Business documents
What to check before sharing a PDF publicly
The PDFStack team · 24 March 2026 · 4 min read
Documents that go outside an organisation carry more than their visible content. This is a short list of things worth checking, ordered by how often they cause trouble.
1. The metadata
Open the document properties. Author, title, subject, the software used, creation and modification timestamps are all in there. The author field very often holds a personal name or a username, and the title field very often holds whatever the original template was called, which can be a previous client's name.
Clearing these takes seconds.
2. The text layer versus what you see
If anything was covered rather than removed, it is still in the file. Extract the text from the document and read it. It takes a minute and it is the single most reliable check available. If a name you thought you had covered appears in the extracted text, it is retrievable by anyone.
This is also a good check for content that was moved off the visible page rather than deleted, which happens more often than people expect when documents are edited by hand.
3. Comments and annotations
Review comments survive export more often than people realise. So do sticky notes, highlights and tracked changes that were converted rather than accepted. Flattening the document turns interactive content into page content, but read the comments first. Flattening a comment makes it permanently visible, which may be the opposite of what you want.
4. Pages you did not mean to include
Long documents built from templates often carry an internal cover sheet, a pricing appendix, or a page of notes at the end. Scroll the whole document once. Extract only the pages that should go out, rather than deleting the ones that should not, so the default is exclusion.
5. Which version this actually is
The commonest failure of all is sending the right kind of document with the wrong content: last quarter's numbers, an unsigned copy, a draft with a placeholder still in it. Open the final file, the actual file you are about to attach, not the one in your editor, and look at it.
None of this is sophisticated. All of it is faster than the conversation that follows getting it wrong.
6. Attachments you did not know were there
A PDF can carry other files embedded inside it. They appear on no page and in no preview, and most people never look.
They arrive more often than you would think: a spreadsheet embedded by an export process, an earlier draft attached during review, a source file someone included for convenience. Check, and remove anything that should not travel.
7. Active content
Documents can contain scripts, actions that fire when the file opens, and actions attached to links. Most are harmless; some are not; almost none are needed in a document you are sending someone.
Stripping them costs nothing and removes a category of risk for the recipient.
Doing this efficiently
The full pass looks long written out. In practice it is three operations and one read-through:
Extract the text and read it. That single step catches covered-but-not-removed content, hidden text, and revision history, which are the three failures with real consequences.
Clear the metadata and strip active content. Two clicks, no visible change.
Scroll the whole document once. That catches the pages you did not mean to include and the version you did not mean to send.
Build it into the process, not the panic
The reason documents go out wrong is almost never ignorance of these checks. It is that they happen at the end, under time pressure, when someone is trying to get something sent.
Doing them as a fixed step before attaching anything, the same way you would check a bank transfer before confirming it, costs two minutes and removes the category of mistake entirely.
What to do if something has already gone out
Act quickly, because the window in which recall is plausible is short.
Ask for deletion in writing, so there is a record. Assume the document has been read and possibly forwarded. If the disclosure is material, personal data, privileged material, anything regulated, escalate it rather than handling it quietly, because the reporting obligations are frequently time-limited and are not yours to waive.
A two-minute version
If you do nothing else: extract the text and read it, clear the metadata, and scroll the whole document once.
Those three catch covered-but-not-removed content, hidden revision history, identifying properties, and the wrong-version problem. Which between them account for the overwhelming majority of documents that go out wrong.
Why these checks belong to the sender
The recipient cannot perform any of them. They cannot know that a black box was drawn rather than the text removed, that the metadata names a different client, or that page nine was meant to be excluded.
By the time anything is discoverable at the other end, it has already been disclosed. That asymmetry is the whole reason this is a sender's checklist rather than a shared one, and it is why it belongs in the sending routine rather than in a document somewhere describing best practice.