ScopePack
For confidential professional work · Mac · Windows · Linux

Your obligation says these files can't go to the cloud. So they won't.

Privilege-safe

Boutique legal, RIA and financial advisory, accounting, advisory, and due-diligence work runs on documents you're bound to keep confidential. ScopePack turns those files into a source-linked briefing pack on your own machine — with the network off. Nothing reaches a server.

AI-grade document review without breaking the obligation. Not a chatbot, not "secure ChatGPT" — a private briefing-pack generator for client files that must stay in your custody. We never receive your data, so we can't be forced to share it.

No accountNo telemetryClient files never leave your custody
AIR-GAPPED · MATTER: CLIENT ENGAGEMENT FILE ↑ 0 B · ↓ 0 B
engagement_letter.pdf · 12 pages extracted & OCR'dlocal
client_financials.xlsx · 6 statements · correspondence.eml · 58 messageslocal
Timeline + key entities assembled from source pages
Sensitive findings flagged · 3 account numbers, 1 SSN, 5 amountsreview
Safe-to-share export written · nothing left the deviceredacted · 0 B sent

A full client-matter briefing — sources, timeline, entities, sensitive findings, safe export — built end to end at 0 bytes sent.

§ 01 · The whole workflow

Client files in. Safe briefing out. Nothing leaves your custody.

Drop in confidential PDFs, Word and Excel files, emails, scans, and notes. On-device AI and OCR build the briefing while the network stays off. Then you review, redact, and export a clean copy you can circulate.

01
Confidential client files

Drop them in — stored locally, encrypted

PDFs, Word and Excel files, emails, scans, notes. They land in encrypted local storage on your machine and stay there. No upload step, no account, no sync.

02
Local briefing pack

Sources, timeline, entities, sensitive findings

On-device AI and OCR build a complete Sensitive Briefing Pack — every dated event and entity linked back to its source page — with the network off the whole time.

03
Safe-to-share export

Review, redact, circulate

Work the sensitive-findings queue — SSNs, account numbers, amounts — then export a full and a redacted, safe-to-share Markdown briefing for colleagues or clients.

Sourcesextraction notes

Every file reviewed, with extraction notes and quality flags for scans and gaps.

Timelinesource-linked

Dated events pulled from your documents, each linked back to its source page.

Key entitiespeople · orgs · amounts

People, organizations, emails, phones, account and money amounts, and date signals.

Sensitive findingsreview queue

A queue of risky values — SSNs, account numbers, amounts — to redact before anything is shared.

Verification reportaudit-file record

A local-processing record showing what ran on the device and that nothing left it — useful for your audit file.

Safe exportfull + redacted

Full and redacted Markdown exports for internal review and safe sharing with colleagues or clients.

§ 02 · Why local, structurally

The safest client data is the data we never receive.

A hosted AI service copies your client files onto a vendor's servers, where they're subject to breach, retention, and legal process. That isn't a flaw in those tools — it's how any cloud service works, and it's exactly why so many firms forbid them for client data. ScopePack removes that surface entirely.

Cloud AI for client files

  • Client documents are copied onto a vendor's servers
  • Subject to breaches, retention, and legal process at the vendor
  • Adds a third-party data surface to your audit and vendor-risk map
  • The exposure that drives firm-wide bans on ChatGPT for client data
  • If the vendor changes terms or shuts down, you're exposed

ScopePack

  • Client documents stay on your machine, encrypted
  • Nothing is sent — there is no server copy to leak or seize
  • We never receive your data, so we can't be forced to share it
  • You keep custody and control of your own client files
  • If we disappear tomorrow, your installed app keeps working offline
Audit & compliance posture

A hosted AI service creates an external copy of client data subject to breach, retention, and legal process at the vendor. ScopePack removes that surface: your files never reach a server, so there is no vendor-held copy to account for in data-mapping, vendor-risk, or audit work — and because we never receive your data, your documents stay in your custody, with nothing for us to be compelled to hand over.

§ 03 · For firms that drew the line

"We banned ChatGPT for client data." Here's the sanctioned local alternative.

Plenty of firms have already told staff, in writing, not to put client data into cloud AI. That ban is correct — and it leaves a gap. People still need AI-grade help with documents, and pretending they don't just pushes the workaround into the shadows. ScopePack is built to close that gap the right way.

01
It respects the ban

It doesn't break the rule — it honors why it exists

The ban exists to stop client data from reaching a vendor's servers. ScopePack never transmits content, so the reason for the ban simply isn't triggered.

02
Sanction it on evidence

Your IT can clear it before anyone installs

Hand the verifier and egress audit to your IT or compliance reviewer. They can confirm the offline workflow runs at 0 sent / 0 received before anyone installs it.

