Privacy / upload mode roadmap

Redact PDF Quality Gate

Redaction must permanently remove underlying text, image data and object references. VaultPDF will not ship a cosmetic black-box cover as secure redaction.

how it works

Designed for the shortest private path.

  1. Use local metadata cleaner for current privacy work.
  2. Redaction must pass destructive-content verification.
  3. Upload or local mode will be labeled only after the quality bar is met.
advanced feature boundary

Redact PDF is not shipped in the local MVP yet.

This feature needs a higher quality bar than the current browser-only pipeline. If it later requires upload or AI processing, VaultPDF will separate it from local tools and ask for explicit consent before any file leaves the browser.

Use local tools now
quality gate

Secure redaction gate

Sensitive content must be removed from underlying text, image and annotation objects, not only covered visually.

hybrid candidate

Must pass before launch

  • Verify extracted text no longer contains redacted strings.
  • Verify raster regions are burned out or object streams are rewritten.
  • Remove related annotations, form values and metadata references.
  • Add a post-redaction inspection report for user trust.

Currently blocked by

  • Object-level removal needs deeper parser coverage.
  • No destructive redaction fixtures yet.
seo content matrix

Privacy and compliance boundaries

Make quality gates visible so dangerous features do not ship as fake security.

Audience
users sharing contracts, IDs, HR files and regulated documents
Primary intent
remove metadata and understand advanced privacy limits
remove pdf metadata locallyredact pdf safelypdf/a conversionrepair pdf
faq

Practical boundaries before you process a file.

Why is Redact not shipped yet?

Because fake redaction is dangerous. VaultPDF will only ship it when underlying content is actually removed.

Is drawing a black box enough?

No. Hidden text or image data can remain extractable unless the PDF objects are rewritten safely.