Why process documents in the browser
Online converters and PDF sites need a copy of your file on their servers. For a leaked memo or a source's records, that copy is a risk you can't audit. Vault Studio Pro loads its PDF engine, OCR engine and editors into the page and works on the file there. The page's Content-Security-Policy tells the browser to refuse connections to any other site, and the only requests to our own server are for the app's files and, if you buy Pro, the license key. The security page explains this in detail, including the limits: we serve the code, so you are trusting what we send, and browser extensions can read the pages you open.
Set it up to work offline
- While online, open the app and the Privacy Audit panel.
- Choose "Make available offline". The browser stores every tool, the OCR engine and the PDF font data, so nothing needs downloading later.
- Disconnect from the network (or use a machine that stays offline) and open the app from the same browser. The editors, redaction, OCR and encryption keep working.
Working offline also answers the question of what the page might send: with no network, it can't send anything. Use a separate browser profile without extensions for sensitive work.
Redacting before you publish
- Work on a copy and keep the original somewhere safe.
- In the PDF editor, box every name, signature, email address, phone number, file path, reference number and routing slip that could identify a source, including headers, footers and stamps.
- Save. Each page with a box is rebuilt as an image with the boxes burned in, so the text underneath no longer exists in the file. Pages without a box keep their text.
- Open the saved copy and search for the redacted words.
Content-level identifiers are the hard part and no tool finds them all: formatting quirks, unusual spellings, distribution lists and the choice of which pages exist can point to a source. Redaction only removes what you box. How PDF redaction works covers the method.
Metadata and what still isn't covered
Saving a PDF with at least one redaction box clears its title, author, subject and keywords, resets the producer/creator fields to a neutral value, removes XMP metadata, and removes embedded attachments — the actual bytes are gone from the file, not just unlinked from view. This happens automatically; there's nothing extra to turn on. For a save with no redaction, turn on "Remove metadata before saving" in the PDF editor's toolbar to get the same clean copy without redacting anything.
This does not cover everything a source document can carry: bookmarks (the outline/table of contents) and the original creation date are left alone either way. Before publishing, inspect the saved file with a separate tool if you need to be sure about those, or publish images of the pages instead. Images exported from Image Studio are new files, so camera metadata such as location isn't copied; check the result anyway.
OCR for scans and photos of documents
OCR turns scanned pages and photos into searchable, copyable English text on your device. It works best on clean, straight scans of printed text. The first page of each PDF is free; Pro runs OCR on every page, which matters for long document sets. Tables can be sent on to the spreadsheet editor for analysis.
Encrypted handoff inside the newsroom
The File Safe locks a document or a ZIP of files in a .vault encrypted with AES-256-GCM, with the key derived from a password by PBKDF2. Send it however you like and share the password through a different channel. The recipient needs Vault Studio Pro and the password. A .vault protects the file in transit and at rest; it doesn't hide that a file was sent, who sent it or when. For communicating with sources themselves, use the secure channels your newsroom already trusts.
Things to keep in mind
- Dictation leaves the device. It uses the browser's speech service (Google in Chrome, Apple in Safari). Type instead.
- Browser storage is not encrypted. Projects are autosaved in the browser. Delete them when you're done, or use a profile you clear.
- No independent audit. Nobody outside has audited the app; the Content-Security-Policy and the Privacy Audit let you check its behaviour yourself.
Cost
Redaction, the editors and encryption are free. Pro costs $9 for a one-off Week Pass, $15 a month, $99 a year or $299 once, and every Pro feature is unlocked for the first 7 days with no card. During the launch, a Founders plan costs $59 a year for as long as you renew (until 2026-12-01). See pricing, or read how we compare with Proton Docs, CryptPad and ONLYOFFICE.
Common questions
Does Vault Studio Pro strip metadata from PDFs?
Yes, automatically, once you redact: saving a PDF with a redaction box clears its title, author, subject and keywords, resets the producer/creator fields, removes XMP metadata, and removes embedded attachments. Bookmarks are not touched, so check those with another tool. For a save with no redaction, turn on "Remove metadata before saving" in the PDF editor to get the same clean copy.
Can I use it with no internet connection?
Yes, once you have turned on "Make available offline" in the Privacy Audit panel while online. That downloads every tool, the OCR engine and the PDF font data to the browser, so the editors, redaction, OCR and encryption keep working with the network off.
Is dictation private?
No. Dictation uses the browser's speech recognition, which sends audio to Google in Chrome or Apple in Safari. Do not dictate anything about a source. The app asks before it turns dictation on.
How do I know the app is not sending my files somewhere?
The page's Content-Security-Policy tells your browser to refuse connections to any site other than vaultstudiopro.com, and the Privacy Audit panel lists the page's own requests. For a complete view, including background workers, watch the Network tab in your browser's developer tools while you use the app, or disconnect from the network.
More questions? See the full FAQ or contact us.