# The Shareable Work Sample Standard, and What Makes One Unsafe to Show

*You can take any single artifact from your history and grade it pass or fail on confidentiality risk and evidentiary value, then decide to show, redact, rebuild, or replace it.*

- Canonical URL: https://www.refolk.ai/candidates/guides/shareable-work-sample-standard
- Pillar: Positioning and materials
- Format: Standard
- Published: 2026-08-20
- Last reviewed: 2026-08-20
- Reading time: 16 min
- Keywords: how to share work samples without violating nda, sanitize confidential portfolio work, redact work sample for interview, show work from previous employer in interview, confidential work portfolio what to remove

## Key takeaways

- The safest-looking redaction is the least safe: Gaussian blur and pixelation leave the underlying pixel data in the file, and tools like Bishop Fox's Unredacter reconstruct it, while a solid mark flattened to PNG or JPG discards the data.
- A black box drawn over live text in a PDF is not redaction; the text still sits underneath and copies straight out, as a 2019 Manafort court filing proved.
- At an initial screen of 7.4 seconds, up 23 percent from 6 seconds in 2012, a reviewer cannot parse a caveat buried in body text, so the NDA label and the quantified result must sit in the top-left scan zone.
- Grade every artifact on two independent axes - confidentiality risk and evidentiary value - because a sample can be perfectly safe and prove nothing, or prove everything and be a breach.
- In Refolk's index there are 17,318 Product/UX/UI designers in the United States against 2,222 in Germany, a 7.8x gap, so portfolio-review competition is concentrated where this standard matters most.
- Sharing code from a prior employer fails on both axes at once: it usually is not yours to show and it signals to the reviewer that you do not honor confidentiality commitments.

Before you paste a screenshot into a portfolio or open a file in an interview, one question decides everything: is this specific artifact safe to show, and does it still prove anything once it is safe? This guide is for job seekers assembling a portfolio or preparing samples to walk through in a loop, and it gives you a pass/fail bar you can apply to a single piece of work in under two hours. The output is a decision - show, redact, rebuild, or replace - that two reviewers grading the same sample would reach the same way.

Most portfolio advice teaches you to build a case study, rank your pieces, or present a deck. None of it tells you whether a given artifact is legally safe to show and whether it still demonstrates skill after you clean it. That is the gap this standard fills, and it fills it by grading every sample on two independent axes rather than the vague "just redact it" that most guidance stops at.

## The two axes: confidentiality risk and evidentiary value

Grade every artifact on two independent axes. Confidentiality risk asks whether showing it violates a contract or exposes protected information. Evidentiary value asks whether, once every identifier is gone, the sample still proves something about your skill. A piece can pass one and fail the other, which is exactly why one axis is not enough.

The mistake the scattered advice makes is collapsing these into a single "is it OK to post" question. It is not one question. A perfectly sanitized artifact can be safe and prove nothing. A vivid, detailed artifact can prove everything and be a breach. You need both scores before you decide.

#### Where an artifact lands on the two axes

Horizontal axis runs from Low confidentiality risk to High confidentiality risk. Vertical axis runs from Low evidentiary value to High evidentiary value.

| Quadrant | What it means |
| --- | --- |
| Safe but weak | Replace with a stronger sample or a personal project |
| Rebuild as a labeled recreation | Recreate the proof without the protected content |
| Drop it | Neither safe nor useful, remove from the shortlist |
| Show as-is | Ready to present once metadata is checked |

*The action you take depends on which quadrant the sample falls into, not on how impressive it looks.*

Read the matrix in reading order. Top-left, high value and low risk, is the sample you show as-is. Top-right, high value but high risk, is where recreation earns its keep: the proof is worth reconstructing because the artifact carries it. Bottom-left, low value and low risk, is safe but not worth a reviewer's seconds. Bottom-right is a sample you drop entirely.

> **Rule:** Both axes must pass
>
> A sample ships only when confidentiality risk is resolved AND evidentiary value survives the cleaning. Passing one axis is not a pass. If cleaning the artifact destroys the proof, it fails and you rebuild or replace.

## What to remove before a sample is shareable

Remove five categories: client and company identifiers, personally identifiable information, real proprietary figures, roadmap and unreleased-product detail, and trade-secret methods. No single canonical checklist is published anywhere, so treat these five as the working set and tag every element of your artifact against them.

Client identifiers include names, logos, and trademarks. PII means personal identification numbers, addresses, phone numbers, email addresses, and any other personal or confidential data that happens to sit in a screenshot. Proprietary figures are the real revenue, conversion, or headcount numbers - replace them with relative or anonymized ranges rather than exposing them. The trade-secret "method" category is defined broadly in law: patterns, plans, compilations, formulas, designs, prototypes, methods, techniques, processes, procedures, programs, or codes. That last category is the one people underestimate, because a process diagram can be a trade secret even with the client's name stripped off.

What you keep is the frame around the work: context, problem, objectives, constraints, your role, your approach, and outcomes stated as ranges. That frame is what a reviewer actually came to see. Practitioner guidance is blunt about this - reviewers usually do not want the project's details, they want to learn how you approach problems. Strip the identifiers, keep the reasoning.

> **Note:** Redaction is also a signal to the employer
>
> Trade-secret protection under the Defend Trade Secrets Act depends on the owner taking "reasonable measures to keep such information secret," and courts dismissed roughly 11 percent of disputed cases for failing that element. A candidate who visibly sanitizes their own samples demonstrates exactly the discipline employers are legally required to see.

## Interview NDAs create a second, live risk

An interview NDA is separate from your old employer's obligation, and it binds you the moment a hiring company shares its roadmap, pricing, or client data to assess you. It is typically unilateral - you are restricted, not the company - and time-bound, with standard agreements requiring non-disclosure for 1 to 5 years after the interview. This matters because you are often a receiver and a discloser of confidential material in the same job search.

The distinction the dossier draws is precise. Your former employer's NDA governs what you may show about your own past work; if you signed it, you may be barred from talking publicly about the projects or even listing the company as a client. The interview NDA governs what you may repeat about the company now assessing you. Note one thing employers cannot do: an employee NDA protecting trade secrets cannot be used during the interview process, which is why a separate interview NDA exists to fill that gap.

| Instrument | What it governs | Typical term |
|---|---|---|
| Interview NDA | The hiring company's roadmap, pricing, and client info shared to assess you | 1 to 5 years after the interview |
| Former-employer NDA | Whether you may show or name your own past work | Tied to duration of confidentiality |
| Non-compete | A post-termination period, not confidentiality | A specific fixed period after leaving |

Keep the non-compete out of your confidentiality analysis. An NDA is tied to the duration of confidentiality; a non-compete enforces a specific post-termination period in which you may not work for a competitor. They are different instruments answering different questions.

## The redaction methods that fail

The safest-looking redaction is the least safe. Gaussian blur and pixelation feel thorough because you dragged a heavy effect across the sensitive area, but they transform the data rather than remove it, and the underlying pixel data still sits in the file. Machine-learning models reconstruct blurred faces, plates, and screen content well enough to recover names and numbers.

This is not theoretical. A Bishop Fox researcher, Dan Petro, built an open-source tool called Unredacter that reconstructs text from pixelated images, and an earlier tool, Depix, recovers pixelated text by permutation lookup. Black boxes over live text fail the same way: a "redacted" PDF where the text still sits under the box can be recovered, which is how a 2019 Manafort court filing leaked text that had merely been highlighted black over a live text layer. The only safe visual method is a solid mark flattened into a raster PNG or JPG, which leaves nothing underneath.

| Method | Recoverable? | Why |
|---|---|---|
| Gaussian blur | Yes, often via ML | Averages pixels that stay in the file |
| Pixelation / mosaic | Yes, via Unredacter or Depix | Reconstructable by permutation lookup |
| Black box over live PDF text | Yes | Text sits underneath the box |
| Solid mark flattened to PNG/JPG | No | Nothing remains to recover |

> The visually heaviest edit is the reversible one, and the plain flattened mark is the only one that discards data.

