We tested 6 free PDF redaction tools. 4 left the SSN in the file.
Updated
Short answer
In our September 2026 test of six free PDF redaction tools, every tool removed the text we marked. But iLovePDF, PDF24, Smallpdf and Xodo all produced files that still held the SSN from a form field, and all four kept the patient’s name in the metadata. GhostX (ours) and SafeRedact left nothing recoverable.
What we tested, and how
We built one synthetic document — a one-page "patient intake summary" — and ran it through every free, no-account PDF redaction tool we could use end to end: GhostX, SafeRedact, PDF24, Smallpdf, Xodo and iLovePDF. Every value in it is fake: the SSN is 078-05-1120, a number the Social Security Administration voided decades ago; the card is the standard 4111 test number; the email and phone are reserved example values.
The page shows six sensitive values (name, SSN, email, phone, card number, medical record number) plus a filled-in form field that displays the SSN again. Behind the page, the file also carries the places real-world redaction leaks come from:
- Document metadata: the patient’s name as Author and in the Title, the medical record number as Subject, and the name again in the XMP metadata block.
- A sticky-note comment: "Call Jane Q. Testperson at (212) 555-0142".
- A bookmark titled with the patient’s name.
- A line of white text containing the email address — invisible on the page, present in the text layer.
For each tool we marked every visible value and the form field — using the tool’s own detection or search where it had one and drawn boxes where it didn’t — applied the redaction, downloaded the result, and scanned it. We did not mark the hidden items: the question there is whether a tool cleans up what a reviewer cannot see.
The scanner looks where anyone with free software could look: the text a PDF reader extracts, the metadata, annotation and form-field values, bookmarks, and every byte of the file with all compressed streams unpacked — including leftover objects nothing references any more. Before trusting it, we confirmed it finds every planted value in the unredacted document and reports a PII-free control file as clean. Because it cannot read pixels, we also inspected the flattened outputs by eye.
Results
| Tool | Marked text | Boxed form field (SSN) | Metadata (name, MRN) | Sticky note & bookmark | Hidden white text | Verdict |
|---|---|---|---|---|---|---|
| GhostX (ours) | Removed | Removed | Removed | Removed | Removed | Clean |
| SafeRedact | Removed | Removed | Removed | Removed | Removed | Clean |
| PDF24 | Removed | Kept in form data | Kept | Removed | Removed | Leaks |
| Xodo | Removed | Kept in form data | Kept | Kept | Removed | Leaks |
| Smallpdf | Removed | Kept in form data | Kept | Kept | Kept | Leaks |
| iLovePDF | Removed | Could not be marked; kept | Kept | Kept | Removed | Leaks |
Not tested: pdfredaction.com requires an account to redact PDFs; pdf-redaction.com’s editor works without one but requires a login to save the result (its auto-detection found all six visible values and the hidden white text — the best detection we saw); Sejda has no online redaction tool and says its Whiteout feature hides but does not remove text; Adobe Acrobat’s online redaction needs an account.
What leaked, and why
The good news first: every tool removed the text it was told to remove. The classic failure — a black rectangle drawn over text that is still selectable underneath — did not happen in any output we tested.
The form field is where things went wrong. A PDF form stores a field’s value in the file’s form data, separately from what is painted on the page. PDF24, Smallpdf and Xodo all let us draw a redaction box over the SSN field, and all three exported a file whose form data still says the field holds 078-05-1120 — readable by any tool that reads PDF forms. PDF24 is the instructive case: it turned the page into an image, so nothing on the page can be selected, yet the form data survived alongside it. iLovePDF never displayed the field at all, and its redaction tool can only select text or whole pages, so the SSN could not be marked in the first place.
All four of those tools also kept the document’s metadata, so each "redacted" record still names the patient as its author and carries the medical record number in its Subject field. Smallpdf and Xodo also kept the sticky note (with the name and phone number) and the bookmark; their outputs carry the same PDF engine signature, which fits the identical results. Smallpdf, which has no search or detection feature to find it, also kept the hidden white-text email in the text layer.
The two clean tools share one design: they turn every page into an image with the boxes burned in and build a new file from those images, so nothing from the original file — form data, metadata, comments, bookmarks — is carried over. The cost is that the text in the result is no longer selectable.
Auto-detection helps, but never finishes the job
No tool found everything on its own. SafeRedact’s detection found the name, SSN, email, phone and the hidden white text but missed the card number, the medical record number and the form field, and split the name into pieces that left a sliver uncovered until we drew over it; in the final image one letter of the surname is still visible at the seam between two boxes. SafeRedact says only the document’s extracted text is sent to its server for detection, and free downloads carry a watermark.
GhostX found the SSN, email, phone, card number and the hidden white text, and missed the medical record number, which needs a custom detection rule. It also missed the name — and the reason was a bug this test uncovered: our on-device name detector was running, but a change in the library it uses meant every name it found was discarded before reaching the page. We fixed it the same day (GhostX v4.74.2); re-running the same document now suggests the full name. The results table reflects the tool as tested, before the fix.
Xodo and iLovePDF offer search rather than detection; searching for each value also found the hidden white-text copy of the email. PDF24 and Smallpdf have no search or detection in their redaction tools.
How to check any redacted PDF before you send it
Whichever tool you use, a few minutes of checking catches everything this test found:
- Open the redacted file and select all text (Ctrl/Cmd+A), then paste it somewhere. Anything that pastes was not removed.
- Open the document properties (File → Properties in most readers) and read the Author, Title, Subject and Keywords fields.
- If the original had form fields, check whether the redacted file still does — or flatten the form before redacting.
- Open the comments and bookmarks panels. Sticky notes and bookmark titles survive many redaction tools.
- When in doubt, use a tool that rebuilds every page as an image, or run a separate "remove metadata" step after redacting.
Limits of this test
- One document, one run per tool, on one day. Tools change, and a result here is a dated snapshot, not a certification.
- Hidden-channel results measure clean-up the tester did not ask for. Some tools offer a separate sanitize or remove-metadata feature that may clean these when used; we tested each tool’s redaction flow on its own.
- Free tiers only. Paid tiers may behave differently.
- Where a vendor describes where processing happens, we quote its own description; we did not independently audit any tool’s network traffic for this test.
Disclosure, and how to reproduce it
GhostX is our product. We tested it with the same document, the same steps and the same scanner as every other tool, and the one GhostX flaw the test surfaced is reported above rather than quietly fixed.
The test document and the scanner are published so anyone can repeat this. Redact the document with any tool, install pdfjs-dist with npm in the folder holding the two script files, and run node check-leaks.mjs on the output. If you make one of these tools and believe a result is wrong or has changed, contact us and we will re-test and update this page.
Frequently asked questions
-
Which free PDF redaction tool is safest?
In this test, GhostX and SafeRedact were the only tools whose output contained none of the planted data. Both rebuild every page as an image. Whatever you use, check the result: select all text, read the document properties, and look for form fields, comments and bookmarks.
-
Why did the SSN survive when the page was flattened?
A PDF form stores each field’s value in the file’s form data, not only on the page. Flattening the page into an image removes what is painted there, but if the form data is copied into the new file, the value is still readable by any program that reads PDF forms.
-
Does redaction remove PDF metadata?
Not necessarily. Four of the six tools we tested kept the Author, Title and Subject fields, which in our test document named the patient and held the medical record number. Remove metadata as a separate step, or use a tool that rebuilds the file.
-
Can I run this test myself?
Yes. Download the test document and the scanner linked on this page, redact the document with any tool, install pdfjs-dist with npm, and run the scanner on the output. It lists every place a planted value can still be recovered.