Control over AI
Documentation
Document Redaction

Document Redaction: clean documents before sharing

How the Document Redaction module works: the review screen, document profiles, where processing runs, and what the admin sees.

Het_Grote_PII-Dossier.pdfOpen another…Defaultorg default130%4 / 23Draw box

Friday night - Emergency Department

It was pouring when the first ambulance pulled into the grounds of St. Catherine's Hospital on Maple Avenue 112 in Riverside at 19:42. Nurse Sophie Lambert wiped her hands and took a deep breath.

On the stretcher lay Michael Brennan, a 34-year-old plasterer. Born on March 11, 1992, living at Elm Street 47 in Riverside. He gave a mobile number that Sophie quickly noted: +1 415 555 0148. His BSN, 184629375, was already in the system.

Search detections
46 found · 46 selectedDeselect all
BSN3
184629375
CITY6
Riverside
DATE5
March 11, 1992
GIVENNAME12
Sophie
Michael
Sophie
PHONE4
+1 415 555 0148
STREET7
Maple Avenue 112
Elm Street 47
SURNAME9
Lambert
Brennan
Mask a term (no mouse needed)
Type a word from the documentMask
46 items will be removedPreviewAnonymise (46)
Review each finding in a document and remove, replace, or mask it before you share.

Document Redaction turns a PDF into a clean copy: open it, review what detection found, and save an anonymised version before the document is shared or sent to an AI tool.

What it does

  1. Someone opens the redaction screen and picks a PDF.
  2. BeeSensible detects sensitive data using the organisation's document profile: names, account numbers, addresses, phone numbers.
  3. Every finding starts selected and is highlighted on the page. The user unticks anything that should stay, draws a box over anything detection missed, or masks a word everywhere in the document in one click.
  4. Preview shows the result; Anonymise produces the clean copy.

In that copy the selected text is genuinely removed from the file and covered with a black box. Hidden document properties (metadata) are also wiped when the file is processed in the cloud. The original is never modified; the clean copy is a separate file.

Where your team finds it

PlaceWhat it offers
DashboardDocument Redaction → Redact. Members without an admin role see only this part.
Desktop appThe Documents tab, with Anonymise, Insights, and Profiles inside it. The clean copy is saved to a location the user picks.
ExtensionThe Documents tab in the sidebar. A PDF can be dragged in straight from the page; after the review step the clean copy sits in the sidebar as a card, one click away from being attached to the chat or email the person is writing. Files up to 25 MB; the extension always uses the organisation's default profile.

Document profiles

A document profile is a named, reusable set of the data types BeeSensible looks for in a document. Each type is on or off, grouped by category. Unlike the detection profiles in Realtime Privacy, document profiles have no app assignment and no per-type levels: they only decide what gets found.

Profiles are managed in the dashboard under Document Redaction → Profiles:

  • BeeSensible ships one built-in profile, BeeSensible Pro. It carries the BeeSensible label and cannot be edited or deleted.
  • New profile creates your own: a name, a description, and a toggle per data type. A new profile starts with everything on; the editor is the same one Realtime Privacy uses, with search and grouping by category.
  • One profile is the default, marked with a star labelled Default. It applies automatically whenever someone redacts a document. Change it with Set default on another profile.

While redacting, the user can pick another profile from the bar above the document; detection then runs again with that profile, for that document only. The default profile shows the tag org default. The desktop app lists the profiles read-only; editing happens in the dashboard.

Where processing runs

  • Dashboard and extension. The document is sent to BeeSensible's servers inside the EU, processed in working memory, and discarded straight after. Nothing is stored.
  • Desktop app. It follows the organisation's detection plan. With on-device detection the document is processed entirely on the machine and never leaves it; if the local engine is not running, the app says so and redaction is unavailable at that moment, rather than quietly routing the file to the cloud. On a cloud plan the desktop app takes the same route as the dashboard. The bar above the document shows which of the two is active: On-device or Cloud.

Which engine runs

Documents use the same detection engine as Realtime Privacy: Bombus, with the same 65 data types. See The detection engine.

Supported files

PDF files only. A scanned PDF without a text layer produces no automatic detections; the screen says so, and drawing boxes by hand still works.

What the admin sees

Under Document Redaction → Insights the dashboard shows two counters for the chosen period: Documents anonymised and Sensitive items removed. If your organisation uses department insights, a per-department split is shown as well (redactions per person); departments below the minimum group size are bundled.

Document content never reaches the dashboard: only counts are recorded, and there is no per-employee view. Documents processed entirely on-device do not appear in these organisation figures; the user sees those numbers in the desktop app, and they stay on the device too.

Insights in the dashboardYour organisation's document figures, with period and department filters.

Who can use it

Document Redaction is a separate module that is switched on per organisation and belongs to the subscription. With the module off, the feature is absent from the dashboard, the desktop app, and the extension, and the server refuses any document processing. With it on, every member of the organisation can redact documents; admins additionally see Insights and Profiles.