BASALT · JOURNAL

PDF redaction and chain of custody

2026-10-01 · pdf redaction chain of custody

Sensitive PDF handling has two goals: remove information from the release and preserve confidence in how that release was produced. A simple chain-of-custody record makes the source, decisions, and output easier to explain.

Assign stable versions

Record the source filename, hash or document identifier when your policy supports it, the redaction working copy, and the release filename. Avoid overwriting the source. Restrict access to the original and store the release separately.

Document review events

Record who prepared the redactions, who verified them, when the work occurred, and which rule or request governed the release. Log locations and categories, not the sensitive values themselves. Note any page omissions or attachments removed.

Verify the final artifact

Search for removed values, inspect page images and hidden layers, check metadata and attachments, and compare structure with the source. Preserve the verification result with the controlled case record rather than inside the shared PDF.

Frequently asked questions

Does a filename provide chain of custody?

No. Use consistent versioning and a record of people, times, and decisions.

Should hashes be used for every PDF?

Use them when your organization’s policy or the matter requires file-integrity evidence.

Can the redacted PDF replace the original?

Usually not. Retain the source under controlled access and treat the release as a separate artifact.

Doing it in Basalt

Basalt’s local processing and verification make it easier to create a controlled release without transmitting the source PDF to a remote service. Download Basalt.

Redaction that proves itself

Basalt destroys the content you mark, then re-opens the file it wrote and proves the content is gone before it saves anything. Your documents never leave your Mac.

DOWNLOAD BASALT 2.3.1 BUY $29 FREE FOR 24 HOURS · MACOS 13+