For developers, support, DevOps & security teams

Redact secrets out of a screenshot before it leaves your laptop.

Black out API keys, bearer tokens, .env values, JWTs and customer PII in the screenshots you paste into Jira, GitHub, Slack and Notion — the pixels underneath are destroyed, the file never leaves your browser, and every redaction ships a signed certificate.

A secret in a screenshot is a leak class of its own.

Secret scanning watches your repos and logs. Almost nothing watches the images you paste into a ticket.

Think: GitHub secret scanning — but for images

A live credential in a screenshot is exactly as exfiltrated as one committed to a public repo — except no scanner flags it, and the image is searchable, attachable and forwardable forever.

A reproduction screenshot pasted into a ticket routinely captures a terminal with an API key, a .env file, an Authorization: Bearer header, a decoded JWT, a customer's email, or an internal hostname or IP. Those tickets are frequently world-readable to the org, retained indefinitely, indexed by search, and sometimes mirrored into a data warehouse. Least-privilege hygiene says don't paste prod credentials anywhere — but the durable fix is to redact before the image leaves the device. Pasting that same screenshot into a cloud redaction tool just moves the secret to one more server.

What one leaked screenshot can cost.

A live credential, already exfiltrated

A key, token or session cookie visible in a pasted screenshot is a usable credential. Anyone with read access to the ticket — or anything that indexes it — now holds it, and you're into key rotation and incident response.

Retained and indexed forever

Ticket and chat attachments are rarely purged on the timeline you'd want. The image is full-text searchable, forwardable, and frequently synced into logging or analytics — long after the bug is closed.

Another server holding the secret

Drop the screenshot into a cloud redaction or markup tool and a copy lands on their disk — exposed to their retention, their breach surface, and their access controls. The one thing you needed was for the secret to stay on your machine.

The keptimage tools that handle it.

Two tools cover the workflow — and both run entirely on your device.

Redact keys, tokens & PII

Mark the key, the token, the .env line or the customer email and keptimage overwrites those pixels with a solid fill, then re-encodes the file — there is no hidden layer to peel back. The output ships with a SHA-256 certificate you can re-verify.

Remove Metadata on export

Re-encoding rebuilds the image from raw pixels, so EXIF, capture timestamps and any embedded device data are dropped in the same pass — and the standalone metadata tool scrubs photos you aren't redacting.

No upload endpoint to leak through

The screenshot is processed in your browser. There is no server that receives it — so there is nothing for a vendor to retain, breach, or index, and nothing to add to a risk assessment.

OCR auto-flagging Roadmap

Today redaction is manual marking — you draw the boxes, which is fast and reliable. On-device OCR that auto-flags likely secrets and PII (keys, tokens, emails, IPs) for one-click redaction is on the roadmap. We won't claim it ships until it does.

How it works.

Paste a screenshot, box the secrets, export. The file never touches a server.

  1. Open the screenshot in your browser

    Drop in a PNG, JPG or WebP — a terminal capture, a dashboard, a Postman response. It loads into a canvas on your device; nothing is uploaded. Watch the network tab if you want to confirm it.

  2. Mark every secret and identifier

    Draw a box over each API key, bearer token, .env value, JWT, customer email, internal hostname or IP. Use the Black fill for anything sensitive — it destroys the pixels rather than obscuring them.

  3. Export a re-rasterized, metadata-stripped file

    keptimage overwrites the marked pixels and re-encodes the whole image, so the original detail and all embedded metadata are gone from the file you download — there's no removable overlay. A SHA-256 certificate comes with it, so you can prove later that the file you shared is the redacted one.

Why a black box beats a blur

Blur and pixelation can sometimes be reversed — the underlying structure is still present in the file. A solid fill overwrites the pixels, so there's nothing left to recover.

This is the same guidance the app gives you in the redact tool: for a key, token, email or any other secret, use Black. Blur and pixelate are fine for cosmetic blocking, but they retain enough signal that a determined viewer may reconstruct the original. keptimage marks the solid fill as irreversible right in the certificate, and the re-encode drops EXIF, GPS and camera data along with it.

How we compare.

Same redaction. Very different exposure profile.

Capability keptimage Cloud redaction / screenshot tool OS markup (Preview / Snip & Sketch)
Screenshot is processed in your browser — never uploaded
Destroys the underlying pixels (no liftable layer)
Strips EXIF / metadata in the same step
Ships a verifiable SHA-256 redaction certificate
No vendor-side copy to retain, breach, or index
You can verify zero uploads yourself — watch the network tab

✓ yes · – partial, depends on workflow · ✗ no. Marks reflect typical default workflows as of May 2026. OS markup tools run locally and are a fine option, but a shape laid over text can be flattened wrong, they rarely strip metadata, and they issue no certificate; cloud redaction services destroy pixels but upload the file and retain a copy. keptimage overwrites the pixels, strips metadata, and issues a certificate — all on your device.

For the whole team.

The fastest way to stop secrets leaking through screenshots is to make redaction a one-tab habit, not a process step. keptimage runs in any modern browser with nothing to install, so you can drop the link into your incident-response runbook, your support macros, or the onboarding doc next to "rotate your keys."

For teams handling support tickets or production debugging at volume, the Business plan adds the SHA-256 redaction certificate and seats on one invoice — useful when you need to show, after the fact, that the screenshot attached to a ticket was the redacted version. A lightweight embeddable redaction surface for internal tools is on our radar; tell us if that would help your stack.

You shouldn't have to take our word that nothing uploads. Open the Verify page, open your browser's network tab, and watch zero outbound requests carry your screenshot.

Pricing for teams.

Solo developer? Start free — no card, or upgrade to Pro ($9/mo) inside the app.

Redact the secret before the screenshot leaves your browser.

Open the app