How to find and redact SSNs, IBANs and card numbers in a PDF

Open UnboundPDF’s Redact tool, switch to Patterns, tick the kinds of personal data you want found — US Social Security numbers, IBANs, credit-card numbers, email addresses, international phone numbers, dates — and scan. Every match is listed per page for review; nothing is removed until you apply. Applying deletes the matched text from the page content, draws the black box, and re-reads the file to confirm. It runs in your browser; the documents are not uploaded.

Updated 19 August 2026

UnboundPDF is a free suite of 43 PDF and image tools that run entirely in your browser — merge, split, compress, edit text, OCR in 126 languages, redact, sign, convert and archive to PDF/A. Your document is read and written by the page on your own device; there is no document-upload endpoint in the core tools, no account, no watermark and no daily cap. Every result can be checked — with the Network tab, or with the Document Passport the Workspace writes for a chain of steps.

Steps

  1. Open Redact PDF and drop in the PDF — or several; the scan runs across all of them.
  2. Switch to Patterns and tick what to look for: SSN, IBAN, credit-card numbers, email, phone, dates. Tick more than one.
  3. Scan. Matches appear page by page with the text shown, so you can see what was caught.
  4. Untick any match that should stay — a reference number that merely looks like a card number, a date that is not personal.
  5. Optionally tick Sanitize to clear metadata, XMP, embedded files, scripts, annotations and bookmarks in the same pass.
  6. Apply, read the result note, download. Open the file and search for one of the numbers: it should not be found.

What each pattern catches

US Social Security numbers in the usual nine-digit forms. IBANs — country code, check digits, account — as written on European bank documents, with or without spaces. Credit-card numbers of the common lengths, checked with the card-number checksum so a random 16-digit reference is less likely to be flagged. Email addresses. Phone numbers in international form, including a leading plus and country code. Dates in common numeric and written forms. Patterns are shapes, not meanings: review the list.

Redact PDF is the tool that scans for and removes these patterns, in your browser.

Scanning several files at once

Drop the whole bundle — the scan runs across every file and the match list is grouped by document and page. This is the workflow for a due-diligence set, a batch of statements before they go to an accountant, or a stack of applications before they are shared with a panel.

Review before you apply

Nothing is changed by the scan. Each match shows the matched text and the page; untick what should stay. When a page is flagged split — a number that is written across two separate drawing operators — the tool reports it rather than splicing blindly, and the final note will say the file is NOT fully verified if any such page remains. That phrase tells you exactly which page to look at by hand.

What applying does

The matched text is removed from the page content — not painted over — the black box is drawn, and the saved file is re-read to confirm the numbers are gone in plain, hex and two-byte encodings. Pages that are images (scans) are rebuilt with the box burned in and named in the note. Tick Sanitize and document metadata, XMP, embedded files, scripts, annotations and bookmark titles are cleared too, because a name redacted from page 3 is no use if it is still in the document’s Author field.

Check it yourself

Open the downloaded file, search for one of the redacted numbers, and try to select and copy the boxed area. Both should come up empty. Keep the untouched original on your own disk only if you mean to.

Related

The longer explanation of why a black box alone is not redaction: how to redact a PDF so the text is actually gone. The comparison of approaches: redaction that removes text vs a black box. Inspect or clear document properties on their own: Edit Metadata. Bake remaining comments or fields into the page afterwards: Flatten PDF.

Frequently asked questions

Can it find every Social Security number in a PDF automatically?

It finds numbers written in the usual SSN forms in the page text. A number inside a scanned image or a photo is pixels, not text — draw a box over it instead. Always review the match list.

Will it flag numbers that are not card numbers?

Card-number matches are checked with the card checksum, which filters most random digit runs, but an order number can still pass. That is why matches are listed for review and untickable.

Does it redact across multiple PDFs in one go?

Yes. Drop several files; the scan and the match list cover all of them, and applying processes each file.

Are the documents uploaded to be scanned?

No. Scanning, redaction and verification all run in your browser; the files never leave your device.

What does “NOT fully verified” mean?

A page could not be confirmed clean by the re-read — usually a scan rebuilt as an image, or a number split across drawing operators that was reported rather than spliced. The note names the page so you can check it by hand.