RedactWorks
Log inStart free
← All articles

GUIDE · TRUST & SECURITY

Secure Document Redaction: Is It Safe to Upload Your Files?

Before you redact a single page, you ask the only question that matters: where does this file go, and who can read it on the way? You're about to hand a stranger's software a document full of Social Security numbers, medical histories, or a minor's name — the exact data a leak turns into a legal incident. That hesitation is correct. Secure document redaction isn't about a slicker editor. It's about being able to answer that question with an architecture, not a slogan.

Most redaction tools skip the answer. They show you a black box over text and call it done. We'll get to why that's dangerous further down — but first, the part you actually care about: what happens to your file once it leaves your screen.

"Is it safe to upload documents for redaction?" — answer it honestly or not at all

Here's the honest version, and honesty is the whole point of a trust page. RedactWorks runs in the cloud by default. That means your file leaves your machine and is processed on Google Cloud. We're not going to tell you that's "100% private and secure," because for a hosted service that phrase is meaningless — data that travels can never carry an absolute guarantee. Anyone who tells you otherwise is selling, not explaining.

What we can tell you is exactly what protects the file and exactly how far you can verify each claim yourself. That's the difference between a promise you have to trust and an architecture you can inspect.

Your documents are never used to train AI — and that's Google's commitment, not just ours

The first fear with any AI tool is that your data becomes someone's training set. With RedactWorks, it doesn't.

Your documents are processed by Google Cloud's Vertex AI (now part of the Gemini Enterprise platform), which is contractually barred from using customer content to train its models. Google's own data-governance documentation states that customer data "is not used to train foundation models," and the underlying Training Restriction lives in the Service Specific Terms that form part of the Google Cloud Agreement and Cloud Data Processing Addendum. So the no-training guarantee isn't RedactWorks marketing — it's Google's contractual commitment, sitting underneath ours.

This matters as a contrast, too. Many public-records and redaction tools are simply silent on AI training in their public terms — the words "train" and "model" never appear. Silence isn't a denial, and we won't claim they train on your data. But "we put our answer in writing" beats "we never said" every time you're the one whose documents are at stake.

One nuance we refuse to blur, because blurring it is how trust pages lie: "never used to train AI" is not the same as "never stored." Those are two different promises. We make the first one plainly. For the second, see the next section — because the honest answer there is better than the overclaim.

Nothing stored means nothing to breach: one-click deletion after download

You can't leak a file that no longer exists. When your redaction is done and you download the result, your original upload and every working copy are deleted. The moment you're finished, nothing sensitive remains on the platform to be breached, subpoenaed, or mishandled.

Notice the precise claim. We're not saying your file is never written to disk during processing — it is; that's how processing works. We're saying it doesn't linger. That's a claim you can confirm: download your file, then go looking for it. It's gone.

The verify gate: we don't assume the redaction worked

Private redaction software earns the word "secure" only if the output is actually clean. A black box drawn over text isn't redaction — the underlying characters stay in the file, recoverable with a copy-paste. The leak you read about in the news was almost always this: a visual cover-up over live text.

RedactWorks removes the text layer and strips the metadata — the redacted content is taken out of the file, not covered. Then it does the thing most tools skip: it re-scans the finished file. If anything sensitive remains, the verify gate blocks delivery and quarantines the file. High-risk categories — SSNs, financial data, medical identifiers — are locked on by default. An operator can override only with an explicit, logged acknowledgment. The machine doesn't decide your document is safe; a human reviews it, and a second pass refuses to release it if the review missed something.

That's the defensible posture: human-in-the-loop, plus a gate that fails closed.

Who holds the data — and for how long

"Secure" isn't one setting. It's a short list of specifics you can check:

We make the claims we can defend and no more. That restraint is the point — a security page that promises everything is a security page nobody checked.

Frequently asked questions

Is it safe to upload documents for redaction to a cloud tool?

It's as safe as the tool's architecture and its written commitments make it. With RedactWorks hosted, files are never used to train AI (Google's contractual Training Restriction), are deleted on your command after you download (one click wipes originals and working copies), and pass a verify gate before release.

Is my document used to train AI?

No. This is enforced by Google Cloud's Vertex AI Training Restriction — Google's own commitment, not only ours.

Is my file stored after I'm done?

Only if you want them to be. After you download, one click permanently deletes your original and every working copy, and we re-scan storage to confirm. The redacted, PII-free output is kept for up to a year so you can re-download it — or delete that too. We don't claim files are never written during processing — they are, and then they're deleted when you say so.

What's the most private way to run redaction software?

The most private tool is the one that stores the least, for the shortest time, with commitments you can verify. Ask any vendor three questions: is my data used to train AI, how long is my file kept, and is the output re-checked before release. RedactWorks answers those in writing: never, deleted on your command, and yes — a verify gate.

Secure document redaction isn't a feeling — it's a chain of specifics you can check. See exactly what we put in writing on the Trust & Security page.

See it on your own documents

Start free — no card required. Run detect, review, and redact, then watch the verify gate refuse to release a file that still has sensitive data in it.