Metadata Awareness
A black rectangle over text does not remove the text.
What Is Metadata Awareness?
A clean-looking PDF routinely carries tracked changes, reviewer comments, author names, hidden white-on-white text, the cropped-out parts of images, and black rectangles drawn over text that is still fully selectable. In this exercise you send an embargoed press release, then read your own redacted financial projections quoted back at you in the press. A forensics view shows exactly what the reporter pulled out of the file, and you sanitize the next release before it leaves your laptop.
What You'll Learn in Metadata Awareness
- Identify the categories of hidden data that routinely live inside corporate documents: tracked changes, embedded reviewer comments, author + properties metadata, white-on-white hidden text, cropped-out image regions, and layered annotation rectangles drawn over text
- Understand that exporting to PDF is not sanitization: properties, hidden text and drawn-over text survive any export, and export add-ins or settings can carry comments and tracked changes across as annotations
- Distinguish a real redaction (text replaced with [REDACTED] and the file flattened before export) from a drawn black rectangle that leaves the underlying characters fully selectable in any modern PDF reader
- Apply the sanitize-before-share workflow for any external document: press, regulators, vendors, partners, contractors, public bug reports, screenshots into a support chat, attachments into an investor data-room
- Use an approved internal document hygiene tool with a clearance signature the email-gateway DLP recognizes, and recognize that consumer LLMs and free online "PDF metadata cleaners" are out-of-policy substitutes that move the leak to a third-party server
Metadata Awareness — Training Steps
-
An Embargoed Press Release on a Tight Deadline
Coastveil Therapeutics has been waiting on Phase 3 readouts for Verymyl-12 — your lead oncology candidate — for almost two years. The numbers came back strong last Friday. Legal, Clinical, the CFO's office, and Investor Relations have all signed off on the public messaging, and the embargo lifts at 09:30 ET tomorrow when the U.S. market opens. Marcus, your VP of Communications, owns the redline. Priya, on press-ops, owns the distribution wire. Your job is to hand the locked-final to Priya so she can push it to the ~60-outlet financial-press list tomorrow morning.
-
Priya Asks for the Final
Priya Iyer runs press-ops at Coastveil — she owns the distribution wire that pushes releases out to the financial-press list. She just dropped the locked-final into your inbox with a request to confirm send before she queues the wire.
-
Download the Press Release PDF
Pull the attached PDF down to your Downloads folder so you can open it and give it a final look before you reply.
-
Open the Press Release
The PDF is in your Downloads folder. Open it from the file manager and give it a final look before you reply to Priya.
-
Looks Polished
The release reads exactly as Legal cleared it. The lede is the trial result. The body cites the trial design and the safety profile. The financial projections paragraph shows clean redacted blocks where the embargoed numbers used to be. The author byline is Coastveil Investor Relations. Marcus exported it from Word with the Comms team's PDF add-in, the one the team also uses to make review copies. Visually, there is nothing on the page that should not be on the page. That is exactly the problem. What your eyes see in a polished PDF is not what is actually inside the file.
-
Reply to Priya With the PDF Attached
Reply to Priya on the same thread with the locked-final PDF attached. Your reply is the formal handoff that triggers her press-ops wire — she will push the same file to the ~60-outlet financial-press list at 09:00 ET tomorrow, ahead of the embargo lift.
-
Ledgermark Breaks the Story
The Verymyl-12 release went out Tuesday morning via Priya's wire. The trade press picked it up cleanly. By Friday morning, Ledgermark has a different story.
-
Read the Ledgermark Article
Before you go investigate the leak, see what is actually in print. Open the Ledgermark Financial article from the SOC email — the same story Wall Street has been reading for the last hour.
-
Open DocSentry Forensics
DocSentry runs entirely on Coastveil's network. The SOC has already pulled your outbound PDF from the email gateway logs and queued it on the forensics view. You just need to sign in.
-
Read the Internal-Tool Notice
Before you do anything on the page, read the notice at the top. The same banner is on every approved document hygiene surface at Coastveil because skipping the internal tool — by uploading a sensitive draft to a consumer AI or a free online PDF utility — is the most common shadow-IT incident the SOC chases.
Security Framework Coverage
CWE
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer
CIS Controls
- CIS 14.4 Train Workforce on Data Handling Best Practices
- CIS 14.5 Train Workforce Members on Causes of Unintentional Data Exposure
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind