Applies to: All editions; available report formats vary by edition
Keep the evidence set together
A reliable sanitization record should remain associated with the exact sanitized file it describes. Where the workflow requires formal evidence, retain:
- The sanitized PDF;
- Its output SHA-256 fingerprint;
- The source SHA-256 fingerprint where permitted;
- The applicable TXT, PDF, CSV, or JSON report;
- The Enterprise Certificate of Sanitization when used;
- The operator or case identifier;
- The authorization or disclosure record.
Protect the source separately
The source PDF is not overwritten. It can still contain the metadata, embedded content, historical revisions, or other information that motivated sanitization.
Store the source under the retention and access controls appropriate to its sensitivity. Do not place the source and sanitized output in a shared recipient folder merely because their filenames are similar.
Preserve originals of evidence files
Reports, CSV files, and JSON files can be edited after export. Preserve an original copy in a controlled repository before performing transformations, redactions, imports, or formatting changes.
Where evidence integrity matters, record a cryptographic hash of the exported report or certificate under the organization’s normal evidence process.
Use filenames as labels, not proof
A name such as .sanitized.pdf is useful operationally but does not prove that a file is the intended verified output. Use the SHA-256 fingerprint and report relationship for high-assurance matching.
Retention and privacy
Reports can contain full source and output paths, Windows usernames, machine information, document names, findings, and file fingerprints. Treat reports and certificates as potentially sensitive operational records and restrict access accordingly.