Flattening alone is not the whole job. Run a sanitize pass on the file itself, because visible content can be clean while comments, author fields, or EXIF data still name the client. Acrobat's "Sanitize and remove hidden information" option removes comments, bookmarks, attachments, form fields, and embedded metadata in one step. Do this after you flatten, not before.

## When the original cannot be shown: four alternatives

When redaction guts the proof or the contract bars the artifact entirely, four documented alternatives let you demonstrate skill without the original. Each proves your thinking or craft rather than the finished artifact, which is what a reviewer wanted anyway.

- **Labeled recreation.** Build new content that mirrors the original and add a line specifying you created dummy content because the work is confidential. This proves your execution without exposing the client's asset.
- **Process case study.** Write up the challenges and your process without any client information, stating the sample is NDA-guided and exact details cannot be shared. This proves how you approach problems.
- **Sanitized proxy.** Replace sensitive visuals with sanitized proxies that retain the same communicative function, so a reviewer sees the same design decisions against neutral content.
- **Client testimonial.** Provide a testimonial confirming you worked for the client and disclosing only details outside the agreement. This is powerful for showing how significant the client was without naming the work.

**On-artifact disclosure label**

```
This sample is illustrative. Client identifiers, real figures, and
confidential details have been removed or replaced under an NDA.
The layout, process, and my role are accurate; exact details cannot be shared.
Role: [your role]. Outcome: [result stated as a range].
```

*Place this in the top-left scan zone of the sample, not buried in body text. Swap "illustrative" for "sanitized" depending on which applies.*

There is no standardized disclosure wording published, so this label is a load-bearing gap you are filling yourself. The point is that a reviewer reads it as neither a breach nor a fabrication. Without a label, a rebuilt artifact reads as invented, which is its own failure mode covered below.

## The seven-tie window means legitimacy must be visible

A reviewer spends about 7.4 seconds on an initial screen, up 23 percent from 6 seconds in 2012, based on an eye-tracking study of 30 professional recruiters monitored over 10 weeks. That figure is disputed - times vary by role complexity, application volume, and screening stage, and a first-pass screen differs from a hiring manager's deep review. But the direction is clear enough to design around: a caveat buried in body text will not be read.

| Year | Seconds on initial screen | Source |
|---|---|---|
| 2012 | 6.0 | Reported prior figure |
| 2018 | 7.4 | TheLadders eye-tracking study |
| Change | +23% | Derived from the two |

The implication for a work sample is direct. The NDA or illustrative label and the quantified result must sit in the top-left scan zone where a reviewer's eyes land first, so they register legitimacy and outcome before they register anything else. Legitimacy has to be visible, not explained.

**7.4s - Initial reviewer screen time on a sample or resume**

At this speed, the sanitization label and the result must be seen at a glance, not read in a paragraph.

This is also why over-sanitizing is expensive. A sample scrubbed until it is generic reads, in seven seconds, as either forgettable or fabricated. The frame you keep - role, approach, outcome range - has to survive the glance.

## The grading procedure, step by step

Run these eight steps in order on a single artifact. The whole pass takes roughly two hours for a complex file and much less for a simple one. Steps one through four are judgement; five through eight are execution and verification.

#### Grade and prepare one work sample

1. **Read the governing contract first** - Locate the NDA, employment, or severance clause and identify whether it bars public disclosure, client naming, or only confidential information. You are done when you can state in one sentence what it forbids.
2. **Inventory the artifact's content** - Tag every element as a client identifier, PII, a real figure, a roadmap detail, or a trade-secret method. Done when every visible and hidden element carries exactly one tag.
3. **Grade evidentiary value** - Decide what the artifact proves about your skill once every identifier is gone. Reviewers want to see how you approach a problem, so grade against that, not the project details.
4. **Choose the action** - Pick show, redact, rebuild, or replace. Show if safe as-is, redact if identifiers are severable, rebuild as a labeled recreation if redaction guts the proof, replace with a proxy or testimonial if neither works.
5. **Execute redaction correctly** - Flatten to a raster image and place solid marks; never use blur, pixelation, or a black box over live PDF text. Run a sanitize pass to strip comments, bookmarks, attachments, form fields, and metadata.
6. **Get second-eyes verification** - Have a peer try to copy text out of the file and re-open the flattened image to confirm nothing is recoverable. A second pair of eyes catches oversights you cannot see.
7. **Attach the disclosure label** - Add a line stating the content is illustrative or sanitized and NDA-guided. Done when a reviewer can tell at a glance it is neither a breach nor an invention.
8. **Gate access if needed** - For sensitive-but-permitted work, place it in a separate password-protected section shared only during interviews so you control who sees it.