03
End shadow AI

Remove the incentive to paste into a personal chatbot

Give people a sanctioned tool that actually works offline, and you remove the incentive to paste client text into a personal chatbot to get the job done.

§ 04 · Don't trust us — test us

Privacy your compliance team can verify, not just a promise

Don't ask anyone to trust a claim — give them a test they can run. The runtime test is enough for most people; reviewers and IT teams can go two layers deeper.

Run it with the network off0 sent · 0 received

Enable airplane mode or block the app with a firewall. Every core feature still works, and the counter stays at 0 — a test your IT team can repeat.

Read the egress auditone code path

A published audit shows there is exactly one network code path — the optional model download — and it's off by default. Share it with vendor risk.

Run the public verifierMIT-licensed

An open MIT-licensed tool checks release signatures, hashes, and that the offline workflow runs with no connectivity.

No surveillance business model

We make money when you buy a license — full stop. We never see your documents, so we could never sell, mine, or be compelled to disclose them. The absence of that incentive is the entire point.

§ 05 · Who's behind this

Built for the people who handle the most sensitive files

I built ScopePack because in January 2026 a court ordered an AI company to hand over millions of private conversations — and its own CEO admitted there's no legal confidentiality when you use the cloud. The people I know who handle the most sensitive client files had nowhere to turn.

So I built the tool I'd trust myself: one that never sees your data, can't be forced to share it, and lets you prove all of that for yourself.

— Founder, NextAI Forge, LLC · Read the full story →

§ 06 · Straight answers for confidential work

Questions from privilege- and compliance-bound work

Q1Does using ScopePack put privilege or confidentiality at risk?+

ScopePack is built to keep your files in your custody. Documents stay in encrypted local storage on your machine and are never transmitted to us or any third party — so you're not introducing the third-party exposure that comes with pasting content into a hosted AI service. It's a private workspace and operator aid, not legal advice; you remain responsible for how you handle privileged material.

Q2How do I prove to my compliance team that it's actually local?+

Give them a test, not a claim. Put the machine in airplane mode or block the app with a firewall, then run a full briefing — it works, and the counter stays at 0 sent / 0 received. We also publish an egress audit and a public verifier so a reviewer or IT team can confirm there's exactly one network code path, off by default.

Q3What's your data retention policy?+

We have nothing to retain. ScopePack never receives your documents, so there's no server-side copy to store, log, mine, or be compelled to disclose. Source files and briefing packs live only in encrypted local storage on your device, under your own retention schedule.

Q4How does this help our regulator or audit posture?+

A hosted AI service creates an external copy of client data subject to breach and legal process at the vendor. ScopePack removes that surface — your files never reach a server, so there's no vendor-held copy to account for in data-mapping or vendor-risk work, and every pack includes a local-processing verification record. This isn't compliance advice; you remain responsible for your own obligations.

Q5Are we locked into ScopePack as a vendor?+

No. The app runs fully offline on your machine. If ScopePack the company disappeared tomorrow, your installed app keeps working — there's no server to switch off and no account to lose. You're not renting access to your own documents.

Q6Our firm banned ChatGPT for client data. Is this different?+

Yes. Those bans exist because pasting client data into a cloud chatbot sends it to a vendor's servers. ScopePack does the opposite: the AI and OCR run on-device and nothing is transmitted, so you get AI-grade review without the disclosure that triggered the ban. It's designed to be the sanctioned local alternative your IT and compliance reviewers can verify.

§ 07 · Lock in pilot access

Early access while we onboard the first confidential-work operators

Lock in pilot pricing for a year. Manually onboarded — after payment we reach out at your checkout email.

Individual Early License
$499 / year
  • Full local briefing workflow
  • Timeline, entities, sensitive findings
  • Redaction & safe-to-share export
  • Verification report on every pack
  • Direct line to the founder
  • 1 year of updates · yours to keep forever
Get individual pilot — $499/yr
Small Team Pilot
$999 / team
  • Everything in the individual license
  • Set up for a small practice or team workflow
  • Onboarding call included
  • Verification materials for IT & compliance review
  • Named founding-pilot pricing locked in
  • 1 year of updates · yours to keep forever
Get team pilot — $999

30-day refund, no questions asked. Manually onboarded — please don't email sensitive client documents; the product is where they belong. Read why we built it →

Operator aid — not advice

ScopePack is a private workspace and operator aid for reviewing your own documents. It is not legal, security, or compliance advice, and is not a tool for evading lawful obligations. You remain responsible for how you handle your files and for reviewing every output before relying on or sharing it.