Detect. Review. Redact. Verify.
What you see is exactly what gets removed. Every file is re-scanned afterward, and anything that survived is quarantined.
Detect
Sensitive data is found three ways at once: pattern rules, a privacy-detection engine, and an AI model that reads context. Scanned and photographed pages are covered through built-in OCR.
WHAT IT FINDS
Names, SSNs and identifiers, financial and medical data, student records, and contact details.
Highlight review
Each finding appears as a yellow highlight over text that stays readable, and you confirm it in context. Nothing is removed at this stage.
YOU SEE
Exactly what will be removed, before anything is removed.
Multi-reviewer approval
For organizations and teams — currently in pilot. Require one reviewer or several. An approval gate holds the document until everyone assigned has signed off, and a decision log records who approved what, and when. Reviewers can add redactions by hand and tag each with its legal exemption basis, which becomes a requester-ready withholding log (categories and counts, never the values). Individual accounts are single-operator self-review.
DEFENSIBILITY
A documented, multi-reviewer record for courts, audits, and oversight.
Permanent redaction
On approval, the underlying text is permanently removed — not covered — and document metadata is stripped, leaving no recoverable trace of the redacted content.
TRUE REMOVAL
The text layer is destroyed, not masked. Copy-paste recovers nothing.
Bring your own rules. They sharpen the AI — not replace it.
We detect the usual sensitive data out of the box. On the Organization tier, you decide what else counts as sensitive in your documents — define a pattern, format, or keyword, no code required, and it applies on the next scan.
Your formats
A district's student-ID layout, a firm's matter numbers, an internal case code — the things only you know to look for.
Three layers, one rule
A rule you add drives all three detectors at once — the pattern matcher, the privacy engine, and the AI prompt — so the model knows what to look for.
In your hands
Add and edit rules yourself from the Rules screen — no tickets, no waiting. What's sensitive is your call.
If anything survives the re-scan, the file is held back.
After redaction, every file is re-extracted and re-scanned for sensitive data. If anything survived, the job is quarantined and blocked from delivery automatically — a leaking file can't go out by accident. Releasing one anyway takes a deliberate, logged override, so there's always a record of who did it.
Illustrative — sample verification summary.
Scans and images, covered.
OCR with preprocessing
Image-based PDFs and photographs are read with OCR and image cleanup, so redaction reaches text that lives inside a scan.
Vision fallback
When a page is too low-quality for confident OCR, a vision model takes a second look.
See the workflow on your documents.
Start free — no card required. Or see which deployment option fits your organization.