SheetScrub app icon
SheetScrub
Excel metadata scrubber & audit tool — Windows · macOS · $79 one-time
In development · Windows · macOS

Scrub every hidden channel out of Excel — and prove it.

Before you email a spreadsheet to a client, regulator or counterparty, SheetScrub finds and removes everything the file is still carrying — hidden sheets, external-link caches, pivot caches, Power Query code, VBA, image EXIF, author history — then hands you a hash-sealed report that shows exactly what was removed. It never opens Excel, and your file never leaves your machine.

Get SheetScrub — $79 See what it finds One-time, per device. Includes a 30-day free trial.
SheetScrub is in development. Installers (Windows .exe + Microsoft Store, macOS .dmg) will appear in Downloads at launch. The channel catalog below is what it is being built to catch.
sheetscrub — inspect Q3_model.xlsx
$ sheetscrub inspect Q3_model.xlsx
CRIT A1 core.xml creator "j.doe" · modified 2026-09-30
CRIT B1 hidden sheet "Sheet5" (veryHidden)
CRIT B3 externalLinks \\FIN01\shared\clientB\… (+12 cached values)
CRIT D3 pivotCacheRecs 402 source rows retained
CRIT E2 Power Query M code · server path + inline sample
HIGH A2 app.xml Company "Acme LLP" · Manager
HIGH C3 comments by 3 authors · threaded
HIGH A4 thumbnail.jpeg pre-delete render snapshot
MED C4 header [Path] C:\Users\j.doe\Desktop\…
LOW D5 calcChain.xml formula topology
———————————————————————————————
23 findings · 4 critical · SHA-256 a3f1…7d21

Inspect → Scrub → Prove

Three gated steps. Nothing is deleted until you have seen the list; nothing is claimed until it has been re-checked on the output file.

01 · INSPECT

Read-only audit

SheetScrub statically parses the OOXML package (ZIP + XML) and lists every leak channel it can find — with the raw XML evidence shown next to each finding. It never launches Excel and never touches your file.

→
02 · SCRUB

Rewrite a clean copy

Per your policy (Send / Archive / Paranoid, or per-channel overrides), it rewrites a brand-new _scrubbed.xlsx. Destructive actions must be previewed before they run. Your original stays put.

→
03 · PROVE

Re-scan & seal

The output file is scanned again and compared against the "before" snapshot. You get a report, a before/after ledger, and a SHA-256 MANIFEST you can re-verify any time.

9 layers. ~50 leak channels.

Excel's built-in Document Inspector checks a handful of surface items. SheetScrub walks the whole package — including the caches that keep values you thought you deleted.

LAYER A

Package metadata

core.xml, app.xml, custom.xml, thumbnails — author, company, manager, revision history, Purview labels, ghost properties.

creatorcustom propsthumbnail
LAYER B

Workbook structure

Hidden / veryHidden sheets, hidden defined names, external links (+ their cached values), revision logs, protection hashes.

veryHiddenexternal linksrevisions
LAYER C

Sheet edges

Hidden rows/columns, the "junk past the print area", comments + authors, headers/footers with &[Path], hyperlinks, filter caches, number-format text traps.

hidden rowscomments[Path]
LAYER D

Data caches

Orphaned shared strings, formula cached values, pivot caches, query tables, calc chain, the Power Pivot data model.

pivot cacheformula cachedata model
LAYER E

Connections & queries

Connection strings & credentials, SQL command text, Power Query M code (with inline data samples), Office add-ins.

credentialsM codeadd-ins
LAYER F

Embedded objects & media

OLE embeddings (scanned recursively), image EXIF/GPS, text hidden in text boxes and shapes, stale chart caches.

OLE objectsEXIFdrawings
LAYER G

Code & automation

VBA projects (comments hide paths and passwords), Excel 4.0 macro sheets, custom ribbon UI — with a safe .xlsm → .xlsx downgrade.

VBAXLM macros
LAYER H

File system traces

NTFS alternate data streams (Zone.Identifier / download source), the file path itself, stray ~$ lock files.

Zone.Identifierpath
LAYER Z

Sensitive-word fishing

A dictionary you maintain (client names, project codes, old company names) swept across every XML file — the last net that catches anything the channel list missed.

raw hits±40 chars context

Why not just use Document Inspector?

Because it has documented blind spots — and it can't hand you evidence.

