Get live legislative updates on your mobile devices

Download now

Back to blog
Government-Affairs Operations
4
min read
15 Sep 2026

Failed Redaction: How Information Leaks Through a Released File

Information escapes a redacted file in four main ways: ablack box drawn over text that was never flattened, metadata and documentproperties, tracked changes and comments left in the file, and hidden rows,columns, or slides. In every one of those cases the document looks correct whenyou open it.

That last point is the whole problem. These are not mistakesanyone can see. The reviewer opens the file, the sensitive material is covered,and the release goes out. The failure only becomes visible to someone who doessomething the reviewer did not do: select the text, open the properties panel,unhide a column.

The four ways it happens

A box drawn over text

The most common failure, and the one with the most publicexamples. Someone places a black rectangle over a paragraph in a PDF viewer ora word processor. Visually the paragraph is gone. Underneath, the text layer isuntouched, and it can be selected, copied, or extracted with any tool thatreads PDFs.

The fix is flattening: the redaction has to remove the underlyingcontent, not cover it. Purpose-built redaction tools do this by default.General document tools frequently do not, and the difference is invisible onscreen.

Metadata and document properties

Author names, the original filename, the network path thefile was saved from, revision counts, the software used, and in some cases GPScoordinates on embedded photographs. None of this appears on the page. All ofit travels with the file.

A released document whose properties show the full path to acase folder has disclosed the existence and naming of that folder, which isoccasionally more sensitive than the document itself.

Tracked changes and comments

A word processing file that went through review often stillcarries every edit and every margin comment. Accepting changes beforeconversion removes them. Converting to PDF without accepting them sometimespreserves them, depending on the settings, and a comment thread discussingwhether to release something is not what anyone wants attached to the releasedversion.

Hidden rows, columns, and slides

Spreadsheets are the worst offender here, because hiding acolumn is a normal working action rather than a redaction. A hidden column isfully present in the file, and unhiding it takes one click. The same applies tohidden worksheets, to filtered rows, and to hidden slides in a presentation.

Spreadsheets carry a second risk: cached values and formulasthat reference material not otherwise included. A cell displaying a total maycontain a formula naming the source rows.

Two more that catch people

The OCR text layer. A scanned document that has beenthrough optical character recognition carries a text layer beneath the image.Drawing over the image does not touch it.

Thumbnails and previews. Some formats embed a previewimage generated before the redaction was applied. The visible document isredacted, the embedded thumbnail is not.

A pre-release check that takes two minutes

Before any redacted file goes out, run it through this. Itis short enough to do every time, which is the only reason it works.

1.   Select all and copy the text out of the releasedfile, then paste it somewhere plain. If redacted content appears, the redactionwas not flattened.

2.   Open document properties. Check author, title,filename, and path. Strip what should not travel.

3.   Search the file for a term you redacted. If thesearch finds it, so will anyone else.

4.   Unhide everything. In spreadsheets, unhide allrows, columns, and sheets. In presentations, check for hidden slides.

5.   Confirm changes and comments are gone, notmerely displayed as final.

6.   Check the page count and file size against whatyou expect. A redacted file that is larger than the original usually meanscontent was added on top rather than removed.

None of that requires special tooling. It requires thediscipline of treating the released file, rather than the working file, as thething to inspect.

Why this keeps happening to careful people

It is tempting to read failures like these as carelessness.They are not, mostly. They happen because the tool used to redact was a generaldocument tool that was never designed to remove content, and because the personusing it had no way to see the difference.

That is a tooling and process gap rather than an attentiongap. The reviewer did look. What they looked at was a rendering that told themthe truth about the pixels and nothing about the file.

A redacted document anda document that merely looks redacted are indistinguishable on screen. Everyone of these failures is invisible in exactly the place people check.

Govflo appliesredactions to the file rather than over it, and locks them once applied, so areleased document cannot carry the original underneath. One unredacted masteris kept, with every case-specific redacted version linked back to it, whichmeans the question of which version went out with which request has an answerthat does not depend on filenames, and the redacted and unredacted copies canbe produced together for in camera review.

It does not decide what should be redacted. That judgmentstays with the caseworker who reviews and signs off, and the tooling onlyguarantees that what they approved is what actually leaves.

What to do if it has already happened

Move quickly and treat it as a disclosure rather than anerror to be managed quietly.

Pull the file from wherever it is published. Notify therequester and, where the exposed material concerns a third party, follow youragency's process for notifying them. Tell counsel. Record what happened in thecase file, because the next question anyone asks will be whether the samedefect affects other releases, and the honest answer requires knowing whichfiles were produced the same way.

Then check the batch. These failures come from a method, anda method that failed once has usually been applied more than once.

‍

Frequently asked questions

Is a black rectangle ever an acceptable redaction?
Should we release PDFs or the original file format?
Do we need to remove metadata on every release, even unredacted ones?

See it running on your statute

Govflo runs public records requests and open meetings from intake through to release, configured to the law that governs each request. Tell us about your agency and we will set up a working session.

Talk to us
Back to blog