Home / Defensibility

Every Redaction Carries the Reason It Was Made

Redactor records a statutory exemption against each redaction, prints it on the released record, and reports what was withheld, by whom, and under which basis. When a withholding is challenged, the answer is already in the file.

How Defensible Redaction Works

A code is applied to a redaction as it is made, not reconstructed afterwards from notes. In audio and transcript redaction the spoken segment is replaced and the transcript shows the code in place of the words, so a reader sees that something was withheld and under which exemption rather than an unexplained gap.

The same code is drawn onto the redaction itself in video, images and documents. A requester opening the released file sees both the mask and the basis for it, without being sent to a separate log.

What Defensible Redaction Covers

Exemption codes

51 default codes ship, grouped as US FOIA, UK FOIA and the US Privacy Act. An example is (b)(1)(A), for national security information properly classified under Executive Order.

Custom code lists are created per organization, which matters because agencies interpret the same exemption differently and a records unit needs its own wording to survive its own appeals process.

Overlay text on the redaction

The code is rendered into the mask, with configurable color, sized to the region and wrapped to fit it. The basis travels with the file rather than with the covering letter.

Compliance coverage reporting

When a detection job runs against a framework, the dashboard reports how much of that framework's detection set was actually redacted. It answers whether a release meets the standard it was redacted against, not merely that redaction happened.

Twelve frameworks ship with their own class sets:

FrameworkClass set
US FOIA, UK FOIAPublic-records exemption classes
HIPAAPHI identifier classes
PCI DSSPayment and account identifiers only
GDPR, CCPA and CPRAPersonal-data classes
CJISIncludes license plates, vehicles, weapons, screens and street signs
FERPA, COPPAStudent and minor identifier classes
GLBA, SOX, FRCPFinancial, reporting and civil-procedure classes

Custom class sets are definable alongside the twelve.

Classification marking

Classified passages are shaded as classification markings rather than as ordinary redactions. Removing that shading is a restricted right, not something available to anyone holding edit permission.

The custody trail

Every action on an item is recorded with the user, their email address, the IP address they acted from, the local date and time, and the event. Around 36 event types are recorded, running from ingestion through to disposition.

Viewing custody for your own content and for all content are separate entitlements, so an investigator sees their own trail while a supervisor sees the whole one.

Reporting and export

The redaction dashboard reports what was redacted, by whom and when, across the portal, with per-asset detail underneath. The filtered view exports as CSV, for review outside the portal or for attaching to a release package as evidence of how the redaction was carried out.

Metadata removed on export

Embedded metadata is removed or rewritten before a redacted file is exported. A release that obscures faces but ships GPS coordinates, device identifiers or an author name in the file metadata has not achieved what the redaction intended. Applies to audio and video file metadata on export.

Lock against automated deletion

Locking an item excludes it from lifecycle policy action, so an automated purge, soft delete or tier change passes over it while a matter is live. Policy handlers exclude locked items when they select their targets, so the exclusion is applied at selection rather than checked afterwards.

Where It Matters

  • FOIA and public records — exemption codes on every withholding, and a coverage report against the framework
  • eDiscovery — privilege decisions recorded with their basis, exportable for a privilege log
  • Body camera footage — custody from ingest to release, with the address every access came from
  • Government — release packages that survive an appeal

What Defensible Redaction Does Not Do

  • Codes record the basis for a redaction. Choosing the correct exemption remains an operator judgement.
  • Coverage reports against the framework's configured class set, and is meaningful only where the job ran with a framework selected.
  • Overlay text is sized to the redacted region, so a small region carries less text.
  • The custody trail records actions taken within the platform. Integrity verification within it depends on the hash recorded at ingest.
  • Metadata removal on export applies to audio and video file metadata.
  • Lock is the per-item exemption from lifecycle policy. Legal hold is a separate, case-scoped control.

How Defensible Redaction Is Evaluated

  • Redactions are labelled with a statutory exemption, drawn from default US FOIA, UK FOIA and Privacy Act lists or from custom lists.
  • The exemption shows on the released record, both on the redaction and in the transcript in place of the redacted words.
  • Custom codes are definable, which matters because agencies interpret exemptions differently.
  • The coverage panel reports the proportion of a framework's detection set that was redacted, across twelve frameworks, each with its own class set.
  • Every action is recorded with user, email, IP address, local date and time, and event, across roughly 36 event types.
  • Own-content and all-content custody are separate entitlements, so custody visibility is restrictable to supervisors.
  • Redaction records export as CSV for attachment to a release package.
  • Embedded file metadata is removed or modified before export, alongside content redaction.

See Defensibility on Your Own Records

Send us a file you have already released and we will show you what the exemption report would have looked like.