 Excel Document InspectorSheetScrub
How it readsOpens the file in Excel (a live Office process)Static ZIP + XML parsing — never launches Excel
DepthSurface items (comments, hidden rows, basic properties)9 layers / ~50 channels, incl. external-link caches, pivot caches, Power Query M, data model
Audit evidenceNoneBefore/after ledger + SHA-256 manifest + independent review records
BatchOne file at a timeQueue / batch
Reversible?Saves in placeAlways writes a new file; original untouched

The part nobody else ships: proof

Every scrub produces an archivable evidence pack. Re-run the seal check any time to prove the pack hasn't been altered.

Evidence pack

Evidence_20261003T141022_a3f19c/
├─ report.pdf  human-readable
├─ report.json  machine-readable
├─ before.json  pre-scrub scan
├─ after.json  post-scrub re-scan
├─ actions.log
├─ triangulation.json  3-tool review
└─ MANIFEST.sha256  🔒 seal

Before → after ledger

Channelbeforeafteraction
B1 hidden sheet10REMOVED
B3 external links30REMOVED+CONVERTED
A1 core props82REWRITTEN (allow-list)
D3 pivot cache4020REMOVED
C3 comments110REMOVED

Independent review: T1 7-Zip ✓ · T2 ExifTool ✓ · T3 Doc Inspector ✓

Three presets, full manual control

Pick a starting point, then override any channel. Destructive actions always show their consequences before they run.

Send Default

Clear the outward-facing sensitive layers, keep formulas and features working. For the file you're about to email.

Archive

Remove all metadata but preserve workbook structure and refresh behaviour. For long-term retention.

Paranoid

Maximum scrub — connections, the data model, Power Query. May break refresh; requires typing SCRUB to arm.

Free trial

  • Single file up to 50 MB
  • Audit report view is disabled
  • No multi-file batch scrubbing
  • 30 days from first start — the full version removes all three limits.

Downloads

Windows and macOS. (No Linux build.) Installers will appear here at launch — each with a version history and a stable "latest" link. A Microsoft Store listing is planned for Windows.

🪟 Windows

Windows 10/11 · x64 · .exe installer — plus a Microsoft Store listing at launch

Releases coming soon

Download

🍎 macOS

macOS · Apple silicon & Intel · .dmg

Releases coming soon

Download

Permanent latest links (live once SheetScrub ships): /api/downloads/latest?slug=sheetscrub&platform=windows /api/downloads/latest?slug=sheetscrub&platform=macos · update checks: /api/software/latest?slug=sheetscrub&platform=…

One price. Yours forever.

SheetScrub — Full Version

$79 one-time · per device
  • 9-layer / ~50-channel deep scan
  • Clean rewrite — originals never overwritten
  • Audit report view + evidence pack
  • Batch queue & per-channel policy
  • Independent review (7-Zip · ExifTool · Doc Inspector)
  • Free updates within 1.x
Get SheetScrub — $79

Payment handled securely by Creem (merchant of record). Card · Apple Pay · Google Pay. Your license key arrives by email and in your account.

Installers are on the way — your key is ready the moment the first build ships.

Questions, answered

How is this different from Excel's Document Inspector?

Document Inspector runs inside Excel, checks a handful of surface items, and leaves no trail. SheetScrub parses the file statically (no Excel process), walks ~50 channels including the caches that still hold values you deleted, and produces a hash-sealed evidence report. See the comparison table above.

Does SheetScrub modify or upload my file?

No. It opens the original read-only and always writes a new _scrubbed.xlsx beside it — your source file is never overwritten. Everything runs locally; the app only goes online for trial/license verification and update checks.

Which files does it handle?

Modern Excel packages: .xlsx and .xlsm (macro workbooks are cleaned and downgraded to .xlsx). Legacy .xls and encrypted workbooks are detected and flagged — you'd re-save them first.

Will scrubbing break my workbook?

Output is structurally validated so Excel still opens it. Some channels are inherently destructive — those actions are clearly marked and must be previewed before running; the Send preset leaves formulas and features intact.

What's the trial limit?

The 30-day trial caps a single file at 50 MB, hides the audit report, and disables multi-file batch scrubbing. The full license removes all three.

Is the report legal advice?

No. The evidence pack is a processing record — timestamps, hashes, operator, before/after state — designed to support audit narratives. It is not a legal opinion.