PDFArrow · Illustrated redaction safety guide

How to prove sensitive text is gone from a redacted PDF

A black rectangle is not proof of redaction. The safe workflow removes the underlying content and then tests the exported file like a recipient would.

Reviewed July 21, 2026 by PDFArrow Product Engineering.

1. Mark only what must be removed

Work from an authorized copy. Mark complete names, identifiers, signatures, barcodes, or surrounding context that could reconstruct the sensitive value. Keep an untouched source in a restricted location.

2. Export a permanently rebuilt copy

PDFArrow's permanent redaction workflow rebuilds pages from rendered pixels, removes the original page content streams and metadata, and places the visible redaction marks into the new flattened pages. The result is no longer searchable, form-fillable, linked, layered, or tagged.

3. Try to recover the secret

Open the exported file, search for the value, drag-select around the redaction, copy and paste nearby content, inspect document properties, and run text extraction. For high-stakes disclosure, ask a second person to repeat the checks on a different PDF reader.

4. Check visual leakage

Zoom to at least 400 percent and inspect edges, partial characters, neighboring cells, headers, comments, attachments, and repeated values. Redaction is a document-review task, not just a drawing task.

Published recovery proof

The fictional secret is present in text extracted from the unsafe before sample and absent from text extracted from the flattened after sample. Download both PDFs and the extraction record to repeat the check.

Downloads and evidence

Related tools and resources