What it adds to redaction
The redaction tool already rebuilds a redacted page as an image so the covered text can't be recovered. Redact → Verify → Certify goes one step further: it re-parses the file you just saved — not the editor's in-memory state, so a bug in the save itself couldn't produce a false-clean result — and turns the manual checklist from how to check a redaction worked into something that runs automatically every time.
The 7 checks
- No selectable text on redacted pages. Reads the saved page's text layer directly; fails if any survives.
- Metadata and attachments confirmed stripped. Re-checks Title/Author/Subject/Keywords, Producer/Creator, XMP metadata and embedded attachments on the saved bytes.
- Bookmarks reviewed. Walks the document's outline and flags — never edits — any bookmark title that repeats the text you redacted.
- Optional content groups (layers) reviewed. Flags any layer in the file, since a layer can hide content the default view doesn't show.
- Annotations on redacted pages reviewed. Flags any comment, sticky note or form field placed on a redacted page whose text repeats what you redacted.
- Single revision. Counts the file's
%%EOFmarkers; more than the expected one can mean an earlier, unredacted version is still inside the file. - Whole-document duplicate search. Searches every page — not only the redacted ones — for the text that was under your boxes, since duplicates in headers, footers or an appendix are exactly what the manual checklist warns about.
A check either passes, or is flagged for your review (something needs a human look, left untouched) or fails (the saved file itself has a problem). Nothing is ever silently fixed or deleted — bookmarks in particular are left exactly as they are, for you to edit yourself.
The certificate
Certify computes the SHA-256 hash of the exact file you saved, records the app version, the page and redaction-box counts, and the result of each check above, and signs that record with an ECDSA P-256 key built into the app. You get a downloadable .json certificate alongside the redacted PDF, plus an in-app summary listing each check. There's no separate typeset certificate PDF in this version — the JSON file and the in-app view are it.
How the signature works, precisely
Vault Studio Pro has no server and uploads nothing, so there is no infrastructure of ours in the loop when you save a redacted file — the certificate has to be signed the moment you save, inside your own browser tab. That means the signing key ships inside the app itself, the same as the app's other code. Anyone who inspects the built JavaScript can find it. This is a deliberately different, weaker guarantee than the key that signs Pro license purchases (which never leaves our infrastructure): a Redact → Verify → Certify signature proves the certificate came from an unmodified build of Vault Studio Pro and was not edited afterward — not that a person at this company personally attested your specific file. The two keys are kept completely separate for exactly this reason: a compromise of one could never be used to forge the other.
There is also no timestamp authority involved. The certificate's time comes from your own device's clock and is labelled as such — it is evidence of what the checks found, not of exactly when they ran.
What this is not
- Not a claim that your redaction is legally sufficient, court-admissible, or "provably redacted."
- Not a scan for Social Security numbers, names or any pattern you never boxed — it only re-checks the text you already redacted.
- Not a tool for verifying a PDF redacted by someone else, or in another program — it only runs on a file this save just produced.
- Not automatic bookmark cleanup — a matching bookmark is flagged, never rewritten or deleted.
Common questions
Is this a legal guarantee that a redaction is correct?
No. Verify only re-checks the specific things listed above, against the one file it just saved. It cannot know whether you boxed the right passages, and it is not a court-admissible attestation or a promise the redaction is legally sufficient. Treat the certificate as supporting evidence for your own file, and still do a manual check on anything that matters.
Who is the certificate's signature proving is it from?
It proves the certificate came from an unmodified copy of Vault Studio Pro's code and has not been edited since it was generated, using a key built into the app. It is not a secret only we hold: because everything runs in your browser with no server, both halves of this signing key ship inside the app, unlike the separate key that signs license purchases. Read "How the signature works" below for what that does and doesn't mean.
What happens if a check finds a problem?
A "flagged" result (a matching bookmark, layer, annotation or duplicate elsewhere in the document) is left exactly as it was — Vault Studio Pro never rewrites or deletes anything on your behalf. Go back to the editor, remove or redact the flagged content, and save again to get a clean certificate. A "fail" result (redacted text is still selectable, or metadata was not stripped) means something went wrong with the save itself; do not rely on that file.
Does Verify search for what I forgot to redact?
No. It only knows about the text that was under the boxes you already drew, and checks the rest of the document for THAT text. It does not scan for Social Security numbers, names or other patterns you never boxed — that is still on you, using the checklist in "how to check a redaction worked."
Is Verify + Certify free?
No, it's a Pro feature (Redact → Verify → Certify). The redaction tool itself, and everything on the /redact-pdf page, stays free with no page limit.
More questions? See the full FAQ or contact us.