Jetformat

PDF encryption, redaction, and sanitization

Encryption, redaction, and sanitization address different problems. Choose the operation from the information or behavior that must change, and review the resulting file before sharing it.

Published · 5 min read

By Jetformat

PDF encryption is an access-control operation, redaction removes targeted content, and sanitization removes selected active behavior. These operations answer different requirements. Define the required change and verify that property in the resulting file before distributing it.

1. Define what needs to change

Encryption adds a password requirement. Redaction targets matching text. Sanitization removes JavaScript, URI, Launch, and similar actions. None of these names should be treated as a blanket guarantee that a document is safe to publish.

Write a short acceptance criterion before running a command: “opens only with the supplied password,” “the specified text is absent from extraction and the reviewed pages,” or “active links and scripts are removed.” These can be checked separately.

2. Write a distinct output

For active-action removal:

jetformat pdf sanitize source.pdf -o sanitized.pdf

For a text pattern:

jetformat pdf redact source.pdf --term 'Internal project code' -o redacted.pdf
jetformat text redacted.pdf -o redacted.txt

The redaction term is a regular expression. Escape metacharacters if the intention is a literal match. Text in scanned images is outside this text-layer operation; reviewing extracted text alone is not enough for image-based content.

3. Verify before distribution

Inspect all affected pages visually and search the extracted output for the target and expected variants. Review metadata and attachments separately. Cropping a page or drawing a black annotation is not a substitute for removing the underlying information.

If a document will be signed, plan the editing order before signing and validate the final signature. Later edits can affect signature validity. Keep originals in the appropriate private location while distributing only the verified derivative.

Use encryption, redaction, sanitization, and attachment inspection as separate task guides.

Compare the security operations

Requirement Operation Follow-up check
Require an opening password Encryption Open with and without the authorized password
Remove matching text Redaction Extract text and inspect affected page images
Remove active actions Sanitization Check the expected actions and remaining content
Remove unwanted attachments Attachment review and appropriate removal Inspect the final attachment list

An encrypted file can still contain sensitive material. Sanitizing active actions does not mean all private text or metadata has been removed. A visible black rectangle is not evidence that the underlying words are absent. Keep each acceptance criterion independent.

Use an ordered verification procedure

  1. Preserve the original in its appropriate private location and inventory the material that must change.
  2. Choose the matching operation and write a distinct output.
  3. Extract text from the result and check the target strings, spelling variants, and nearby context.
  4. Render and inspect affected pages, including any scanned or image-based content that text extraction cannot assess.
  5. Inspect metadata and attachments separately, then distribute only the reviewed derivative.

If a required property cannot be verified, keep that uncertainty in the result instead of labeling the document safe. For sensitive distributions, the reviewer needs the criteria and evidence, not just a successful command exit.

Account for each output operation

Consider an illustrative 5-page PDF. One successful sanitization write uses 5 credits. A separate redaction write producing 5 pages adds 5 credits. Rendering all 5 final pages adds another 5 credits, for 15 credits total. The example is a unit calculation, not a recommendation that every document needs all three operations.

Free pdf info, pdf attachments, and text reads can support review without increasing that total. They still check different aspects of the file and should not be treated as interchangeable evidence.

Keep signatures and copies in the workflow

Complete content changes before signing when possible, and validate the final signature using an appropriate verifier. Do not assume an existing signature remains valid after an edit. Also review filenames, attachments, and the distribution destination: removing text from one PDF does not remove the original or a previously shared copy.

For command-specific limits and syntax, read redaction, sanitization, encryption, and PDF signing. These task guides describe available operations rather than a certification of a document’s overall safety.

Last updated