Security model

What the editor can—and cannot—see.

FreeRedact minimizes trust by processing source documents in a separately deployed, cross-origin editor and rebuilding sanitized outputs locally.

Network boundary

The editor at app.freeredact.com loads application code, OCR assets, and face-detection assets only from its own origin. It does not load advertising, session replay, third-party analytics, or cloud AI. The public site at www.freeredact.com has no messaging bridge and cannot read the editor DOM or memory under the browser’s same-origin policy.

Export boundary

Images are decoded into a fresh canvas, redactions are painted into the pixel buffer, and a new image is encoded without inherited metadata. PDFs are rendered page by page and rebuilt from sanitized page images.

Limitations

Automated detection can miss information. FreeRedact is an assistive review tool, not a legal compliance certification. Password-protected PDFs, video, audio, and files over the documented limits are not supported in the MVP.

Vulnerability reporting

Please report suspected security issues privately to hello@freeredact.com. Do not include a real sensitive document in the report.