Try live
Seal a redacted-text residual (original→scrubbed) into a carrier image with pre/post hashes and key-bound fail-closed extraction. Not proof of deletion everywhere, not auto GDPR compliance — residuals are liability if the key leaks.
Not proof of deletion everywhere, not auto GDPR compliance — residuals are liability if the key leaks. Not undetectable steganography.
Demo host: isolated demo host set by your deployment
Scrub Residual Sealer · Disclosure
Seal a redaction residual
Seal a redacted-text residual (original → scrubbed) into a carrier image with pre/post hashes, then extract it with key-bound fail-closed semantics. The demo host runs in isolation — nothing is stored.
Not proof of deletion everywhere, not auto GDPR compliance — residuals are liability if the key leaks. Not undetectable steganography. Sample data for demonstration only.
Carrier image
01No carrier loaded. Upload an image or generate a blank carrier (minimum 128×128).
Redaction residual
02
Character offsets (start inclusive, end exclusive). Optional replacement
string (defaults to [REDACTED]).
Provide the already-scrubbed text directly. The host will compute pre/post hashes from original and scrubbed text.
Verify residual
03After sealing, the sealed carrier and residual ID are held client-side. Extract with the same key to recover the residual and hashes. A wrong key fails closed.
Result
04Residual
—
Hashes & report
- Residual ID
- —
- Pre-image hash
- —
- Post hash
- —
- Bytes embedded
- —
- Capacity remaining
- —
- Encrypted
- —
- Channel
- —
- Scrubbed
- —
Raw response
—
Operator and workspace consoles are separate applications (pilot).
