PromptShieldpromptShieldpromptShield
See it in actionFeaturesHow It WorksAI WorkflowsPeace of MindLicense managementCompliance monitoring
PricingDownload
Developers
OverviewAPI DocsAPI Keys
FAQs
Sign In
  1. Home
  2. Blog
  3. How it works
How it works2026-07-22· 5 min read

Reversible Redaction Explained: How Tokenization Lets You Un-Redact a Document

Permanent redaction destroys information forever. A great deal of real work — sending a contract to an expert, circulating a bundle, handing a file to a vendor for analysis — needs the opposite: identities removed for the outside world, but recoverable for you. That is what reversible redaction is for.

Key facts

  • Reversible redaction replaces each entity with a stable, unique token instead of a permanent black box, keeping the token-to-value mapping on your own machine.
  • The same real value always maps to the same token, so an entity stays consistent across an entire document or bundle.
  • Unlike permanent redaction, tokenized documents can be decoded back to the original identities whenever you need them.
  • The privacy of reversible redaction depends entirely on the mapping being stored locally rather than in the cloud.

The short answer

Reversible redaction replaces each piece of personal data with a stable, unique code — a token — instead of a permanent black box, and keeps a private code-to-value mapping on your machine. That lets you share a document with identities removed, keep the same token for the same person across an entire file, and decode it back to the originals internally when you need to. Ordinary redaction is one-way and destroys that ability.

Why one-way redaction isn’t always what you want

Permanent redaction is the right tool when a document is going into the public record. But a lot of work sits between “fully identified” and “gone forever”:

  • You need to send a contract to a vendor or expert with names stripped, but your own team still needs to know who is who.
  • The same individual appears on dozens of pages, and “[PERSON_14]” needs to mean the same person every time.
  • You want a third party to analyze a document, then map the results back to the real entities afterward.

Black boxes make all of this impossible. Once the content is destroyed, there is no path back.

How tokenization works

Instead of deleting an entity, a tokenizing tool:

  1. Detects each piece of personal data — names, addresses, IDs, account numbers.
  2. Replaces each one with a consistent token, so the same value always maps to the same code: “Jane Okafor” becomes [PERSON_14] everywhere in the document and across the batch.
  3. Stores the mapping locally — a private registry of token to original value that lives on your machine, never on a vendor’s server.
  4. Decodes on demand — when you, or a teammate on the same machine, need the real identities back, the tool reverses the mapping.

The document you share contains only tokens. The key to reverse them stays with you.

Reversible vs. permanent redaction

PropertyPermanent redactionReversible tokenization
Underlying dataDestroyedReplaced with a code, mapping kept locally
Can you recover identities?NoYes, from your machine
Consistent across a bundleNot inherentlyYes — stable per entity
Best forPublic filings, final disclosureInternal sharing, vendor / expert review, analysis

Neither is “better” — they are for different jobs. Mature anonymization tools offer both, per entity, so you decide what gets permanently removed versus tokenized.

Where the mapping lives is the whole ballgame

The security of reversible redaction rests entirely on where the token-to-original map is stored. If it lives in a cloud service, you have reintroduced exactly the third-party exposure you were trying to avoid — see redacting legal PDFs without the cloud. Done right, the mapping never leaves your device, the same principle that should govern the redaction itself.

Frequently asked questions

Is tokenized data still “personal data” under GDPR?

Generally yes, if you retain the mapping. Regulators treat reversible replacement as pseudonymization, not anonymization — an important distinction covered in GDPR document anonymization.

Can two different people get the same token?

No. Good tokenization assigns a unique, stable code per distinct entity, so tokens don’t collide and the same person stays consistent throughout.

Where is the reverse key stored?

It should stay local to your machine. If a tool keeps it in the cloud, reversibility comes at the cost of the privacy you were buying.

The bottom line

Reversible redaction gives you a way to share documents safely without throwing away the information you still need. The one rule that makes it trustworthy: the mapping stays on your device.

promptShield lets you choose, per entity, between permanent redaction and reversible tokenization — with the token mapping stored locally on your device and one-click decoding when you need the originals back. Try it on your own document.

Share

AI-powered document anonymization. Detect and redact sensitive data offline, with complete privacy.

Product

Account

Legal

Canada flagProudly Canadian
promptShield Inc. · 222, Wayman, Gaspé (QC) G4X 1T1, Canada · IP geolocation by DB-IP
© 2026 promptShield inc. All rights reserved.
promptShieldpromptShieldpromptShield
Features
Pricing
Download
Developers
How It Works
AI Workflows
Peace of Mind
vs Microsoft Presidio
Alternatives
Blog
Team
Sign In
Sign Up
Dashboard
Privacy Policy
Terms of Service
Security
Data Processing (DPA)
Refund Policy
Contact
Exchange Rates