PDF guide
FrançaisVisual whiteout vs confidential PDF redaction
A visual correction can make a page look right while leaving the original content in the document structure. That distinction matters whenever names, account numbers or other confidential text must be removed.
Open the PDF editorWhat visual whiteout does
Whiteout draws a covering shape over the page. It is useful for a visible correction or presentation mock-up, and it is quick to review in the editor.
- 1Choose Whiteout and place it over the visible line.
- 2Add replacement text if the page needs a corrected value.
- 3Export only for a use where the underlying text is not confidential.
Why it is not a secure redaction
The original PDF text can remain underneath a visual replacement and may still be extracted, searched or exposed by another processing tool. A white rectangle is therefore not proof that the value has been removed.
- 1Do not use visual whiteout for personal data, credentials or legal disclosures.
- 2Keep a copy of the untouched source before any removal workflow.
- 3Use software that removes the content and checks the result by searching and inspecting the PDF.
Use the editor for the right job
The browser editor is suited to annotations, layout corrections and signatures that you can inspect visually. Its own questions and limits explain where it stops.
- 1Use Edit text for a visible line correction.
- 2Use Sign, Add text or Highlight for additions and review notes.
- 3Use a dedicated redaction workflow when confidentiality is the requirement.
Where data hides beyond the visible page
A PDF carries more than its visible pages. Document properties — author, title, creating software, timestamps — travel with the file and are one right-click away in any reader (File → Properties). A "clean" page with the author's full name sitting in the metadata is not clean at all.
Then there's the text underneath. Drawing a white shape over a paragraph changes what the eye sees; it does not delete the characters beneath. Anyone can select the "covered" area and copy it, search for it with Ctrl+F, or extract it wholesale. Running the file through PDF to text is a sobering demonstration: covered text shows up in the extraction as if the shape were never there.
Annotations are a third leak. Comments, sticky notes, and highlights carry author names and timestamps, and review markup often contains the very discussion you meant to keep private — a note reading "remove the salary figure on page 2" sitting right next to the salary figure, for example. Delete annotations before sharing, and re-check that the note text itself didn't contain sensitive content.
The fastest sanity check takes five seconds: open the exported file, drag-select across a covered area, and paste into a text editor. If the hidden words appear there, they will appear for your recipient too. Do this before every share, not just the first — one careless page is enough to undo the rest.
The pattern is the same in each case: what you can't see can still be read. Treat every layer of the file — visible content, hidden text, annotations, metadata — as part of what you're sharing, because for the recipient, it is.
Two more hiding spots deserve a mention. PDFs can carry embedded file attachments — a spreadsheet tucked inside the document travels with it silently. And files saved repeatedly can retain earlier versions of their content in the file's structure. Neither is visible on the page, and both are reasons to verify the exported file itself rather than trusting what you see in the editor.
A safer removal workflow
If you must remove sensitive content with a general-purpose editor rather than dedicated redaction software, this workflow is meaningfully safer than whiteout alone. It is still best-effort — not certified redaction — but each step closes a real leak:
- 1Keep an untouched copy of the original before you change anything. If a step goes wrong, you start over from a known-good file instead of compounding edits.
- 2Use Edit text to delete or replace the sensitive words themselves wherever the tool allows — change the underlying characters, not just their appearance. Covering text you haven't altered leaves the original fully recoverable.
- 3Only then place whiteout shapes over the area, so the page looks clean and intentional rather than visibly tampered with.
- 4Export the file and search it (Ctrl+F or Cmd+F) for each removed term. Expect zero hits — any hit is a leak you still need to fix.
- 5Run the exported file through PDF to text and scan the extracted text for the sensitive strings. Extraction sees what shapes hide.
- 6Check document properties for author names, titles, and software traces, and remove any remaining annotations or comments.
Be honest about the limit: a browser editor is not certified redaction software. For legal disclosures, personal data under regulation, or anything an adversary might actively try to recover, use a dedicated redaction tool — and still run the verification steps above on its output.
Notice that every verification step runs on the exported file, not the draft inside the editor. The exported copy is what the recipient receives, and it's the only version whose hidden layers you can actually test. Verify the artifact, not the workspace.
When you replace sensitive words rather than deleting them, use a neutral placeholder such as "REDACTED" and keep it visibly distinct from the surrounding content. A placeholder that mimics the original wording invites misreading; one that is obviously a placeholder invites no confusion at all.
Verification checklist before sharing
Run through this list on the exported file — the copy you will actually send, not the draft in the editor. Treat it as a pre-flight routine: two minutes now beats an incident response later.
- ✓Searching the exported PDF finds none of the removed terms.
- ✓Text extraction shows no hidden copies of the sensitive content.
- ✓Document properties contain no author names or revealing titles.
- ✓All comments, sticky notes, and review markup are gone.
- ✓The file opens and reads correctly in a second viewer.
- ✓The file name itself reveals nothing (no "contract-DRAFT-salary-figures.pdf").
- ✓No embedded file attachments travel with the document.
- ✓Page count and layout match what you intended to share — no stray draft pages.
Which removal level each scenario needs
Not every cover-up needs the same rigour. Redaction is a ladder, and the right rung depends on who receives the file and what happens if the hidden data surfaces:
| Scenario | Required removal level |
|---|---|
| Hiding a draft typo before an internal print | Visual whiteout is fine — nothing confidential is involved. |
| Masking figures in a report shared with partners | Remove the underlying text, whiteout, and verify by search and extraction. |
| Sharing a contract with ID numbers visible | Dedicated redaction software, then verify its output. |
| Covering a watermark on a mock-up | Visual whiteout is fine. |
| Publishing a document sample publicly | Full removal workflow plus a metadata and annotation check. |
| Preparing evidence for a legal filing | Certified redaction process — visual tools are not sufficient. |
When in doubt, choose the stronger level. The cost of over-redacting is a slightly longer workflow; the cost of under-redacting is the data itself, in someone else's hands — and unlike the editing, which happens privately in your browser, a shared file can't be taken back. Calibrate the effort to the audience: a figure leaked to a colleague is embarrassing, while the same figure in a published sample is permanent. When the audience is "everyone", assume someone will look.