Reader question: How can a small team remove what an AI tool should not see without mistaking a black rectangle for a secure redaction?
A sharing copy is a new artifact with a smaller purpose, not the original with a few marks added. This proposed drill uses synthetic text and labels; it reports no completed test or provider conclusion.
Decide what may travel, remove the rest with a real tool, then reopen the copy and try recovery. If the check cannot answer, hold the upload.
Materials and roles
Set aside 35 minutes, the original read-only, a synthetic fixture, the format's editor, a plain-text editor, a timer, and a reviewer with reject authority. The redaction author cannot be sole approver.
Use this tiny fixture, or make an equivalent one without borrowing live records:
SYNTHETIC BRIEF / FIXTURE S-17
Keep: Public summary - three packaging ideas due Friday.
Remove: NAME-ALPHA; EMAIL-ALPHA@example.invalid; CLIENT-TEST-0001.
Remove: INTERNAL-NOTE-ALPHA: hold the invented budget in the owner file.
Write keep and remove lists before opening the tool. Keep the public summary; remove the invented name, address, client code, internal note, comments, tracked revisions, and file properties. The copy should explain what was removed without the original.
00:00-00:08 - Freeze the boundary
Save a working copy named fixture-S17-sharing-copy; leave the original controlled. Record file type, page count, and remove-list tokens. Do not paste live material; realism is not evidence.
Read pages once for text boxes, screenshots, headers, comments, revisions, links, attachments, and content revealed by selection or expansion. Choose the smallest useful output format; it can reduce hidden structure but not the duty to inspect.
00:08-00:20 - Apply a real redaction
For a Word starting point, save a copy and use File > Info > Check for Issues > Inspect Document. Select relevant inspectors, review results, remove approved hidden items, and inspect again. Microsoft recommends a copy because removals may not be restorable; categories include comments, revisions, properties, hidden text, custom XML, and invisible content. This is cleanup, not visible-text redaction. In the working copy, delete or replace approved body text with [REMOVED], address tracked changes, save, and reopen. If needed, export to PDF and finish with Acrobat; only the checked output is shareable. Microsoft Document Inspector guidance
For a PDF in Acrobat Pro, open All tools > Redact a PDF > Redact text and images, select the synthetic fields or image, choose Apply, and save the sanitized document. Adobe's current procedure also offers a prompt to sanitize hidden information during that save. Adobe's current redaction steps
Do not substitute a black shape, highlight, white font, crop, or screenshot. Those can change the view while leaving selectable text or another layer. A proper redaction may still look like a colored box; the proof is the applied-and-saved removal plus a recovery test that cannot recover the marked content. Adobe's redaction and sanitization distinction
00:20-00:28 - Sanitize the container
Visible text is one layer. In Acrobat Pro, use All tools > Redact a PDF > Sanitize document. Choose Selectively remove to review Hidden Information, or Remove all after the reviewer accepts the loss. Remove approved categories and save a new file. Adobe describes sanitization as separate treatment for metadata, embedded content, scripts, and other non-visible elements. Adobe's sanitization guidance
In Word, treat the Document Inspector report as a lead, not a certificate. Microsoft notes that some content cannot be removed or detected by a given inspector. Resolve flagged objects and do not assume a clean page means a clean file.
00:28-00:35 - Read back like an uploader
Close the editor; reopen only the sharing copy, preferably in a second viewer. Search for every removed token: NAME-ALPHA, EMAIL-ALPHA@example.invalid, CLIENT-TEST-0001, and INTERNAL-NOTE-ALPHA. Select all accessible text and paste it into the plain-text editor. Check comments, revisions, properties, links, attachments, and layers. View every page at normal size and zoom. Try to remove or move each overlay, then search or extract text again. A recovered forbidden token or overlay that reveals it is a fail; selection of a genuine redaction mark alone is not proof.
Use this reviewer checklist:
| Check | Expected result | Reviewer |
|---|---|---|
| Original | Still present and unchanged in its controlled location | pass / fail |
| Keep list | Public summary survives accurately | pass / fail |
| Remove list | No synthetic token appears in search or copied text | pass / fail |
| Hidden content | Inspector or sanitizer results reviewed; unresolved items listed | pass / fail |
| Visual pass | No box, crop, or layer exposes the removed material | pass / fail |
| Upload boundary | Only the verified copy is selected; receiving-service terms remain a separate question | pass / fail |
Fail and discard the copy if the original was edited, a token returns, a flagged object is unresolved, the file was only covered visually, or the reviewer cannot determine what the receiving service may retain or expose. Make a new copy from the untouched original; do not repair in place.
If every row passes, the next decision is a limited dry run with a second synthetic fixture or less complex format, with independent readback. It is not permission to upload a live document. This proves only a file-level check against this fixture; it does not establish deletion, training, access, or interpretation behavior at the receiving service.
A clean sharing copy is a boundary you can explain: keep only what the recipient needs, remove visible and hidden layers with the format's tools, and attempt recovery before upload. If any part remains uncertain, stop and ask the source owner.
Sources and limitations
- Adobe Acrobat Help, “Redact sensitive content in PDFs in Acrobat Pro” - checked September 4, 2026; page last updated August 31, 2026. Supports the current Acrobat Pro path for marking text or images, applying redactions, choosing hidden-information sanitization, and saving a sanitized document. Limitation: menus and availability depend on Acrobat Pro version, license, and file characteristics.
- Adobe Acrobat Help, “About redacting and sanitizing PDFs in Acrobat Pro” - checked September 4, 2026; page last updated September 23, 2025. Supports the distinction between permanent visible redaction and separate hidden-data sanitization, including the stated scope limits. Limitation: the guidance does not make a universal guarantee that every object in every PDF is detected; readback remains necessary.
- Adobe Acrobat Help, “Sanitize PDFs in Acrobat Pro” - checked September 4, 2026; page last updated September 23, 2025. Supports the Sanitize document path, Selectively remove or Remove all choices, Hidden Information review, and saving the removed result. Limitation: this describes Acrobat Pro categories and workflow, not universal detection of every PDF object.
- Microsoft Support, “Remove hidden data and personal information by inspecting documents, presentations, or workbooks” - checked September 4, 2026. Supports copy-first Document Inspector steps, review and reinspection, and examples of hidden or personal information it can find or remove. Limitation: Microsoft notes that some information cannot be detected or removed by the inspector; document type and version affect coverage.