Before You Share: What Sanitize and Redact Actually Do
Sanitize strips scripts, embeds, and metadata. Auto Redact blacks matching pages. Neither alone is a share checklist—and a black box is not content removal.

Sharing a PDF safely is two jobs. Sanitize strips active or covert extras (JavaScript, embedded files, metadata, links). Auto Redact targets visible text you do not want readable on the page. Redact what must not be readable, then sanitize what should not travel with the file.
Sanitize does not hide names on the page
Sanitize (POST /api/v1/security/sanitize-pdf) edits the document catalog and page dictionaries. With the portal defaults (most remove flags true, removeFonts false) it removes:
- Document and page JavaScript hooks (
AA,OpenAction) - Embedded file name trees
- XMP and Info metadata
- Link annotations
It does not rewrite paragraph text. A Social Security number sitting in the content stream is still there after sanitize. Treat sanitize as share hygiene for embeds and scripts, not as privacy redaction.
Auto Redact matches text, then blacks out the page
Auto Redact (POST /api/v1/security/auto-redact) takes a comma-separated listOfText. For each page it extracts the text layer and checks whether any term appears. On a hit, it paints a full-page black rectangle over that page.
That is blunt by design: matching pages go dark; non-matching pages stay untouched. Image-only scans with no text layer will not match terms until you OCR them first. Always spot-check the download (including select/copy or a text extract) before you send the file.
Black box vs real redact
Drawing a black rectangle in a viewer is not the same as deleting the underlying text objects. Classic "fake redaction" leaves glyphs in the content stream so copy, search, or pdftotext can still recover the secret under the ink. True redaction removes or replaces those objects so the string is gone from the file bytes.
PDF123's Auto Redact is a server-side match-and-overlay step for pattern hygiene, with review required. It is not a certified e-discovery redaction suite. If your policy needs content removal guarantees, verify with extraction on the output (and keep the unsanitized original under your retention rules).
A practical pre-share path
- Unlock only if you are allowed to remove encryption.
- OCR scans so Auto Redact can see terms.
- Run Auto Redact with the strings that must not ship.
- Run Sanitize on a copy meant for distribution.
- Open the result and confirm pages, attachments, and text behavior.
Browser tools need no account. For the same ops from a script, see Developers.