A photographed document, about to be published. This is an illustration — no real file, name or location is used.
Before — what you would be sending
leaked-page-04.jpgJPEG
Exact location51.503364, -0.119543
Camera serial numberF2LX9K3QW1
Date taken2026-08-14 02:17
The serial number links every frame this camera ever took.
After cleaning
leaked-page-04-clean.jpgJPEG
Exact locationremoved
Camera serial numberremoved
Date takenremoved
Consider what you need to keep privately for verification before publishing.
What identifies a source
The author field of a document. The camera serial number in a photograph, which links every image that body ever produced. The GPS coordinates of a picture taken inside a building. A printer's identification pattern in a scan. The username embedded in a file path inside an office document.
Published files carry it onward
Uploading a leaked document to your own site republishes its metadata to the world. The safe practice is to transcribe or re-render the content rather than publish the original file, and to verify the replacement independently.
Instruct sources before they send
By the time a file reaches you, the exposure has already happened, and it may be logged somewhere in transit. Guidance to sources is worth more than any cleaning done at your end: photograph a screen rather than screenshot it, retype rather than forward, avoid the original file where the content can be conveyed without it.
Verification cuts the other way
The same metadata that endangers a source can authenticate a document. Strip it for publication, but consider what you need to retain privately, and separate those decisions deliberately.
In practice
Printer identification patterns
Many colour laser printers add a faint pattern of yellow dots to every page, encoding the printer's serial number and a timestamp. The dots are nearly invisible under normal light and survive scanning and photographing. A printed document that is then scanned and sent therefore carries an identifier for the machine that printed it, entirely independently of any file metadata. This has been used in real prosecutions.
Instructions worth giving a source
Photograph a screen with a device that has location disabled, rather than taking a screenshot. Retype rather than forward. Do not print. Use a device and an account with no connection to you. None of this involves a tool, and all of it is more effective than anything done after the file arrives — because by then the exposure has already happened and may be logged somewhere in transit.
Publishing decisions
If you publish an original file, you republish everything inside it to the world, including whatever would identify the source. Re-render or transcribe instead, and verify the replacement independently. Keep the original privately if you need it for verification, and be deliberate about the separation between what you hold and what you publish.
Common questions
Can a leaked document identify who leaked it?
Frequently. Author fields, timestamps, editing history and printer patterns have all been used to do exactly that.
Should I publish original files or transcriptions?
Transcriptions or re-rendered versions are safer. Publishing an original republishes everything inside it.
Does stripping metadata make a document unverifiable?
It can. Decide separately what you keep privately for verification and what you publish.