DPA available · Zero server storage

Bulk document redaction
for DSAR compliance

Process thousands of files in a single batch. The data subject's PII is preserved — everyone else's is redacted. Files never leave your browser.

11
file types
1,000s
files per batch
0
documents stored
2-layer
AI detection pipeline

Capabilities

Everything you need to respond to a data subject access request

When a data subject requests their personal data under GDPR, CCPA, or UK GDPR, you must redact all third-party PII before disclosure.

Selective PII preservation

Name the data subject. Their personal information is preserved across every file. All other individuals' PII is redacted — names, emails, phone numbers, addresses, NI numbers.

Bulk upload via ZIP

Upload a single ZIP or a Purview PST export. Nested ZIPs are extracted automatically and PST mailboxes are expanded into individual messages, with attachments and forwarded messages included in detection.

11 file types

PST, PDF, DOCX, XLSX, EML, MSG, HTML, TXT, CSV, JSON, ZIP. Covers the full range of data found in DSAR exports: Outlook mailboxes and email, Teams transcripts, spreadsheets.

Zero data retention

Documents stay in the browser. Only extracted text is sent for AI detection. Nothing is stored on our servers; our AI provider does not train on your text and deletes it within 30 days. Audit metadata only.

Process

How enterprise redaction works

01

Upload your data export

Drag in a ZIP, a PST, or individual files. Batches of thousands of files upload in seconds and process in parallel, with a full disclosure pack exported at the end.

02

Enter the data subject's details

Name, email addresses, phone number, NI number, employee ID, and other identifiers. The more fields you provide, the more precisely the tool distinguishes the subject from third parties.

03

AI detects and flags PII

A two-layer detection pipeline — inline regex and LLM classification — processes files in parallel. Each file shows detected PII in-context for review.

04

Review and export

Verify every detection before export. Add manual redactions for anything the AI missed. Download redacted files and a processing summary CSV for your internal records.

Trust

Built on enterprise infrastructure

SafeRedact is built on infrastructure providers — Anthropic, Vercel, and Supabase — that are each independently SOC 2 Type II certified. Their reports are available on request. SafeRedact is not separately certified at this time; documents never touch our servers, so the providers above are the security perimeter that matters.

Anthropic Claude
AI provider

Anthropic is SOC 2 Type II certified. Text is never used for training and is deleted within 30 days under our commercial terms.

Vercel
Hosting & compute

Vercel is SOC 2 Type II certified. Edge network, serverless functions, zero persistent storage of document content.

Supabase
Auth & metadata

Supabase is SOC 2 Type II certified. Stores only account data and job audit metadata. No document content.

Destructive redaction

Redacted content is removed from the document, not hidden behind boxes. There is nothing beneath a redaction to copy, extract, or recover.

No third-party CDNs

Every dependency is served from our own domain, so strict corporate networks and security policies do not interfere with processing.

UK GDPR
Supports Article 15
EU GDPR
DPA available
CCPA / CPRA
Consumer access rights
Pay after review, not before.

Process your files. Review every detection. Add manual redactions. Only when you're satisfied and ready to sign off — then you pay. Pilot terms, including the file allowance, are set with you before you start. No credit card required.

No upfront payment
Full review before you're charged
Pay only for verified, completed work

Use cases

Who uses SafeRedact Enterprise

DPOs & privacy teams

Process the redaction step of UK GDPR, EU GDPR, and CCPA access requests — often the most time-consuming part of meeting the statutory deadline.

Legal & compliance

Redact third-party PII from litigation holds, discovery sets, and regulatory disclosures. The processing summary documents your run for internal records.

HR departments

Employee DSARs cross HR records, payroll, performance reviews, and internal communications. Bulk processing detects PII across the full dataset in a single pass.

Outside counsel

Law firms handling DSAR responses for clients. Documents stay in the browser — only extracted text is sent for AI detection. Nothing is stored on our servers.

Ready to process your first DSAR?

Tell us about your data volume and compliance requirements. We'll scope the right plan.

Contact Sales Pilot Guide