Sharing a job file safely: the redacted copy and the export record

The **Job file** button on a job's hero produces the full record by default. The small caret beside it opens a menu with two choices: **"Download job file"** ("Full record, for your own counsel") a…

4 min read·Updated August 25, 2026
On this page

Two copies of one record

The Job file button on a job's hero produces the full record by default. The small caret beside it opens a menu with two choices: "Download job file" ("Full record, for your own counsel") and "Download redacted copy" ("Third-party names masked, email bodies withheld"). The two exist because the same document travels to two very different audiences. Your own lawyer needs everything, names and email text included. A copy that goes further, to a mediator, another party, or anyone outside the privileged conversation, should not carry third-party personal information it does not need to carry.

The full record is the default on purpose. Every other place the export appears, the per-job download on a client's Jobs tab and the "Open a job's file" picker, produces the full record; the redacted copy is only offered here, on the job hero, where you are making a deliberate sharing decision.

What the redacted copy does

Redaction works differently on structured fields than on free text, and it is worth being precise about both:

  • Structured fields are masked wholesale. The insured's name, the client's name, adjuster names, and sender addresses are replaced outright: a name becomes "[Third-party name withheld]" and an email address keeps only its domain. These are fields Verinode knows are names, so they are masked with certainty.
  • Free text is scrubbed of the job's known parties. Subject lines, denial reasons, attachment names, and other free text have the specific people Verinode knows are on this job (the insured, the client, the adjusters on its supplements, the email senders) scrubbed out and replaced with "[redacted]." This is targeted, not a general guess at what might be a name.
  • Email bodies are withheld entirely. The text of emails is not reproduced in a redacted copy, because free-flowing email text can mention people Verinode has no record of, and a scrub that only knows some of the names would leak the rest. The correspondence section still lists every email by sender, date, and party, and states that an unredacted copy reproduces the text in full.
  • The carrier stays named. The carrier is a company central to the dispute, not third-party personal information, so it is named even in a redacted copy. A record of a carrier dispute with the carrier blanked out would be useless.
  • No exhibit files are appended. A redacted copy carries the exhibits index but not the attached files, because appending the original, unredacted source documents would defeat the redaction. The full record appends them; see exhibits.

What it does not do, and what that asks of you

The scrub removes the names Verinode could identify on this job. A name it could not identify, a neighbor mentioned in a denial reason, a person referenced only by first name in a subject line, is not scrubbed, and the document says so on its own scope page: a name that could not be identified is not scrubbed, so review the copy before sharing it more broadly. Treat the redacted copy as a strong first pass produced honestly, not a certification that no name survives. The redacted copy itself states on its cover that it is redacted and that an unredacted copy can be produced.

The export record

Every export of a job file, full or redacted, writes one entry to an append-only export record before the PDF is handed over. Each entry captures who exported, which job, when, and in which mode (full or redacted), together with two fingerprints: one of a retained snapshot of the source records the document was built from, and one of the finished PDF itself. The snapshot stores email bodies only as fingerprints, never as readable text, so keeping the record does not create a second copy of your correspondence at rest.

Entries chain: each one carries the fingerprint of the export before it, so altering or removing any past entry would visibly break every entry after it. And the record write is not optional bookkeeping: if the entry cannot be written, the export fails with "Could not record the export. The packet was not produced." There is no such thing as an unlogged copy of a job file.

Matching a produced file back

The document's final Provenance page prints the source fingerprint, the same one held in the export record. If a job file surfaces later, in a dispute, in discovery, forwarded beyond where you sent it, that fingerprint ties it to the exact export that produced it and to the retained snapshot of what your records said at that moment. You can demonstrate that the document matches the records it came from, and equally that a tampered copy does not.

Data sources

Data sources

  1. 1.Your job's record, correspondence, and documents, as compiled into the export. Your business.
  2. 2.Verinode's append-only record of every job file export from your account. Your business.
Was this helpful?