BASALT · JOURNAL
How to keep an audit trail for PDF redactions
A redaction audit trail should explain what was removed and why without reproducing the sensitive information. It gives reviewers confidence that the release copy was prepared deliberately and can be recreated if questions arise.
Record scope, not secrets
Capture the source filename, version, page range, redaction category, legal or business reason, reviewer, and verification date. Avoid putting the actual SSN, patient number, or confidential phrase into the log. Use a stable reference such as “page 4, account identifier.”
Separate working and release files
Keep the original protected and the redacted copy under a new name. Record the tool version and export settings when they affect the result. If two people review the copy, record both roles and the checks each person performed.
Verify in an independent pass
Search for removed values, inspect page images and attachments, and confirm that metadata and comments are handled. A verification result should be reproducible without reopening the sensitive source on an untrusted machine.
Frequently asked questions
What belongs in a redaction log?
Record page, location, category, reason, reviewer, and verification status. Do not copy the removed sensitive value into the log.
Is the audit trail part of the released PDF?
Usually no. Keep it with the controlled case or project record unless the recipient specifically requests it.
How long should I keep the log?
Follow the applicable retention policy for the matter. The log should remain available while the release decision may be challenged.
Doing it in Basalt
Basalt provides a local redaction and verification workflow so your internal record can describe the result without sending the source PDF to a cloud service. Download Basalt.
Redaction that proves itself
Basalt destroys the content you mark, then re-opens the file it wrote and proves the content is gone before it saves anything. Your documents never leave your Mac.