Local AI for consultants: query confidential client files on your own machine
A client NDA won't let you paste a data room into a cloud AI. Index and question your engagement files on-device, with citations and no upload — verifiable with a packet capture. Free 14-day trial.
The duty: a client’s data room is theirs, and you answer to them — not to an AI vendor
The client didn’t just sign an NDA with you; they handed you their data room on the strength of your discretion. The engagement files on your disk — the data room export, the board deck, the financial model, the diligence pack, the management interview notes — belong to the client, and when something goes wrong with them, the person the client calls is you, not a vendor’s status page. Your practice runs on being the advisor who can be trusted with the sensitive version of the story.
So “just paste it into a chatbot” is not a shortcut; it is a decision you would have to defend to the client. The moment a confidential board deck or a target’s financials leaves your laptop for a hosted AI service, a copy exists on infrastructure you do not own, governed by terms you did not write, on material you promised the client would stay close.
SealedBrief is local AI for consultants who handle confidential client data, built on one decision: the engagement files stay on your machine. You point it at a folder — a data room export, a deal directory, an interview archive — and it indexes and answers questions across it on your own hardware, with no upload step to opt out of, because there is no upload at all.
Why “sync to the cloud and trust us” fails an NDA — and a client security review
Independent advisors increasingly field the same question a large firm’s procurement team does: the client’s security review. Before your work touches their data room, the client’s information-security function may ask what tools you use, where their data goes, and who else can technically read it. “I upload it to a hosted AI assistant” is a hard answer to give — it introduces a party the client never vetted onto a data flow they never approved.
- A cloud AI turns you into an undisclosed subprocessor. The NDA binds you and the people you are permitted to involve. A hosted model you paste files into is a third party the client did not review — and a “we don’t train on your data” setting still asks them to accept a processor they never saw.
- The reviewer assumes the trade, not the promise. A security review does not ask whether a breach is likely; it asks who could access the data if one happened. Once a file leaves your disk, the honest answer includes the vendor, their subprocessors, and their hosting providers — and for a live data room, that answer can end an engagement.
- Right-to-audit meets a black box. Many engagement letters give the client a right to inspect how their material is handled. Neither you nor the client can audit a hosted model’s internals — so you are offering their auditor a promise where they wanted a record.
The defensible position for confidential client work is that the material was never transmitted at all — so there is no subprocessor to disclose and no data flow to approve. This is not legal advice about your particular NDA; it is about removing the extra copy the review worries about.
Cited answers across your engagement files, grounded in the exact page
SealedBrief is a local-first AI workspace that runs offline RAG over your own engagement material. Point it at a folder and its ingestion engine indexes everything in place: PDF, DOCX, TXT, Markdown, EPUB, and HTML, plus scanned pages and still images (PNG, JPG, TIFF) through on-device OCR. There is no proprietary cloud store and no migration; the files stay where they already sit. This is on-device AI for a data room, not another place to upload one.
Then you ask questions across the whole engagement: Where does this growth assumption first enter the financial model, and do the diligence-pack findings support it? Which agreements in the data room carry a change-of-control clause? Reconcile the headcount in the board deck against the management interview notes. Every answer is grounded in retrieved passages from your own documents and shows the source paragraphs alongside it, so you can click back to the exact page a figure came from. When the model cannot ground a claim in your files, it says so — an explicit “couldn’t ground this” signal — rather than inventing a citation.
Treat the output the way you would treat a first-year analyst’s first draft: read the cited passages before anything goes near a client deliverable. The answers come from a local open model, not a frontier hosted system, so verification is the workflow. This is the same wedge SealedBrief makes across regulated work; see the broader case for private, local AI for confidential documents.
What’s encrypted at rest — and the one carve-out, stated plainly
On disk, SealedBrief encrypts your indexed content. The document text, source references, and metadata are encrypted field by field with AES-256-GCM, using HKDF-SHA256-derived subkeys and a fresh random nonce per record; the core database and the full-text search index sit behind SQLCipher AES-256 page encryption. The master key lives in your operating system’s keychain.
One carve-out belongs up front, because precise claims are the point: the embedding vectors — the numeric representations used to find relevant passages — are stored unencrypted. Approximate-nearest-neighbour search needs plaintext math over those numbers, so they cannot be encrypted at rest without breaking the retrieval that makes the product work. Your document text and metadata are encrypted; the vectors are not — so do not treat a vector store as if the underlying prose were sealed. It is not accurate to say everything on disk is encrypted, and SealedBrief does not claim that.
