Skip to content
Reference / CompareSheet 01 of 05 · Updated 20 Sep 2026
Compare

What changes when a disclosure is not redacted by hand

Answering an access request by hand is a real method with real properties, and most of them are properties of the person doing it rather than of any tool. This page sets those properties beside the ones this product has, question by question.

What this page compares

Two methods, not two products. There is no other tool named on this page, no feature grid about one and no score. What another product does is that product's to describe, and a table of it written here would be written by the party with an interest in the answer.

The method on the left is the one almost every organisation is using now: somebody reads the documents, marks what has to come out, and sends what is left. It is not a straw man. It is how the work was done before there was anything else, it is still the right answer for a small request, and the last block on this page says where it stays the right answer.

Reference / CompareSheet 02 of 05 · Updated 20 Sep 2026
The comparison

Eight questions, answered twice

Each one is answered for the manual method first, then for this one, then linked to the page on this site that states it in full.

How many times is one person decided about?

By hand

Once for every occurrence. The same colleague appearing in forty documents is forty separate judgements, made hours apart, and the fortieth is made at the end of a week by somebody who has read four hundred pages.

With Veil

Once for the case. Every mention of one person is gathered into a single row, the decision is taken on the row, and it applies to every occurrence of that person in every document at the same instant.

the path a document takes through the pipeline

What does the person receiving it actually get?

By hand

Their own files back, with parts covered over. The document that leaves is the document that arrived, edited.

With Veil

A new document, generated from the text the pipeline chose to emit and from nothing else. The file you uploaded is never modified and is never what ships.

a complete bundle, generated from synthetic data

Can what was removed survive in the file?

By hand

That depends on how it was removed, and a box drawn over a name changes what a reader sees without always changing what the file holds. There are eight places text is known to survive an edit made in place, and most of them are invisible in the reader the redaction was done in.

With Veil

There is nothing underneath to survive, because the output file was never the input file. A name that was not written into the generated document is not in it in any layer, any revision history or any attachment.

the places a file keeps what you removed

Who checks the result before it goes out?

By hand

Usually the person who did the redaction, reading their own work, under the deadline that produced it. A second reviewer doubles the cost of the most expensive part.

With Veil

A separate component re-reads every generated document and looks for what should not be there. It is built and run apart from the part that redacts and shares no code with it, and it can withhold a document rather than release it.

how the independent check works

What happens at the point of doubt?

By hand

A judgement call, taken under time pressure, and nothing afterwards records that it was a close one. The cases that go wrong are rarely the obvious names.

With Veil

It is redacted and raised. Anyone who cannot be attributed to the data subject comes out by default, and the only route back to disclosure is a named person attesting to it in the product.

the three fail closed rules

What can you show a regulator afterwards?

By hand

Whatever was written down at the time, which is usually a note in a case file and the reviewer's memory of why a name stayed.

With Veil

An append-only record of every decision, every state change and every download, carrying identifiers, counts and durations and no personal data at all, plus a report in the bundle stating how the run went.

the controls this record maps to

What is the bill a function of?

By hand

Hours, at whatever an hour of a reviewer qualified to make these judgements costs you, multiplied by pages and by however many pages need a second read.

With Veil

Pages of the bundle you release, on published rates, with nothing charged for a document you do not release and nothing charged for a seat.

what a redaction costs, and what is counted

What happens to the material once it is sent?

By hand

It is wherever the review happened: a working folder, a laptop, an email thread, an export nobody deleted. Every copy is a copy of the unredacted originals.

With Veil

It is encrypted under a key belonging to that case alone, and purging the case destroys the key, which makes the data unreadable everywhere it was written including in backups.

residency, encryption and retention

Reference / CompareSheet 03 of 05 · Updated 20 Sep 2026
Scope

What Veil will not guess at

That list is the reason this page compares properties rather than outcomes. No system reads every document perfectly and this one does not claim to. What is on offer is which way it errs when it is uncertain, which is the row above about the point of doubt, and the fact that a separate component gets the last word before anything is released.

Three classes, raised rather than resolved

Purely indirect identification, the colleague who broke his leg skiing. Badly degraded scans and handwriting. Original page imagery such as signatures. All of it is redacted first and raised for you second. None of it reaches a bundle because nobody looked.

Reference / CompareSheet 04 of 05 · Updated 20 Sep 2026
The other direction

Where doing it by hand is still the answer

A comparison that finds nothing in favour of the other method is an advertisement. These are the four cases where the manual answer is the right one.

  • A request that is a handful of pages

    Opening a case, declaring the subject and reviewing a registry is more effort than reading three letters and covering two names. The method on the left wins on a small request and it is not close.

  • A disclosure that has to look like the original

    Every output here is generated from extracted text and coarse layout, so a scanned page's imagery, its signatures and its letterhead are not reproduced. The text is, with a note saying so. Where the appearance of the page is itself the point, that is a real loss.

  • Material a machine cannot read well

    Handwriting and badly degraded scans are raised rather than resolved. They are still redacted first, so nothing reaches a bundle because nobody looked, but a person is doing the reading either way.

  • A judgement that is about the law rather than about a name

    Whether a document is in scope at all, whether an exemption applies, whether legal privilege is engaged: none of that is a redaction decision and none of it is made here. The Handbook is where this site writes about those.

Reference / CompareSheet 05 of 05 · Updated 20 Sep 2026
Objections

Common objections

Why is there no comparison with a named product on this page?

Because a comparison of another product written by us is written by the party with an interest in the answer, and a reader who notices that has a reason to discount the true rows as well as the arguable ones. The honest version of this page is a comparison with the method, which is what almost every organisation is actually doing today.

Is the point that manual redaction is unsafe?

No. The point is that it is consistent only as long as the reviewer is, and the properties that decide whether a disclosure is safe are mostly properties of the person rather than of the file. A careful reviewer with ten documents and a week will do this well. The same reviewer with four hundred documents and a month is making the fortieth decision about one colleague at the end of a long day.

Does this replace a lawyer reading the file?

It replaces the part of the work that is finding and removing other people's personal data from the documents that are going out. Whether a document is in scope, whether an exemption applies and whether the request is valid are separate questions this product does not answer and does not pretend to.

What does the comparison assume about volume?

Nothing, which is why no figure on this page is a cost or a duration. Both methods scale differently and the crossing point depends on your own documents, your own reviewer and your own rate, so the cost model on the Desk takes all three as inputs rather than assuming them here.

The one way to settle any of this is to read an output. The sample bundle is a complete disclosure produced by a real run on invented people, manifest, quality report and every generated document, and it needs no account.