How to Redact a Scanned PDF or Photo of a Document
A scanned PDF or a photographed document usually has no text layer at all — just an image of the page. That means the usual copy-paste test tells you nothing, and every redaction has to cover the information visually, completely, and with an opaque box. SladdPDF can run local optical character recognition (OCR) in the browser to suggest where sensitive details are, but you still export in Secure mode, exactly as with a text-based document.
TL;DR
- A scanned page is an image with no searchable text, so the copy-paste test doesn't apply the way it does for text-based PDFs.
- SladdPDF's Smart Detect can run OCR locally in the browser to find ID numbers, names and similar details on scanned pages — with no upload.
- Always use a fully opaque box. Pixelation, blur or low opacity is not safe redaction on an image.
- Strip metadata on export — scanners and phone cameras can leave behind a device model, a username, or even location data.
- Verify with zoom and contrast instead of copy-paste — look for edges where text shows through the redaction.
Scanned PDF vs. regular PDF — what's the difference?
A regular PDF created digitally — say, exported from Word — usually contains a separate text layer alongside the visual page. That layer is what lets you search, select and copy text. It's also what makes a black box drawn over the text unsafe: the text underneath is untouched and can be lifted out, as covered in our guide to redacting a regular PDF.
A scanned PDF — or a photo of a document taken with a phone and placed into a PDF — normally has no such text layer. The whole page is one image. That changes the threat model: there's no hidden text layer under your redaction to worry about, because there's nothing to lift out with copy-paste. In exchange, every box you draw has to actually cover the detail completely in the image itself — there's no text to delete, only pixels to hide or remove.
Some scanned PDFs actually contain both: an invisible, OCR-generated text layer laid over the image by the scanning software, to make the document searchable. If your file has such a hidden text layer, the same rules as for regular PDFs apply — the text layer has to be removed, not just the image covered.
How to redact a scanned PDF with SladdPDF
- Open the scanned PDF on sladdpdf.com. The file is processed locally in your browser with JavaScript and WebAssembly, whether it's a scan, a photographed document or a regular PDF. Nothing is uploaded.
- Run Smart Detect to let local OCR read the page. When a page has little or no searchable text, Smart Detect automatically falls back to a local OCR engine built on the open-source Tesseract project, which recognizes text directly in the browser. The models download once and then run entirely on your device — the image never leaves your machine.
- Review the suggestions manually. OCR is an aid, not a verdict. Sharpness, the angle of a photo, and older scanners all affect accuracy. Watch especially for handwritten notes, stamps and text in headers or footers, which OCR is more likely to miss.
- Draw boxes with a generous margin. Cover the detail completely, with a little extra margin at the edges — a sliver of visible text at the boundary is often enough for someone to guess the rest.
- Export in Secure mode and remove metadata. Secure mode bakes the boxes into the image itself on export, so there's no layer left to peel them back off. Also enable metadata removal — scanned files can carry the scanner model, a username, or even location data from a phone camera, just like metadata in regular PDFs.
The mistakes that make image redaction unsafe
Because a scanned page is an image, it's tempting to "redact" it with tools built for images in general — a blur filter, pixelation, or a semi-transparent highlight. All three are unsafe:
- Pixelation and blur can be reversed. In 2022, security researchers at Bishop Fox showed how their tool Unredacter could reconstruct pixelated text by testing which character combinations produced the exact pixel pattern seen in the image. The attack works because pixelation is a predictable, mathematical operation — not because the text has actually been removed.
- Transparent or colored overlays let the shape of the text show through. A box with low enough opacity, or a colored highlight instead of a solid black fill, can leave the text readable after a small contrast adjustment.
- A separate image placed on top of the original. The U.S. National Security Agency warned as early as its own "Redacting with Confidence" guidance against covering sensitive content in images with a separate graphic layered on top — because that object can be moved or removed without anyone noticing, and the original image still sits underneath it in the file.
- Scanning at low resolution as a shortcut. A grainy scan doesn't hide information any better — it just makes it harder to see whether the redaction actually lines up, which raises the odds that the edges don't fully cover the text.
The same principle applies if you print a document, black it out by hand with a marker, and scan it back in: if the ink is thin or the light is strong enough, the text can still show through in the scan. Several well-known redaction failures have exactly this cause.
How to verify a redacted scan
Since there's no text to copy out of a scanned page, verification has to be visual instead:
- Zoom into every redaction. Look for edges where the shape of letters or numbers shows through, especially in the corners.
- Test contrast and brightness. Open the exported file in an image editor and temporarily push the contrast. If outlines appear under the redaction, it isn't holding.
- Check the metadata. Open the document properties and look for a scanner or camera model, a username, and any location data.
- Review the whole document, not just the page you edited. The same detail — an ID number, a signature, an invoice number — often reappears on other pages of a scanned document, as an attachment or a stamp.
This process complements the copy-paste test for regular PDFs — use whichever applies, depending on whether the document has a text layer.
This article is general guidance, not legal advice.
Ready to redact a scanned PDF?
SladdPDF runs 100% locally in your browser, with local OCR and Secure mode. Free with no page limit, no account needed.
Redact a PDF nowFrequently asked questions
Can I redact a scanned PDF that has no text layer?
Yes. A scanned page is already an image, so you draw boxes directly over what you see and export in Secure mode. SladdPDF can also run local OCR to suggest where sensitive details are on the page, so you don't miss anything.
Is it safe to pixelate or blur text in a photographed document?
No. Security researchers have shown that pixelated or heavily downscaled text can often be reconstructed by testing which text produces the same pixel pattern. Always use a solid, fully opaque box — never pixelation, blur, or a semi-transparent overlay.
How do I know OCR found all the sensitive text in a scan?
OCR is an aid, not a guarantee — accuracy depends on the scan's resolution and sharpness. Always review every page manually as well, especially headers, footers, stamps and handwritten notes, which OCR is more likely to miss.
Does Secure mode remove metadata from a scanned file?
Yes, if you enable it on export. Scanned files can carry metadata from the scanner or camera — such as the device model, a username, or location data from a phone photo — on top of whatever is visible in the image itself.