Verify the no-egress claim yourself — the check a client’s reviewer would run
You should not take a privacy claim on faith, and neither should your client’s security team — so the claim is built to be checked. SealedBrief runs as two operating-system processes that cannot swap roles. The Compute Plane — which reads your documents, runs the model, searches the index, and does OCR — has no network egress by construction. The Presentation Plane, the interface, contacts sealedbrief.com for exactly two things: validating your licence and checking for updates. Neither call carries your documents or your queries.
That is what makes the claim checkable rather than promised. Run a packet capture on your own machine — tcpdump, Wireshark, or your client’s approved tooling — index an engagement folder, and run a real question-and-answer session while you watch the traffic. The document-handling process opens no connection; the interface’s two calls carry a licence check and an update check, never your records. A client’s security reviewer can reproduce it in a few minutes, turning a vendor-questionnaire answer into something they can falsify instead of trust. Follow the full verify-it-yourself walkthrough for the exact commands.
The boundary is precise, and you can hold SealedBrief to it: the process handling your documents makes no network calls, and the one that does reach the network never has your content to send.
Honest limits
A tool you are personally answerable to a client for deserves its boundaries stated up front.
- The model is a local open one. SealedBrief ships with Qwen3-8B and Qwen3-14B (both open-weight GGUF, auto-selected by your available VRAM), running fully offline. Capable, but not a frontier hosted model — verify the citations against the cited passages every time, and expect the occasional miss on a long or messy data room.
- Hardware shapes the experience. The recommended setup is a machine with a 12 GB-or-larger NVIDIA GPU, where answers come back in seconds; it also runs on 8–12 GB GPUs and on Apple Silicon Macs (M1–M4) via Metal, and CPU-only in tens of seconds. Plan on about 16 GB of RAM and 15 GB of free disk for the one-time download, after which it works offline.
- Documents, not recordings. On-device OCR reads scanned contracts and photographed pages; there is no audio or video transcription, so a recorded interview must be transcribed elsewhere first.
- Platforms, and the Mac reality. Consulting skews heavily toward MacBooks, and macOS on Apple Silicon (a signed, notarized build) ships today alongside Linux (a portable AppImage). Windows is a waitlist — genuinely blocked on an encryption-library dependency, not a marketing “coming soon” — and you are not charged until it ships. If your firm issues Windows laptops, join the waitlist rather than buy today.
- A technical control, not a certification. Keeping engagement files on the device is a meaningful safeguard, but it does not by itself satisfy any particular NDA clause or regulation, and nothing here is legal advice. How this control maps to your obligations is your own judgment to make.
The Professional tier: a commercial-use grant, and evidence for a client’s security review
Consulting is paid client work by definition, and that is exactly what the Professional tier’s commercial-use grant covers — using SealedBrief on billable engagements, across up to three devices. Personal ($199 for a 3-year term, one device) runs the same on-device workspace and is never crippled.
What sets Professional ($499 for a 3-year term) apart for advisors is the exportable evidence surface. When a client’s security review asks how their data room is handled, this tier gives you three artifacts to attach to the questionnaire: an at-rest encryption proof, a network-egress attestation, and an ingestion audit log — a record of what was indexed, held by you rather than a vendor. Rather than ask the client’s information-security team to take your word, you hand them a self-owned account of what touched their material and that nothing was transmitted. That turns “what AI tools do you use?” into a short, evidenced answer — the kind a private AI for consulting engagements can give.
Both tiers are a 3-year term licence — not perpetual, and not a subscription — backed by a 30-day, no-questions refund that is separate from the free trial. You can compare the two on the pricing page.
Try it on your own engagement files
The honest way to judge a confidentiality tool is against your own files, on your own hardware, watching your own network — so the download is the free 14-day trial, the full workspace rather than a limited demo. On first launch you choose “Start 14-day trial” on the welcome screen: no account, no credit card, and starting the trial makes no network call, which you can confirm with the same packet capture. This is local AI for NDA client documents, evaluated the way that actually counts — on an engagement you genuinely cannot upload.
After 14 days the app opens read-only. Nothing is deleted and nothing is locked away — you keep full read, search, and export (Markdown and PDF) of everything already indexed; only indexing new documents and asking new questions pause until you enter a licence, which unlocks the same install with no lost work.
Run it against an engagement you cannot hand to a cloud service, and capture the traffic while you do. Download the free 14-day trial for Linux or macOS on Apple Silicon, or compare the two licences if you already know which tier fits your practice.