Safeguard Redact
Data protection and privacy
Last updated: October 2026
Safeguard Redact has been designed to help professionals reduce the amount of identifiable information they disclose when using case information for legitimate professional purposes.
We have completed a Data Protection Impact Assessment (DPIA) for Safeguard Redact to identify potential privacy risks, assess how the product handles sensitive information and establish the safeguards required for its use.
How Safeguard Redact processes your information
Safeguard Redact is a desktop application.
When you import or paste a document into Redact, the text is processed on your computer using a locally installed detection model together with application rules and any corrections or mappings you make.
In the normal desktop workflow:
- your case documents are not sent to Safeguard Insights for processing;
- document text is not submitted to a cloud AI model;
- your case information is not used to train the detection model;
- Safeguard Insights does not have routine access to your documents or saved mappings.
The application may make limited technical network connections associated with software components or licensing. These are separate from the processing of the case document itself. We review these connections as part of our release and privacy assurance process.
Pseudonymisation, not guaranteed anonymisation
Safeguard Redact is designed to support pseudonymisation.
It identifies information such as names and other identifiers and allows these to be replaced consistently throughout a document. Users can review and amend the replacements before using the resulting text elsewhere.
However, removing names does not necessarily make a document anonymous.
People may sometimes still be identifiable from information such as:
- locations;
- schools or organisations;
- family relationships;
- unusual events or circumstances;
- combinations of contextual information.
Automated detection can also miss information.
For this reason, Redact is designed as an assisted review tool rather than an automatic guarantee of anonymity. Users remain responsible for checking the document before sharing or using it elsewhere.
Protecting mappings
Redact can maintain mappings between original information and replacement terms so that pseudonyms remain consistent and, where required, information can later be restored.
Saved mappings are stored within an encrypted local vault protected by a passphrase.
Mappings are sensitive because they can reconnect pseudonymised information with the individuals concerned. Users should therefore protect their device, passphrase and any mapping information they choose to export.
Mapping exports are separate files and should be stored securely and separately from pseudonymised documents.
Information stored outside the encrypted vault
The encrypted vault protects saved Redact mappings. It does not replace the security controls required for the rest of the user's computer.
Original documents, exported documents, clipboard contents and other files remain subject to the security of the user's device and organisation.
We therefore recommend that Redact is used on appropriately secured devices with suitable access controls, operating-system locking, disk protection, backup arrangements and organisational information-governance procedures.
Human review is essential
Safeguard Redact assists the user; it does not make safeguarding, eligibility or professional decisions.
Users should check:
- that the document has been extracted correctly;
- that direct identifiers have been removed or replaced;
- whether contextual information could still identify somebody;
- that replacements have not changed the meaning of the information;
- that the correct mapping set has been used;
- the final document before it is shared.
The authoritative case record should remain within the customer's approved records system.
Using Redact before using external AI services
Using Safeguard Redact does not automatically make it lawful or appropriate to upload information to an external AI service.
Redact can reduce the disclosure of identifiable information, but the organisation or practitioner remains responsible for deciding whether information can be shared with another service.
Before using information with an external AI provider, customers should consider their own:
- lawful basis;
- confidentiality obligations;
- information-governance requirements;
- organisational policies;
- contractual arrangements;
- international data-transfer requirements where applicable;
- assessment of whether an individual could still be identified from the remaining information.
Some particularly distinctive case information may remain unsuitable for external disclosure even after identifiers have been replaced.
Who is responsible for the information?
For case information processed using Safeguard Redact, the organisation or practitioner deciding why and how the information is being used will normally remain the data controller, or may be acting as a processor on behalf of another organisation.
Safeguard Insights supplies the desktop software but does not normally receive the case material processed within it.
Customers remain responsible for establishing the appropriate lawful basis and, where relevant, conditions for processing special-category or criminal-offence information.
Customers are also responsible for deciding:
- what information should be processed;
- who can use the software;
- which devices may be used;
- how long records and mappings should be retained;
- where resulting information may be sent;
- what additional organisational security measures are required.
Support
We ask customers not to send identifiable case records or mapping files through normal support channels.
Where possible, technical problems should be demonstrated using synthetic or appropriately anonymised examples.
If an exceptional situation requires Safeguard Insights to receive identifiable material, the purpose, security arrangements, responsibilities, retention and deletion arrangements should be agreed before the information is transferred.
Retention
Safeguard Insights does not maintain a central archive of the case documents processed using the normal desktop application.
Customers should apply their own appropriate retention policies to:
- original documents;
- pseudonymised outputs;
- saved mappings;
- exported mappings;
- any working copies created during processing.
Mappings should normally be retained only for as long as they are genuinely required for consistent pseudonymisation or authorised reversal.
Our Data Protection Impact Assessment
Our DPIA considers risks including:
- identifiers being missed;
- identification through contextual information;
- unauthorised access to mappings;
- insecure exported mapping files;
- device or local-file compromise;
- inappropriate onward disclosure;
- changes to meaning during extraction or replacement;
- incorrect case or mapping selection;
- retention and information-rights risks;
- inaccurate or misleading privacy claims.
The DPIA is reviewed alongside product development and when significant changes are made to the way Safeguard Redact processes or protects information.
Safeguard Insights maintains the full DPIA and supporting technical assurance records internally.
A copy of the current customer-facing DPIA information or further data-protection information can be requested from Safeguard Insights.
Customer DPIAs
Our DPIA assesses Safeguard Redact as a product and the processing for which Safeguard Insights is responsible.
It does not replace a customer's own DPIA or other information-governance assessment where one is required.
Each organisation remains responsible for assessing how it proposes to use Safeguard Redact within its own environment, including the information involved, users, devices, lawful basis and any onward disclosure.