GUIDE · TRUST & SECURITY
Secure Document Redaction: Is It Safe to Upload Your Files?
Before you redact a single page, you ask the only question that matters: where does this file go, and who can read it on the way? You're about to hand a stranger's software a document full of Social Security numbers, medical histories, or a minor's name — the exact data a leak turns into a legal incident. That hesitation is correct. Secure document redaction isn't about a slicker editor. It's about being able to answer that question with an architecture, not a slogan.
Most redaction tools skip the answer. They show you a black box over text and call it done. We'll get to why that's dangerous further down — but first, the part you actually care about: what happens to your file once it leaves your screen.
"Is it safe to upload documents for redaction?" — answer it honestly or not at all
Here's the honest version, and honesty is the whole point of a trust page. RedactWorks runs in the cloud by default. That means your file leaves your machine and is processed on Google Cloud. We're not going to tell you that's "100% private and secure," because for a hosted service that phrase is meaningless — data that travels can never carry an absolute guarantee. Anyone who tells you otherwise is selling, not explaining.
What we can tell you is exactly what protects the file and exactly how far you can verify each claim yourself. That's the difference between a promise you have to trust and an architecture you can inspect.
Your documents are never used to train AI — and that's Google's commitment, not just ours
The first fear with any AI tool is that your data becomes someone's training set. With RedactWorks, it doesn't.
On the hosted tiers, your documents are processed by Google Cloud's Vertex AI (now part of the Gemini Enterprise platform), which is contractually barred from using customer content to train its models. Google's own data-governance documentation states that customer data "is not used to train foundation models," and the underlying Training Restriction lives in the Service Specific Terms that form part of the Google Cloud Agreement and Cloud Data Processing Addendum. So the no-training guarantee isn't RedactWorks marketing — it's Google's contractual commitment, sitting underneath ours.
This matters as a contrast, too. Many public-records and redaction tools are simply silent on AI training in their public terms — the words "train" and "model" never appear. Silence isn't a denial, and we won't claim they train on your data. But "we put our answer in writing" beats "we never said" every time you're the one whose documents are at stake.
One nuance we refuse to blur, because blurring it is how trust pages lie: "never used to train AI" is not the same as "never stored." Those are two different promises. We make the first one plainly. For the second, see the next section — because the honest answer there is better than the overclaim.
Nothing stored means nothing to breach: auto-delete after download
You can't leak a file that no longer exists. When your redaction is done and you download the result, your original upload and every working copy are deleted. The moment you're finished, nothing sensitive remains on the platform to be breached, subpoenaed, or mishandled.
Notice the precise claim. We're not saying your file is never written to disk during processing — it is; that's how processing works. We're saying it doesn't linger. That's a claim you can confirm: download your file, then go looking for it. It's gone.
The verify gate: we don't assume the redaction worked
Private redaction software earns the word "secure" only if the output is actually clean. A black box drawn over text isn't redaction — the underlying characters stay in the file, recoverable with a copy-paste. The leak you read about in the news was almost always this: a visual cover-up over live text.
RedactWorks removes the text layer and strips the metadata, so nothing is recoverable from the output. Then it does the thing most tools skip: it re-scans the finished file. If anything sensitive remains, the verify gate blocks delivery and quarantines the file. High-risk categories — SSNs, financial data, medical identifiers — are locked on by default. An operator can override only with an explicit, logged acknowledgment. The machine doesn't decide your document is safe; a human reviews it, and a second pass refuses to release it if the review missed something.
That's the defensible posture: human-in-the-loop, plus a gate that fails closed.
You choose who holds the data: the privacy ladder
"Secure" isn't one setting. It's a ladder, and the further down you go, the less you have to take on trust.
- Hosted, in your own isolated tenant. Your data is never shared with another customer. It runs on Google Cloud under Google's Training Restriction — never used to train AI, auto-deleted after download. This is the only tier live and self-serve today, and it's where you can start free in minutes.
- Your own Google Cloud project. The platform deploys inside infrastructure your data never leaves. This is for teams in pilot — an option you discuss with us, not a button you click today. At this tier, "your data stays yours" stops being a policy and starts being where the servers physically are.
- Fully air-gapped, on-premise. On your hardware, with on-device AI, no internet connection at all. Nothing can leave because there's no path out. This edition is coming soon — not downloadable today, and we won't pretend otherwise.
Read that ladder carefully. The phrases "never leaves you" and "nothing can leave" are reserved for the architectural tiers, where they're literally true. On the hosted tier we make the claims we can defend and no more. That restraint is the point. Compare the deployment options to see which rung fits your risk tolerance.
What teams get in writing
For a records office, legal team, or healthcare org, "secure" also means paperwork your counsel can sign. RedactWorks offers a signed Data Protection Agreement (DPA) — the template is ready for your legal review — and, for teams, multi-reviewer approval workflows with an audit trail. These team features are in pilot, not a shipped product with a customer roster, and we say so. FERPA and HIPAA compliance comes from product design plus that signed DPA, never from a badge we bought.
Frequently asked questions
Is it safe to upload documents for redaction to a cloud tool?
It's as safe as the tool's architecture and its written commitments make it. With RedactWorks hosted, files are never used to train AI (Google's contractual Training Restriction), are auto-deleted after you download, and pass a verify gate before release. For maximum control, the private-cloud and on-prem tiers keep data inside infrastructure it never leaves.
Is my document used to train AI?
No. On hosted tiers this is enforced by Google Cloud's Vertex AI Training Restriction — Google's own commitment, not only ours.
Is my file stored after I'm done?
Your original and working copies are deleted on download. Nothing stored means nothing to breach. We don't claim files are never written during processing — they are, and then they're deleted afterward.
What's the most private way to run redaction software?
The air-gapped, on-premise edition (coming soon): on-device AI, no internet, nothing can leave. Below that, your own Google Cloud project. Both trade convenience for an architectural guarantee instead of a promise.
Secure document redaction isn't a feeling — it's a chain of specifics you can check. See exactly what we put in writing on the Trust & Security page.