Selectively sanitize supported PDF structures

Remove selected, documented metadata, annotation, form, attachment, and action entry points from an unsigned PDF and report observable residual structures.

When this tool is useful

Creating a reduced-interactivity working copy after choosing exactly which supported active structures should be removed and which source must be retained.

How local processing works

Switches cover the trailer Info dictionary, Catalog XMP Metadata, supported comments, supported HTTP(S) URI links, AcroForm and Widget entries, Catalog EmbeddedFiles plus AF/FileAttachment entries, and checked action entry points: Catalog OpenAction and AA, Names/JavaScript, and page AA. The output is reopened and those selected checked locations are inspected again.

How to use it

  1. Prepare a safe working copy: Keep every source unchanged and review the supported input, controls, and limits before processing. Creating a reduced-interactivity working copy after choosing exactly which supported active structures should be removed and which source must be retained.
  2. Process locally: Run the documented operation in this browser and stop if an unsupported structure is reported. Switches cover the trailer Info dictionary, Catalog XMP Metadata, supported comments, supported HTTP(S) URI links, AcroForm and Widget entries, Catalog EmbeddedFiles plus AF/FileAttachment entries, and checked action entry points: Catalog OpenAction and AA, Names/JavaScript, and page AA. The output is reopened and those selected checked locations are inspected again.
  3. Download and verify: Read the residual report, inspect document properties, annotations, forms, attachments, actions, and links in a specialist viewer, and use dedicated security tools when the threat model requires more than structural reduction.

Important limitations

Only the documented checked entry points are removed. Unsupported actions and annotations, unreferenced objects, earlier incremental revisions, content streams, private data, malware, steganography, and proprietary containers are not completely inspected; this is neither antivirus cleaning nor secure erasure.

Verify the downloaded result

Read the residual report, inspect document properties, annotations, forms, attachments, actions, and links in a specialist viewer, and use dedicated security tools when the threat model requires more than structural reduction.

Private by design

Your files stay in this browser. The tool does not upload the source or output to our servers.

Questions and answers

When is this tool useful?

Creating a reduced-interactivity working copy after choosing exactly which supported active structures should be removed and which source must be retained.

What does the browser actually do?

Switches cover the trailer Info dictionary, Catalog XMP Metadata, supported comments, supported HTTP(S) URI links, AcroForm and Widget entries, Catalog EmbeddedFiles plus AF/FileAttachment entries, and checked action entry points: Catalog OpenAction and AA, Names/JavaScript, and page AA. The output is reopened and those selected checked locations are inspected again.

Which limits must I understand?

Only the documented checked entry points are removed. Unsupported actions and annotations, unreferenced objects, earlier incremental revisions, content streams, private data, malware, steganography, and proprietary containers are not completely inspected; this is neither antivirus cleaning nor secure erasure.

How should I verify the result?

Read the residual report, inspect document properties, annotations, forms, attachments, actions, and links in a specialist viewer, and use dedicated security tools when the threat model requires more than structural reduction.

Related tools