Skip to content

Repository files navigation

Blot

release ci license: GPL-3.0-or-later

Redaction that destroys what it covers.

The redaction failures that make the news share one anatomy: a black rectangle drawn over text that was still in the file. Copy, paste, and the "redacted" names are on the clipboard. Courts have done it, law firms have done it, government agencies keep doing it, because most PDF tools treat redaction as decoration.

Blot treats it as demolition. Your document's pages are rendered to plain pixels, your ink is painted into those pixels, and a brand new PDF is built containing only the pictures. There is no text layer in the output because there is no text in it at all, no annotations, no form data, no attachments, no metadata, no earlier versions. The finished file is then reopened and re-checked in front of you: zero extractable text items, zero annotations, zero form fields, or you see exactly what survived.

Documents Blot cannot flatten honestly get refused with an explanation, not half-handled: password-protected files, filled forms, XFA, and digitally signed documents each get told why and what to do instead. The trade is stated plainly too: the output is a picture of a document. It prints and reads fine; it is not editable and not searchable. That is the cost of certain.

A rendered PDF page in the editor, ready for ink The proof screen: checked clean, zero extractable text, zero annotations, zero form fields

Get it

Android: install blot.apk on Android 9 or newer, with Android System WebView at Chromium 109 or later (Android 9 phones with Google Play keep this current by themselves; a stock, never-updated WebView is older than that). Below that version, Blot shows a plain screen asking you to update WebView instead of a blank page. It's not in the Play Store, so Android will warn you that it's blocking an install from outside the store; that warning exists for apps that misuse permissions, and Blot asks for none. Settings offers a one-time "install anyway," which is the only extra step. The same release link always points at the current version, so an updater like Tern can track it for you.

Get it with Tern

iPhone: open blot.munzzyy.dev in Safari, tap Share, then "Add to Home Screen". Blot is not on the App Store; you can also build the ios/ wrapper yourself with Xcode (docs/IOS.md).

Anywhere else: open blot.munzzyy.dev. app/ is the whole web app, a static page with no build step and no server side, so you can also serve your own copy from anything that can serve files.

Check the claims

npm test validates the PDF writer against poppler, a completely independent implementation: image-only output must yield zero text to pdftotext. npm run e2e goes end to end: a real PDF with a planted secret goes in, ink goes over it, and the output is checked outside the app three ways: pdftotext extracts nothing, the secret string exists nowhere in the raw output bytes, and the re-rendered page is probed to confirm the ink is really there. The APK requests no Android permissions, not even INTERNET; its one manifest entry is androidx's self-scoped not-exported marker, which grants nothing.

The web app has one dependency, on purpose: Mozilla's PDF.js reads the input, vendored at a pinned version whose checksum is verified against the npm registry. CI re-checks every vendored file's checksum on every push; provenance and manual re-verification steps: app/vendor/pdfjs/PROVENANCE.md. Everything else in the web app, including the PDF writer, is dependency-free (the Android wrapper carries the standard androidx runtime, like any modern app).

Run it

For development: node test/serve_local.mjs serves the web app, and cd android && ./gradlew assembleDebug builds an installable debug APK (release signing goes through tools/release-android.sh).

There is also a native iOS wrapper around the same app/, built with Xcode from a generated project rather than a checked-in one. It has no prebuilt release yet; Safari can install the hosted web app from blot.munzzyy.dev instead. Details, and exactly how the wrapper differs from the Android app: docs/IOS.md.

Roadmap

What is left needs someone other than this repo's code: a store review or a native speaker.

  • F-Droid. Blot is not in it yet. The store text and the per-version changelogs it reads are in fastlane/; the submission to fdroiddata and its review are still ahead.
  • The sha256 and signing certificate lines in the release notes. v0.3.0 and v0.5.0 have them; the v0.4.0 to v0.4.3 notes still need them added.
  • A native speaker's read of the Spanish UI and store text. The move from "redactar", which means to write, to "tachar" was not checked by one.

Bugs, holes, contributions

Getting text, form data, or metadata out of a Blot output is the bug that matters; SECURITY.md has the private route for that. Everything else: issues and pull requests are open and welcome. Releases list the APK's sha256 and signing certificate digest.

License

GPL-3.0-or-later. You can use, study, change and share it. If you distribute a copy or a modified version, it has to stay under the GPL and come with its source. Releases up to v0.4.0 were under MIT. The vendored PDF.js is Apache-2.0.

About

Redaction that destroys what it covers. PDFs flattened to pixels, inked, and re-checked to contain zero extractable text.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages