Home / Permanent redaction

Permanent Redaction

The failures that make the news are the same failure twice: a black box drawn over text that was still underneath it, or a file released with its metadata intact. Redactor produces a new rendition with the content removed, and decides what happens to the original by policy rather than by accident.

How Permanent Redaction Works

Objects are detected, reviewed, and then burned out of a new rendition. The released file does not carry the redacted content beneath a mask, because the released file is not the original with a mask applied. It is a different file, produced from the original, with the content gone.

What happens to the source is a configured policy, not a side effect.

What Permanent Redaction Covers

Three output policies

PolicyEffectWhen it is right
Create copyThe original is retained; the redaction is a new assetPublic records and evidence. The default posture.
Create copy and recycle originalThe redaction is created; the original goes to the recycle binWorkflows where the source is transient
Use originalThe original is redacted in placePrivacy workflows where the unredacted version must not persist

Public-records and evidence work generally requires the unredacted record to survive so the withholding can be reviewed, while the redacted copy is what gets released. Create copy is that posture, and it is the default.

An appeal against a withholding is decided against the original. If the original is gone, the appeal cannot be answered.

Metadata removed on export

Embedded metadata is removed or rewritten before a redacted file is exported, so identifying information that travels in the file's metadata does not survive a release that redacted the content.

A release that obscures faces but ships GPS coordinates, device identifiers or an author name in the file metadata has not achieved what the redaction intended. This applies to audio and video file metadata on export.

Where It Matters

What Permanent Redaction Does Not Do

  • Use original replaces the source, leaving the redacted file as the only version. That is the right answer for some privacy workflows and the wrong one where the record must be preserved. Choose deliberately.
  • Metadata removal on export applies to audio and video file metadata.

How Permanent Redaction Is Evaluated

  • Redaction produces a new rendition with the obscured regions burned in, which is what makes the redaction permanent in that asset.
  • Detection quality follows source quality; a clear, well-lit source produces better detection than a poor one.
  • The default posture keeps the original and produces the redaction as a separate asset.
  • Three output policies are configurable, and one of them deliberately replaces the source.
  • Embedded file metadata is removed or modified before export, alongside content redaction.

Check a File You Have Already Released

Send us a redacted file and we will tell you whether the content is really gone and what its metadata still carries.