MXPROCESS Home

SaaS · APIs · Cybersecurity

What Your Files Really Reveal: Hidden Metadata and How to Check It Before Sharing

Try this service

What Your Files Really Reveal: Hidden Metadata and How to Check It Before Sharing

A photo can show a room, a street or an object while carrying additional information that is invisible in the image itself. A document can retain the name of an editing application, and a media file can describe the device, encoding process or exact timing used to create it. This hidden metadata is often useful to software, but it can also disclose more than you intended when a file leaves your device. Checking file metadata before sharing gives you a chance to understand the file first. FileInspection is a practical inspection step for that review.

Why EXIF deserves attention

Photos from phones and cameras may contain EXIF fields such as the device model, capture date, precise time, orientation and, when location services were active, GPS coordinates. The pixels may show only a marketplace item, but the metadata could identify the camera or the place where the picture was taken. Editing software may add or preserve additional fields. None of this is necessarily a problem, but it is worth knowing before an image is sent to an unknown person or published publicly.

The same principle applies beyond photographs. Documents may contain author names, application versions, revision details or timestamps. Audio and video can expose codec, duration, bitrate and resolution information. A metadata check is not about assuming that every field is sensitive; it is about making an informed decision about what accompanies the visible content.

Three everyday situations

Imagine selling a table online. A photo taken at home may contain GPS coordinates even though the listing text does not mention your address. Before sharing it with buyers or a public platform, inspect the image and decide whether its metadata should remain. You may then use a separate tool or an export workflow to remove metadata if that is your goal. FileInspection helps you see what is there; it does not remove or rewrite it.

Consider a professional document sent to an external contact. The visible pages may be ready, but the file can still contain an author name, an editing application or dates that reveal details about the work. Inspecting a copy before sending it can support an internal privacy checklist. Similarly, a photo posted to social media may carry device or location information even when the platform later transforms the image. Understanding the source file is useful before relying on a platform’s own processing.

What FileInspection shows

Upload one file, up to 50 MB, to FileInspection. The report is a single JSON result containing the filename, size, SHA-256 hash and real detected MIME type. When applicable, filtered EXIF metadata is extracted with ExifTool. For an image or PDF, the report can also include an OCR preview limited to 500 characters, which helps you confirm the visible text without opening the original in a desktop application. Audio and video files can expose technical media information such as codec, resolution, duration and bitrate through FFprobe.

The report is deliberately a technical view, not a privacy score. A field being present does not automatically mean that sharing is unsafe, and a field being absent does not guarantee that a file reveals nothing. Review the context, the recipient and the purpose of the exchange. If the report contains sensitive metadata, keep the original private and prepare a cleaned copy with a suitable local workflow.

Do not confuse inspection with malware certification

FileInspection also returns a antivirus engine status and a detection rule status, but both require careful wording. the antivirus engine is a preliminary triage signal, never an antivirus guarantee. The detection rules supplied by the service are a minimal starter set, not an exhaustive detection base. A clean status in either section must never be presented as “certified safe”, and error or not_run should not be treated as clean. Privacy inspection and security triage are related checks, but neither one replaces the protections on your device.

Make metadata review a simple habit

Before sharing a photo, PDF or media file, make a copy, upload it for inspection and read the JSON report. Note any GPS, device, author, timestamp or software fields that matter to your situation. Compare the SHA-256 hash if you need to keep track of the exact copy reviewed. Then decide whether to share the original, remove metadata with a separate trusted tool, export a new copy or keep the file private. Check the result again after creating a cleaned copy if the distinction matters.

Processing is asynchronous, and a successful inspection costs 12 tokens. Validation failures, such as an empty file or a file larger than 50 MB, are not billed. FileInspection does not promise to remove hidden data or guarantee privacy; it gives you a concise technical report so that the decision to share is based on evidence rather than on what the file looks like at first glance.

Try this service

Contact us