Understand Verification Scope and Assurance Boundaries

Applies to: All editions

What verification establishes

A successful PDFSanitize verification establishes that the sanitized output could be structurally reopened and that the checks associated with the applied policy met their expected conditions at verification time.

Where hashes are recorded, the result can also be tied to the exact source and output bytes.

What verification does not establish

Verification does not certify that:

  • The visible page content contains no confidential information;
  • The selected profile matched the organization’s legal or security requirements;
  • Every possible PDF concealment technique or steganographic method was detected;
  • Copies outside the processed source path were sanitized;
  • The document was never disclosed before sanitization;
  • A recipient’s software will render or infer every feature exactly as the operator’s viewer does;
  • The operator, organization, or process has been independently audited or certified.

Detection scope for hidden text

The current analysis specifically detects invisible text rendering modes and text located completely outside the visible page. Those checks are useful but narrower than the full universe of potentially concealed information.

Maximum Assurance reduces reliance on original page-level PDF objects by reconstructing every page, but it still does not replace human review of the visible rendered content.

Evidence scope

A report or Certificate of Sanitization is strongest when retained with:

  • The exact sanitized PDF;
  • The source and output hashes;
  • The operator and case or document identifier;
  • The selected profile or custom policy;
  • The verification result;
  • The authorization or disclosure decision that explains why the operation was performed.

Treat the software result as technical evidence within the broader document-handling process.