Guides/PDF safety
Independent practical guide

A practical checklist before sharing a sensitive PDF

The most common PDF privacy failures are mundane: the wrong attachment, an extra scanned page, a password sent in the same message or a visual “redaction” that leaves readable text underneath.

1. Make a sharing copy

Keep the original in a controlled location and work on a duplicate. Remove pages that the recipient does not need. A shorter sharing copy reduces both file size and the amount of information that can be disclosed accidentally.

2. Review more than the visible page

PDFs may include comments, form values, attachments, bookmarks and metadata. A page that looks blank can still contain text. Use a trusted inspection or sanitization tool when those features matter; page reordering alone is not sanitization.

3. Treat redaction as a special task

Drawing a black rectangle over a name hides pixels but can leave the text selectable underneath. Secure redaction removes the underlying content and should be verified by search, copy and object inspection. This site does not claim that an ordinary overlay is secure redaction.

4. Protect access appropriately

If password encryption fits the risk, use a long unique passphrase and send it through a different channel. Keep an unencrypted master in a secure location; a service that never receives your password cannot recover it for you.

5. Check the recipient and the output

Open the exact file you plan to attach. Search for sensitive names, inspect the first and last page, verify the page count and confirm that protection works in a second viewer. Then double-check recipient addresses before sending.

6. Know when to use a specialist service

Medical, legal, government and regulated records may be subject to retention, audit or approved-system rules. Local browser processing reduces server exposure but does not replace your organization’s security policy.

Written and maintained by Ferenc Gyurica

Last reviewed 16 August 2026. This guide explains the project’s actual browser workflow and does not replace legal, compliance or security advice.