Zero-Trust PDF Studio is a small set of tools for the job of sending a document with parts of it removed: redact a PDF, check one for anything it carries besides the page, strip its metadata, or flatten its form fields. All four run inside your browser. There is no server doing the work, no account to create, and no limit on how many files you put through it.
It exists because the usual way to solve this problem is to upload a sensitive document to somebody else, which is a strange thing to have to do when the machine in front of you is perfectly capable of the job. The name is the idea: you should not have to trust the site with the file, and you should not have to trust its description of what it did either. Each tool checks its own output and shows you the result.
How it is built
The site is a static one. Pages are generated ahead of time with Astro and served as plain files from Cloudflare, which means there is no application server anywhere in the picture and no database. That is not a performance decision. A backend that does not exist cannot be breached, subpoenaed, or misconfigured into leaving documents open to the internet.
The libraries, and the one script that is not ours
The document work is JavaScript running in the page. Two libraries do the heavy lifting: pdf.js renders pages and reads their text, and pdf-lib assembles the file you download. Both run in the tab, on your machine, on a document that never travels. The only WebAssembly here is the handful of image decoders pdf.js uses for scanner formats such as JBIG2 and JPEG 2000, served from this site and loaded ahead of time so a scan still opens with the network off.
One thing runs that is not ours. Cloudflare's edge adds a Web Analytics beacon to pages on their way out, loaded from static.cloudflareinsights.com. It reports navigation timing and page views to an endpoint on this domain, it sets no cookies, and what it sends is about the page, not about any file you opened. It is the only third-party script here.
What the redaction engine does
Worth spelling out, because the difference between doing this correctly and appearing to do it correctly is invisible in the finished file.
The export pipeline, and the version that got it wrong
When you export, the document's form fields are flattened and its metadata cleared. Each page carrying at least one bar is then drawn at high resolution with the bars filled solid black, and that drawing becomes an image. Then the important part: rather than swapping the image into the existing document, a completely new PDF is built. Pages you never marked are copied into it; each page you did mark is replaced by a blank page carrying only its image. Nothing belonging to a marked page is copied across, so nothing from it can survive into the file you download.
An earlier version did it the other way, detaching the marked page in place and inserting a replacement. That leaves the original page's content in the file, unreferenced and fully readable, which is a failure that looks like a success from every angle except an inspection of the bytes. The how to properly redact a PDF page documents what went wrong and how it was found.
After the export, the new file is read back from its bytes and checked: the marked pages are confirmed to have no text left in them, the pages that kept their text are searched for everything you looked for and for anything that still looks like a Social Security, card or account number, and the file is inspected for hidden text, metadata, attachments, scripts and earlier saved versions. The same checks power the checker, which runs them on any PDF you have.
What it costs
Rebuilding a page as an image is what removes the text, and it is not free. A page you mark loses its text layer completely, so every word on it, not only the words you covered, stops being selectable, searchable and copyable, and assistive software can no longer read any of it. The file also gets larger. Pages you leave unmarked are copied across with their text exactly as it was, so the cost is paid per page rather than per document. They are not quite the pages that went in, since their form fields are flattened along with the rest of the document, but nothing on them is turned into an image and every word stays selectable.
The rebuild also drops document outlines, the tagged structure tree and named destinations, because those do not survive being copied between documents. That loss is accepted deliberately: an outline entry pointing at a removed page is one of the things that kept unredacted content alive in the older version.
What it cannot do
Password-protected documents are refused rather than partly handled. XFA forms, the kind some older enterprise software produces, cannot be flattened by the library underneath, and the tool says so when it meets one. Digital signatures do not survive any export, because rewriting the file is what breaks them; the original on your device is untouched.
Find and the checks read a page's text, so a scanned page with no text layer is invisible to them; those pages have to be marked and checked by eye, and the tools say which ones they are. Metadata inside a photograph embedded on a page you do not mark is not cleared, because it belongs to the picture rather than to the document. And because everything happens in the tab, a very large file makes the page slow while it works, and on a phone can run the browser out of memory.
Who makes it
Zero-Trust PDF Studio is made and run by Kordal Systems, a founder-led design and engineering studio in Kolkata, India. Its founder, Amiya Krishna Bera, wrote the redaction engine and these pages.
Accountability, and how to correct us
That is stated plainly because, on a site whose claim is about what happens to your file, who is accountable for the claim is part of it. There is no database behind the site and no account system, so there is no store of documents or users for anyone to hold. The site is free to use and is intended to be paid for by advertising, which is set out in the privacy policy; advertising is not running yet.
None of this has to be taken on trust: check these claims is the instructions for testing it yourself, including what those tests cannot show.
Corrections are welcome, particularly on the technical pages. If something here is wrong, say so and it will be fixed.