validation are in progress across multilingual recognition, model/script routing, post-processing, benchmarks and browser runtime evidence. It is not the production OCR engine yet.

PLANNED

Stronger OCR review workspace

The goal is to place source images, recognized text and review-needed areas into one clearer workflow after the underlying OCR passes production gates.

PLANNED

Cross-tool workflows

Gradually connect resize, compression, rename, OCR and document export so users repeat less setup across isolated tools.

RECENT SHIPPED EVIDENCE

Not only a roadmap: show what has already changed in production

These are recent improvements already present in the production product. They show that the release path can turn problems into shipped changes; a specific public request counts as completed only when that wall item is marked Shipped.

SHIPPED

Batch image review surface

Multi-image workflows now use a vertically bounded source queue with shared batch settings, preventing the preview surface from growing without limit.

SHIPPED

Execution preflight

Rename, image, PDF, data and OCR workflows expose result, count, page or phase information before consequential execution so users have fewer blind spots.

SHIPPED

Production-parity release gate

Product QA now builds the actual Cloudflare Pages deployment artifact; Worker size, core regressions and production SEO are checked in the release path.

SHIPPED

Public improvement wall

Feedback can be public, supported by other users and carry Received / Reviewing / Planned / Shipped states so improvement evidence can stay traceable.

WHY THIS IS PUBLIC

Competition is not only about feature count; users also need evidence they can judge

Large file platforms often separate trust centers, status pages, updates and support. At FileNest's current scale, one clear trust hub keeps the evidence easy to find; it can split into dedicated surfaces as the service grows.

USER IMPROVEMENT FEEDBACK

Put real user friction into product decisions instead of guessing

Submit feature requests, workflow friction, bugs, privacy/security suggestions or usability issues. Do not include passwords, card details, identity documents, confidential file contents or other sensitive data.

RECEIVED

Received

Real feedback appears on the public wall when the author chooses public sharing; private feedback stays backend-only.

REVIEWING

Reviewing

Repeated pain points, support count, risk, development cost and impact on core workflows are evaluated together.

PLANNED

Planned

The direction has entered the roadmap, but this is not a release-date promise and validation is not skipped to meet a date.

SHIPPED

Shipped

A public request should be marked Shipped only after the improvement is in production and its relevant regression checks pass.

Product feedbackTell us what should improve next.Submission requires a verified free account and is limited to five messages per account per day. Public posts appear below immediately; account email, user ID and contact permission are never shown on the public wall.
Do not post passwords, payment details, identity documents, private file contents or security-vulnerability details. Use the responsible disclosure route below for security issues.
Email support instead
Public request wall

What people most want FileNest to improve

Support counts help us spot repeated pain points, but do not automatically determine roadmap order.
Loading public feedback…
Found a security vulnerability? Do not place it in product feedback.Use the security contact in security.txt for responsible disclosure, and avoid accessing, downloading or modifying data that is not yours.View security reporting route