Burned-in redaction - definition
Burned-in redaction is the permanent alteration of image or video pixels so that concealed content is part of the rendered output file. In image and video anonymization, it usually means that a face or license plate has been blurred, pixelated, covered with an opaque shape, or otherwise obscured before the final file is exported.
The defining characteristic is that the redaction is written into the visual data of the delivered file. A recipient who opens the rendered image or video should see only the redacted pixels. This differs from a non-destructive overlay, annotation layer, editable project file, or separate mask track, where the original pixels may remain available if layers, tracks, or source assets are accessible.
Burned-in redaction is often used when footage must be shared for review, training, publication, investigation, or internal operations without disclosing identifiable faces or license plates. It is a rendering outcome, not a detection method. Face detection identifies the area to redact, while burned-in redaction modifies the exported visual content.
How burned-in redaction differs from overlays
An overlay can be visually effective while a video is played, but it may not remove the underlying image data. The difference matters when recipients can access editable files, alternate video tracks, alpha channels, project assets, or an original file stored alongside the redacted copy.
Method | Original pixels in the delivered visual stream | Can the redaction be removed by disabling a layer? | Typical use
|
|---|---|---|---|
Burned-in redaction | Replaced or materially altered in the rendered output | No, not from the rendered visual stream alone | Distribution of a redacted image or video derivative |
Overlay or annotation layer | May remain unchanged beneath the overlay | Possibly, if the recipient has access to the layer or editable file | Review, editing, or reversible internal workflows |
Separate mask metadata | Usually remains present in the source video or image | Possibly, if the mask is not applied during rendering | Automated processing pipelines and later re-rendering |
Burning in a redaction does not automatically mean that every copy is safe to disclose. The delivery package can still expose unredacted content through source files, proxy files, thumbnails, alternate tracks, cached previews, frame exports, or cloud-sharing permissions.
Application to face and license plate anonymization
For images and video, burned-in redaction is normally applied after face detection or license plate detection identifies a target area. The system then follows that area across frames and renders an obscuring effect into each affected frame. In a video, a successful redaction must remain aligned with the moving face or license plate throughout the relevant time interval.
A practical workflow should distinguish automated detection from manual review. Gallio PRO automatically detects faces and license plates for anonymization. It does not automatically detect logos, tattoos, name badges, documents, or content displayed on monitors. Those elements require manual masking with the built-in editor when they create a privacy or confidentiality risk.
Key parameters and quality checks
The quality of burned-in redaction depends on both concealment and continuity. A mask that covers a face in one frame but misses it during motion, occlusion, camera shake, or a scene cut can expose personal data.
Parameter or check | Purpose
|
|---|---|
Mask coverage | Confirms that the redaction extends beyond the detected face or license plate boundary and covers the relevant pixels. |
Temporal continuity | Checks that the mask remains present and correctly positioned across consecutive video frames. |
Redaction effect | Defines whether the output uses blur, pixelation, a solid fill, or another obscuring transformation. |
Export inspection | Verifies the final delivered file rather than only the editing preview or project timeline. |
Container inspection | Checks for alternate streams, attachments, thumbnails, alpha channels, or embedded source assets. |
A useful review measure is frame coverage: reviewed redacted frames / total frames containing the target. This measure does not prove anonymity, but it helps identify missed frames. Review should include scene transitions, fast movement, partial occlusion, reflections, and frames near the start and end of each tracked segment.
Evidentiary and integrity consequences
A burned-in redaction creates a derivative of the original evidence. It preserves the fact that a redacted version was produced, but it prevents a recipient of that derivative from independently examining the concealed pixels. The original and the redacted derivative therefore serve different evidentiary purposes.
Organizations should preserve the original file separately when retention is justified and authorized. Access to the original should be restricted, while the burned-in derivative can be distributed to a broader approved audience. The following controls support traceability:
- Record the source file identifier, acquisition date, export settings, and redaction method.
- Calculate cryptographic hashes for the original and the redacted derivative before transfer or storage.
- Keep the original and redacted files as distinct records with separate access permissions.
- Document manual edits, quality assurance review, and the identity of the authorized reviewer.
- Verify that shared folders and delivery packages do not include unredacted source assets.
A hash can demonstrate that a specific file has not changed since the hash was calculated, but it does not show that the redaction was complete or appropriate. Completeness requires visual and technical quality assurance.
Standards and references
No single international standard defines burned-in redaction for face and license plate anonymization. However, established evidence-handling and integrity standards provide relevant controls for managing original and redacted media.
- ISO/IEC 27037:2012, Information technology - Security techniques - Guidelines for identification, collection, acquisition and preservation of digital evidence, International Organization for Standardization.
- National Institute of Standards and Technology Special Publication 800-86, Guide to Integrating Forensic Techniques into Incident Response, 2006.
- Federal Information Processing Standard 180-4, Secure Hash Standard, 2015.
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection - Information security management systems - Requirements, International Organization for Standardization.