Report screenshots are full of client secrets — internal IPs, hostnames, creds, tokens, hashes — that can't ship in a deliverable, so you black them out by hand, one by one, hoping you didn't miss one. Blackbar finds them automatically and destructively burns them out (opaque bar into a fresh bitmap, metadata stripped — not a blur you can undo), keeps the same value labeled the same across every screenshot, and runs 100% offline. macOS; Windows; Linux, $19 once.
Blackbar comes from a chore I hated: writing the report after an engagement.
Every screenshot you include as evidence is full of stuff that can't leave the building — internal IPs, hostnames, creds, tokens, NTLM hashes, employee emails. So you spend an evening in Preview/GIMP drawing black boxes by hand across dozens of screenshots, praying you didn't miss one. And it still goes wrong: a box that's a pixel short, a "blur" that's reversible, a PNG that still has metadata, or the same IP redacted three different ways across the report.
That's a security incident waiting to happen — with your client's name on it.
Blackbar does it in one pass:
• Captures, too — grab a screen region with ⇧⌘2 (macOS) / Ctrl+Shift+2 (Linux) and it drops straight into the editor, detected and ready. Capture + redact in one tool, no separate screenshot step.
• Finds the secrets automatically — 27 detectors for IPs, hostnames, API keys, JWTs, AWS/Stripe/GitHub tokens, NTLM hashes, IBANs, and more.
• Destroys them — the export is re-encoded from a fresh opaque bitmap with the regions overwritten and every scrap of metadata stripped. No hidden layer, no un-blur, nothing to recover.
• Stays consistent — the same value gets the same label ([IP-1], [HOST-1]…) across every screenshot, so a 40-image report still makes sense.
• Stays private — OCR, detection, and redaction all run locally. No network calls (enforced by a test in CI), no telemetry, no account. Easy to run on an engagement laptop, and you can verify the download (checksums + GPG signature).
Today's launch is Blackbar 1.0 on Linux / Windows / MacOS — a single-file AppImage that runs on any x86_64 distro (plus a .deb), 1:1 with the Mac app. One $19 license covers both platforms, 14-day trial.
I'd love your feedback — especially a secret that slips past detection or a detector that's too aggressive. Reply here and I'll jump on it. 🙏
Hey Product Hunt 👋
Blackbar comes from a chore I hated: writing the report after an engagement.
Every screenshot you include as evidence is full of stuff that can't leave the building — internal IPs, hostnames, creds, tokens, NTLM hashes, employee emails. So you spend an evening in Preview/GIMP drawing black boxes by hand across dozens of screenshots, praying you didn't miss one. And it still goes wrong: a box that's a pixel short, a "blur" that's reversible, a PNG that still has metadata, or the same IP redacted three different ways across the report.
That's a security incident waiting to happen — with your client's name on it.
Blackbar does it in one pass:
• Captures, too — grab a screen region with ⇧⌘2 (macOS) / Ctrl+Shift+2 (Linux) and it drops straight into the editor, detected and ready. Capture + redact in one tool, no separate screenshot step.
• Finds the secrets automatically — 27 detectors for IPs, hostnames, API keys, JWTs, AWS/Stripe/GitHub tokens, NTLM hashes, IBANs, and more.
• Destroys them — the export is re-encoded from a fresh opaque bitmap with the regions overwritten and every scrap of metadata stripped. No hidden layer, no un-blur, nothing to recover.
• Stays consistent — the same value gets the same label ([IP-1], [HOST-1]…) across every screenshot, so a 40-image report still makes sense.
• Stays private — OCR, detection, and redaction all run locally. No network calls (enforced by a test in CI), no telemetry, no account. Easy to run on an engagement laptop, and you can verify the download (checksums + GPG signature).
Today's launch is Blackbar 1.0 on Linux / Windows / MacOS — a single-file AppImage that runs on any x86_64 distro (plus a .deb), 1:1 with the Mac app. One $19 license covers both platforms, 14-day trial.
I'd love your feedback — especially a secret that slips past detection or a detector that's too aggressive. Reply here and I'll jump on it. 🙏