Is it safe to send a scan of your passport or driving licence, and how to send one that is less useful to a thief
An estate agent, an employer, a bank, a car hire desk or a marketplace asks you to send a photo of your passport or licence. You usually cannot refuse. What you can decide is what is on the copy you send, and where you prepared it.
Send a copy, not the photograph off your phone. Black out the fields the recipient does not need — for most purposes that is the machine-readable zone along the bottom, the document number and your signature — stamp it with who it is for, what it is for and the date, and flatten it so the marks cannot be lifted off. BASTION does all four in one pass and the image never leaves the tab. That last part is not fussiness: a service that collects ID scans for redaction is the single most valuable pile of files on the internet to steal.
What the image is actually worth
A clear photograph of a passport or a driving licence is not a document. It is a credential, and it is enough on its own for a surprising amount:
- Opening accounts in your name. Most remote identity checks are a document photograph plus a selfie. One of the two is the hard part and it is not the document.
- Taking over the accounts you have. "Send a photo of your ID to verify" is how account recovery works almost everywhere, mobile networks included — which is the first step of a SIM swap, and from there the second factor on your bank is theirs.
- Credit in your name, which you discover months later.
- Training a face model, or being sold on, if the recipient is not who you think.
The machine-readable zone — the two lines of angle brackets at the bottom of a passport — deserves particular care. It encodes the document number, your date of birth, nationality, expiry and check digits in a form designed to be read by machines, which means it is the part that automates fraud rather than merely enabling it.
What to black out, by purpose
The principle is duller than it sounds: black out what the recipient will not use. If they come back and ask, you send another copy, and you have lost nothing. If you send everything and their supplier is breached, you cannot get it back.
The watermark is the part people skip
Stamping a copy with "For [company] only — for [purpose] — [date]", written across the document rather than in a corner, does two things. It makes the copy much harder to reuse anywhere else, because the stamp has to be removed convincingly and it sits over the face and the text. And if it does turn up somewhere it should not, the stamp says who you gave it to — which is the whole point, and why banks and solicitors have done exactly this with paper copies for decades.
Write it across the middle, over the photograph, at an angle. A neat stamp in white space is a crop away from gone.
Flatten it
A black rectangle drawn in a PDF viewer, or a layer in an image editor, is a thing sitting on top of the document. Somebody can move it. If it is in a PDF, the text is often still underneath and still selectable — this is the failure that has exposed redacted court filings, repeatedly, for twenty years. What you send has to be pixels: one flat image where the blacked-out parts contain no information. BASTION saves a flattened copy; for a PDF, SEAL removes the text rather than covering it.
The metadata question
A photograph of your passport taken on your phone carries the GPS coordinates where you took it — which is, for most people, their home. It also carries the device, the time, and often a thumbnail of the image before you edited it. EXIF shows what is in yours; CLOAK strips it. The copy BASTION writes is drawn fresh from pixels, so none of it comes along, but it is worth seeing what was in the original once.
How to send it
Email is a postcard that gets stored on at least four machines. If the recipient offers a portal, use it. If they insist on email, a locked archive with the passphrase sent by text is better than an attachment — STRONGBOX writes one, and CAPSULE makes a single encrypted file that opens in a browser with nothing installed. And when it is done, delete the copy from Sent, from the phone's camera roll, and from Downloads. It is the copies you forget that leak.
Why not just use a free redaction site
Think about the position that site is in. It receives, by design, a continuous stream of unredacted passport and licence scans from people who were being careful. Every one arrives with its metadata. Whatever the operator's intentions, that is the highest-value target on the open internet per gigabyte, and the breach notification would be catastrophic for the people in it and survivable for the company.
You do not have to evaluate any of that. A page that does the work in your own browser never receives the file. You can load it, turn the network off, and watch it still work — which is a check you can run, not a promise you have to weigh.
The short version
| The job | Here | Notes |
|---|---|---|
| Black out the fields they do not need | Yes | MRZ, document number, signature, usually |
| Stamp it with who and what it is for | Yes | Across the document, not in a corner |
| Flatten it so the marks cannot be lifted | Yes | Pixels, not layers |
| Lose the GPS and camera data | Yes | The copy is drawn fresh |
| Straighten and crop a phone photograph | Yes | |
| Keep the unredacted scan off every server | Yes | The whole point; works offline |
| Stop the recipient keeping it forever | No | Nothing can. Send less instead |
| Make a redacted copy a bank will accept | No | Ask what they need before redacting |
| Get back a copy you already sent | No |
Questions people ask about sending a scan of your ID