BASALT · JOURNAL
PDF redaction vs password protection
A PDF password can stop an unauthorized person from opening a file, but it does not remove data from the file once it is opened. If a recipient should not see an account number, signature, or private paragraph, password protection alone is the wrong control.
Minimize the document first
Remove pages and content that are outside the recipient’s purpose. Permanently redact text and image regions, clear OCR and form values, and inspect annotations and attachments. A black rectangle or white highlight can leave the original content recoverable.
Add a password when appropriate
After verification, encrypt the final copy if the delivery policy requires it. Share the password through a different channel, and test that the recipient can open the file without weakening the protection. Avoid sending the password in the same message as the attachment.
Verify both controls
Confirm that removed values cannot be searched or selected, and confirm that the exported file prompts for the expected password. Keep the original protected and separate from the delivery copy.
Frequently asked questions
Can a password-protected PDF still be redacted incorrectly?
Yes. A recipient with access may uncover an overlay or extract hidden content. Verify permanence before encrypting.
Should I password-protect every redacted file?
Follow the sensitivity and delivery policy. Redaction and encryption are complementary, not interchangeable.
Does printing to PDF guarantee a clean result?
It can change layers, but it is not a substitute for checking pages, metadata, attachments, and OCR.
Doing it in Basalt
Basalt permanently removes sensitive content locally and verifies the release PDF, leaving password protection available as a separate delivery step. Download Basalt.
Redaction that proves itself
Basalt destroys the content you mark, then re-opens the file it wrote and proves the content is gone before it saves anything. Your documents never leave your Mac.