Home / Permanent redaction
Permanent Redaction
The failures that make the news are the same failure twice: a black box drawn over text that was still underneath it, or a file released with its metadata intact. Redactor produces a new rendition with the content removed, and decides what happens to the original by policy rather than by accident.
How Permanent Redaction Works
Objects are detected, reviewed, and then burned out of a new rendition. The released file does not carry the redacted content beneath a mask, because the released file is not the original with a mask applied. It is a different file, produced from the original, with the content gone.
What happens to the source is a configured policy, not a side effect.
What Permanent Redaction Covers
Three output policies
| Policy | Effect | When it is right |
|---|---|---|
| Create copy | The original is retained; the redaction is a new asset | Public records and evidence. The default posture. |
| Create copy and recycle original | The redaction is created; the original goes to the recycle bin | Workflows where the source is transient |
| Use original | The original is redacted in place | Privacy workflows where the unredacted version must not persist |
Public-records and evidence work generally requires the unredacted record to survive so the withholding can be reviewed, while the redacted copy is what gets released. Create copy is that posture, and it is the default.
An appeal against a withholding is decided against the original. If the original is gone, the appeal cannot be answered.
Metadata removed on export
Embedded metadata is removed or rewritten before a redacted file is exported, so identifying information that travels in the file's metadata does not survive a release that redacted the content.
A release that obscures faces but ships GPS coordinates, device identifiers or an author name in the file metadata has not achieved what the redaction intended. This applies to audio and video file metadata on export.
Where It Matters
- FOIA and public records — release the copy, keep the record for appeal
- eDiscovery — production sets where the original must survive for the privilege log
- GDPR and DSAR — where the unredacted version sometimes must not persist
What Permanent Redaction Does Not Do
- Use original replaces the source, leaving the redacted file as the only version. That is the right answer for some privacy workflows and the wrong one where the record must be preserved. Choose deliberately.
- Metadata removal on export applies to audio and video file metadata.
How Permanent Redaction Is Evaluated
- Redaction produces a new rendition with the obscured regions burned in, which is what makes the redaction permanent in that asset.
- Detection quality follows source quality; a clear, well-lit source produces better detection than a poor one.
- The default posture keeps the original and produces the redaction as a separate asset.
- Three output policies are configurable, and one of them deliberately replaces the source.
- Embedded file metadata is removed or modified before export, alongside content redaction.
Check a File You Have Already Released
Send us a redacted file and we will tell you whether the content is really gone and what its metadata still carries.