On step one, sources disagree on emphasis. Some writer NDAs stress that if the agreement is about private information, published or online work may be shareable. Others say assume nothing is shareable without permission. When the clause is ambiguous, default to the stricter reading and confirm before you show.

#### From raw artifact to a shippable sample

1. **Contract read** - Know what the agreement forbids
2. **Content inventory** - Every element tagged by category
3. **Value grade** - What it proves once cleaned
4. **Action chosen** - Show, redact, rebuild, or replace
5. **Verify and label** - Second eyes, sanitize pass, disclosure line

*The decision at step four routes the artifact down one of four paths, and every path ends at the same verification gate.*

Because grading a whole history one artifact at a time is slow, it helps to start from a resume that already surfaces which projects carry provable outcomes, so you spend your redaction time only on the samples worth showing. [Refolk](/candidates) writes your resume from your own history and scores how well each piece fits a target role, which tells you which artifacts are worth putting through this eight-step pass in the first place.

## How this goes wrong: failure modes and false positives

Every failure here is a false positive - a sample that looks safe or looks proven but is not. These are the checks that separate two reviewers who would otherwise disagree. Give this section the weight it deserves, because a standard that misses these is worse than no standard.

- **Blur or pixelation used as "thorough" redaction.** The heavy blur feels like the data is gone because you can no longer read it, but it is recoverable. Check: attempt a reversal, or flatten and re-inspect. If the shape of the text is still there, so is the text.
- **Black box over live PDF text.** It looks redacted on screen but the text copies straight out. Check: select-all and paste into a plain text editor. If the "hidden" text appears, the redaction failed.
- **Metadata leak.** The visible content is clean but comments, author, or EXIF fields still name the client. Check: run a sanitize pass before you send.
- **Over-sanitizing until nothing is proven.** A sample scrubbed so hard it demonstrates no skill, and a reviewer reads fabrication risk. Check: can a peer state what you did in one sentence? If not, you cut too much.
- **Assuming "published equals shareable."** The work is public but the contract still bars naming the client relationship. Check: re-read the disclosure clause, not the visibility of the artifact.
- **Recreation read as a fake.** A rebuilt artifact with no label looks invented. Check: is the illustrative or NDA disclosure attached and visible in the scan zone?
- **Sharing code from a prior employer.** It seems like proof but it belongs to the company, tells a reviewer little about your ability, and signals that you do not honor commitments. Check: is it yours to show, or is it a personal or open-source project?

> **Watch out:** The two-minute recoverability test
>
> Before any sample leaves your hands: select-all and paste to catch live text under a black box, and re-open the flattened image to confirm the mark is opaque. Then run the metadata sanitize pass. Skip this and you may ship a breach that looks perfectly clean on your screen.

The last failure mode is worth its own emphasis. Prior-employer code fails both axes at once - it is a confidentiality risk you do not own, and it is weak evidence because a reviewer learns more from your reasoning than from source you can neither explain fully nor claim. Replace it with something you own.

## The verification checklist

Run this before you call any single sample done. Every item is a pass/fail check, not a topic, so two reviewers grading the same artifact land on the same answer.

#### Ship-ready sample check

- [ ] You can state in one sentence what the governing contract forbids you to show or say.
- [ ] Every visible and hidden element is tagged as identifier, PII, figure, roadmap detail, or method - and each protected one is removed or replaced.
- [ ] All redaction is a solid mark flattened to PNG or JPG; no blur, pixelation, or black box over live text remains.
- [ ] Select-all and paste returns no hidden text, and the flattened image opens with nothing recoverable underneath.
- [ ] A metadata sanitize pass has stripped comments, author fields, bookmarks, attachments, and EXIF data.
- [ ] A peer can state in one sentence what you did, confirming the sample still proves skill after cleaning.
- [ ] An illustrative or NDA disclosure label sits in the top-left scan zone, readable in the first few seconds.
- [ ] Any sensitive-but-permitted material is behind a password-protected section shared only during interviews.

