Forensic report redaction is the removal of personal data from a digital forensics write-up. Investigators follow recognised chain-of-custody practice for digital evidence, and in civil proceedings a computer-derived record can be admissible hearsay evidence under Civil Evidence Act 1995 s.1. Once the report is anonymous under UK GDPR Recital 26 it leaves that scope. anonym.plus runs locally and keeps the artefacts, timeline, and conclusions whole.
When this applies
A forensic write-up names device owners, account holders, and the examiner. To brief non-technical stakeholders — or to support the evidence chain if the matter later reaches court — you clear those names but keep the artefacts and conclusions.
How anonym.plus handles it
- Load the file into anonym.plus on your device.
- The tool flags owner, examiner, and account names.
- Emails, IPs, and device IDs get flagged too.
- Swap each confirmed item for a steady label.
- Save the clean copy on your device.
What you need to provide
- The file (PDF, DOCX, or export).
- An operator (Replace keeps the text readable).
- Optional allow-list for hashes and tool names.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | device owner → [SUBJECT] |
| Names | PERSON | examiner → [EXAMINER] |
| Contact | EMAIL_ADDRESS | account email → [EMAIL] |
| Network | IP_ADDRESS | 192.0.2.44 → [IP] |
| Identifiers | UK_NINO | user ID → [ID] |
| Dates | DATE_TIME | access 02:14 → [TIME] |
Compliance achieved
- Anonymous output falls outside scope by UK GDPR Recital 26.
- A report later relied on in civil proceedings may need to meet the computer-derived evidence rule in Civil Evidence Act 1995 s.1.
- Local work keeps the examiner's findings as protected work-product.
- On-device AES-256-GCM guards the working files.
- Catches IPs and device IDs as identifiers.
Anonymise forensic reports offline — see plans & start free →
Limitations & cautions
An IP or a rare device can still point to one user after names go. Weigh this for wide release. The tool flags known identifiers, but cannot judge when a unique artefact re-identifies someone, and it does not itself preserve chain-of-custody integrity — keep an unredacted original for that.
Frequently asked questions
Are IP addresses removed too?
Yes. The tool flags IP addresses and device IDs as identifiers, since they can point to a person or machine.
Will the evidence chain survive redaction?
The artefacts, timeline, and conclusions in the redacted copy stay intact for review. Keep the unredacted original untouched for chain-of-custody purposes — a report later relied on as computer-derived evidence under Civil Evidence Act 1995 s.1 depends on that original, not the circulated copy.
Can I keep tool names and hashes?
Yes. An allow-list keeps technical terms and hashes in place while the tool removes personal data.