Processed locally · No upload

Automatic Secure PDF Redaction

Find common sensitive patterns locally, confirm each result, and permanently redact it. Draw manual boxes for names, addresses, images, and anything else. Export burns every redaction into rebuilt pages—without uploads or an account.

Click to choose PDFs or drag them here

PDF only · One file at a time

Files stay on your device and are never uploaded.

Securely redact in three steps

  1. 1Choose a PDFThe file opens only in your browser.
  2. 2Scan and confirmConfirm automatic findings and manually mark anything missed.
  3. 3Redact permanentlyBurn redactions into pixels, rebuild, and download a new PDF.

A black box is not always redaction

Some PDF editors only place a black shape above the text. It looks hidden, but a recipient may still select the text, remove the shape, or inspect hidden layers. This tool takes a more conservative path: it renders every page to pixels, burns the black areas into those pixels, and creates a new PDF from the flattened pages.

Automatic scanning reads only the existing text layer and visible form values, and you confirm every finding. It cannot identify every name, address, image, or scanned word. Secure export does not copy searchable text, interactive form/annotation objects, links, scripts, or attachments, but any visible content may remain as pixels, so review every page before sharing. If the document must preserve accessibility, digital signatures, or evidentiary properties, use your organization’s approved professional workflow.

Frequently asked questions

Can someone copy or recover the original text after redaction?

Export turns every page into an image, burns every confirmed and manual redaction into its pixels, and creates a new PDF. Source text and interactive objects are not copied. Automatic scanning checks visible form values in supported formats; other annotations, signatures, images, or unsupported content still need manual boxes.

Is my file uploaded to a server?

No. Previewing, marking, rendering, and rebuilding all happen inside your browser.

Why is the exported PDF no longer searchable?

That is part of the security model. The original text layer is deliberately discarded when each page is flattened, so no copyable text remains below the black areas.

What sensitive data can it find automatically?

It scans the existing text layer and visible form values for email addresses, phone numbers, valid Chinese ID and bank card numbers, IPv4 addresses, and common API secrets. Findings are not redacted until you confirm them. Names, addresses, images, and scanned pages without a text layer still require manual marking.

How many pages are supported?

A single file can contain up to 50 pages, but that cap is only an initial guard, not a guarantee. The safety budget is 25 megapixels per page and 125 megapixels total, and the device may have less memory available. Split the PDF if it cannot be completed.

Why does the download not keep the source filename?

A source filename may itself contain a name, account number, or case number. The tool uses a generic output name so that clue is not carried into the download or share. After review, you can rename it to something that does not disclose private information.

Should I still review the result?

Yes. The tool securely burns in every confirmed finding and manual area, but it cannot know whether you missed a name, custom identifier, scanned word, or image. Open and review the exported file before sharing it.