Visual black boxes are not enough
A redaction can look convincing while the original text survives underneath. NoblePDF's destructive export path is therefore checked with unique marker strings and independent inspection rather than appearance alone.
ORIGINAL_SELECTABLE_TEXT_364 before vs after export - verify it yourself.The deeper adversarial test
During the independent V5.8.36.6 audit, a source PDF was built with the unique marker NOBLE-MARK-SECRET-5590. The redacted output was decompressed for inspection using:
| Channel checked | Observed result |
|---|---|
| Marker in source | 1 occurrence |
| Marker after redaction export | 0 occurrences |
| PDF annotations carrying secret markers | Removed on destructive/redacted pages |
| Document metadata markers | Not carried into the fresh export document |
| Whiteout / existing-text replacement | Same destructive flatten path; original body and annotation text removed in the audit |
Downloadable regression pair
The pair below is a smaller smoke fixture used during the export redesign. The source contains the extractable marker ORIGINAL_SELECTABLE_TEXT_364; the redaction output contains no extractable text. In this destructive redaction path the affected page is rasterised into page artwork, so searchable/selectable text on that redacted page is intentionally lost as part of removing the original content.
SHA-256 bc0040c9…799b69225,898 bytes ↓NoblePDF redaction output
SHA-256 fb9e1260…998a92f44,762 bytes ↓
Why destructive pages are different
NoblePDF's normal export tries to preserve original PDF page objects when edits are non-destructive. Redaction, whiteout and replacement of existing PDF text are deliberately different: the affected page goes through a destructive flattening path so hidden original page text is not simply left behind beneath an overlay.
Important boundary: this test describes NoblePDF's tested export behaviour. It is not a universal certification that every redaction workflow or every third-party PDF is safe. For high-consequence documents, verify the exported file independently before sharing it.
A practical verification checklist
- Search the output for the exact sensitive phrase.
- Try selecting/copying text in the redacted region.
- Inspect annotations/comments if the source used them.
- Inspect document properties and metadata for sensitive values.
- For high-risk material, use a second PDF tool or decompressed-object inspection.
Why we check more than page text
Sensitive information can live outside the visible content stream. PDF annotations may contain comments, document metadata may contain names or subjects, and some save workflows append a new revision while older bytes remain in the file. That is why the adversarial audit tested multiple channels instead of stopping when text selection failed.
In the tested NoblePDF redaction path, destructive pages are rebuilt into a fresh export document rather than copied as original page objects with a black rectangle placed on top. The independent test then looked for the unique secret marker after decompression, checked annotation payloads, and inspected the exported document metadata. The marker was present once in the source and zero times after the tested redaction export.
Two fixtures, two levels of evidence
The downloadable pair on this page is a compact smoke regression: it demonstrates that an ordinary searchable marker disappears from extractable page text after a NoblePDF redaction export. The later adversarial test was deliberately harsher and used NOBLE-MARK-SECRET-5590 plus annotation and metadata markers. Publishing both is useful because the small fixture is easy for anyone to inspect, while the adversarial measurements describe the wider leak search used during release review.
Redaction is a high-consequence operation, so NoblePDF does not describe one passing fixture as a universal security certification. The practical rule is to verify the exact document you intend to share.