GUIDE · FERPA
FERPA Redaction Software That Proves the Data Is Gone
You have a records request on the clock and a stack of files full of student names, IDs, and the occasional Social Security number. Get it right and nobody notices. Get it wrong — leave one name behind, or "redact" with a black box that copy-pastes right off — and you have a privacy incident, a parent complaint, and a paper trail that says it was avoidable.
FERPA redaction software exists to take that risk off your desk. But most tools stop at drawing a box over the text. RedactWorks goes one step further: it re-scans the file you're about to release and blocks delivery if any student data is still in there. That last step is the difference between hoping the redaction worked and knowing it did.
What FERPA actually requires of you
FERPA protects the privacy of student education records. Before a school or agency discloses personally identifiable information (PII) from those records, it generally needs written consent from the parent or eligible student — unless a specific exception applies (34 CFR Part 99, Subpart D).
The part that makes redaction hard is the definition of PII. Under FERPA it isn't just names and Social Security numbers. It includes indirect identifiers — and the working test is whether information would let a reasonable person in the school community identify a specific student with reasonable certainty (U.S. Department of Education). A grade level here, a date of birth there, a small-class detail — combined, they can re-identify a student even when the obvious identifiers are gone.
That's why manual redaction is slow and error-prone. You're not scanning for one pattern. You're reading every page for anything that, in context, points back to a student. One missed line is a disclosure.
Why a black box isn't redaction
A black rectangle drawn over text only covers it. The underlying characters stay in the file, recoverable with a copy-paste.
This isn't a theoretical risk. In January 2019, attorneys in the Paul Manafort case filed a court document with sections blacked out — and a reporter recovered the "redacted" text simply by copying and pasting it, revealing material the defense had fought to keep sealed (The Hill; Vice). The black boxes were drawn on top of the text layer, not removed from it.
If a legal team with everything on the line can ship a copy-pasteable redaction, so can a records office working through a queue at the end of the month. The fix isn't more careful boxing. It's removing the data from the file.
What "verified redaction" means for a records office
RedactWorks runs the same four steps on every document:
- Detect. The tool scans for PII — names, IDs, SSNs, dates, and the other identifiers that re-identify a student in context. High-risk categories like SSN, financial, and medical data are locked on by default, so nobody can switch them off by accident. You can also define your own rules for what counts as sensitive in your records.
- Human review and approval. You see the highlighted findings and approve before anything is destroyed. The software proposes; a person decides. Nothing is removed without sign-off.
- Permanent redaction. Approved items have their underlying text layer removed and metadata stripped — not a visual cover. Nothing is recoverable from the output file.
- Verify. Every redacted file is re-scanned. If sensitive data still remains, the file is quarantined and blocked from delivery. An operator can override only with an explicit, logged acknowledgment.
That fourth step is the one built for your job. The verify pass is what lets you release a file knowing a second, independent check confirmed the student data is gone — instead of trusting that the boxes landed in the right places.
To be clear about what software can and can't do: no tool can guarantee a perfect outcome, and FERPA judgment calls still belong to a person. What RedactWorks does is keep a human in the loop and refuse to deliver a file that fails its own re-scan. That's a defensible workflow, not a magic button.
Built for how records offices actually work
A single open-records request and a district-wide release are not the same job. RedactWorks runs three ways so the work fits the office doing it:
- Cloud — the edition that's live today. Hosted in an isolated tenant; start free and redact right in your browser, no install.
- Org — for teams that need more than one reviewer before a release goes out: a multi-reviewer approval workflow, currently available to organizations as a pilot. (Individual accounts are single-reviewer.)
- Local — a fully offline, air-gapped downloadable app for the most sensitive work. This edition is coming soon; it is not available to download yet.
On the hosted tiers, your documents are never used to train AI — and that's enforced by Google Cloud's Vertex AI Training Restriction, which is Google's contractual commitment, not just ours.
Frequently asked questions
Is RedactWorks FERPA compliant?
Compliance is something your office achieves through its process, not a checkbox a vendor can claim for you. RedactWorks is built to support a FERPA-defensible workflow: it requires human approval before redacting, permanently removes the text layer, and re-scans every output, blocking delivery if student PII remains.
Does it permanently remove the data, or just cover it?
It permanently removes it. Approved content has its underlying text layer deleted and metadata stripped, so there's no hidden layer to copy-paste back out.
Can more than one person review a release before it goes out?
Multi-reviewer approval is what the Org edition is built for — routing a release through more than one reviewer before it goes out. Org is currently available to organizations as a pilot; individual accounts are single-reviewer.
Can the documents stay entirely inside our own environment?
On every tier, your documents are never used to train AI. For fully offline work where documents never leave your environment, the air-gapped Local edition is coming soon. Organizations with specific deployment or data-residency needs can raise them as part of an Org pilot.
What if the tool misses something?
The verify pass exists for exactly that. It re-scans the redacted file and quarantines it if sensitive data is still present, so a miss is caught before delivery rather than after.