## Keeping the standard current

Adopt this as team or personal policy and it stays valid, because it is built on mechanisms rather than a moment. Two things do move, so re-check them rather than trusting a saved answer. First, redaction-recovery tools improve; the rule that blur and pixelation are recoverable will only harden, but confirm your flatten-to-raster method still leaves nothing behind by running the copy-out and re-open tests every time. Second, the reviewer-time figures are disputed and vary by stage, so treat 7.4 seconds as an order of magnitude, not a constant, and keep the label and result in the scan zone regardless of the exact number.

The population this standard serves is large and uneven. In Refolk's index there are 17,318 Product/UX/UI designers in the United States, 4,362 in the United Kingdom, and 2,222 in Germany - a 7.8x gap between the US and Germany. Top US employers in that sample include Palantir, Meta, Reddit, and Runway, all places where the confidentiality question is real and portfolio review is competitive.

| Country | Designers in index | Multiple vs Germany |
|---|---|---|
| United States | 17,318 | 7.8x |
| United Kingdom | 4,362 | 2.0x |
| Germany | 2,222 | 1.0x |

If you want to see how other people in your field solved the same problem - showing proof without breaching - look at how they present it, then borrow the pattern, not the content.

Ask me this: `Freelance designers in Germany who list client testimonials instead of client names` - [run the search](https://www.refolk.ai/start?q=Freelance%20designers%20in%20Germany%20who%20list%20client%20testimonials%20instead%20of%20client%20names).

*This returns practitioners who chose the testimonial alternative, so you can see how a credible sample reads without a single named client.*

The standard does not change when a tool or a study does. Run the eight steps, pass both axes, and clear the checklist. A sample that survives all three is safe to show and still proves what you did.

## Frequently asked questions

### How do I share work samples without violating an NDA?

Read the contract first and identify whether it bars public disclosure, client naming, or only confidential information. Then remove client identifiers, PII, proprietary figures, and trade-secret methods, keeping only what proves your approach. If the contract bars even naming the relationship, rebuild the work as a labeled recreation or replace it with a testimonial. Attach a disclosure line stating the sample is sanitized and NDA-guided so the reviewer reads neither a breach nor a fabrication.

### Is blurring or pixelating enough to redact a screenshot?

No. Gaussian blur and pixelation are visual effects, not data removal, so the underlying pixel data stays in the file. Open-source tools such as Bishop Fox's Unredacter and the earlier Depix reconstruct pixelated text well enough to recover names and numbers. The only safe visual method is a solid mark flattened into a raster PNG or JPG, which leaves nothing underneath to recover.

### Can I show code I wrote at a previous employer?

Usually not. The code belongs to the company, so showing it is a confidentiality risk you do not control, and it tells a reviewer little about your ability while signaling that you do not honor commitments. Replace it with a personal or open-source project you own, or describe the approach in a case study without the proprietary source. If in doubt, treat it as unshareable until you confirm ownership.

### What is the difference between an interview NDA and my old employer's NDA?

An interview NDA takes effect before any employment exists, the moment a hiring company shares its roadmap, pricing, or client information to assess you. It is typically unilateral and time-bound, with standard agreements requiring 1 to 5 years of confidentiality. Your former employer's obligation instead governs what you may show about your own past work. The two run at once, so you can be a receiver and a discloser of confidential material in the same job search.

### Does a work sample that is already published online mean it is safe to share?

Not necessarily. Public work can still be barred by a disclosure clause that prohibits naming the client relationship, even when the artifact itself is visible online. Some writer NDAs stress only private information, in which case published work may be shareable, but others require you to assume nothing is shareable without permission. Re-read the specific clause before you rely on the fact that something is public.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/candidates/guides/shareable-work-sample-standard*
