Scrub every hidden channel out of Excel — and prove it.
Before you email a spreadsheet to a client, regulator or counterparty, SheetScrub finds and removes everything the file is still carrying — hidden sheets, external-link caches, pivot caches, Power Query code, VBA, image EXIF, author history — then hands you a hash-sealed report that shows exactly what was removed. It never opens Excel, and your file never leaves your machine.
Inspect → Scrub → Prove
Three gated steps. Nothing is deleted until you have seen the list; nothing is claimed until it has been re-checked on the output file.
Read-only audit
SheetScrub statically parses the OOXML package (ZIP + XML) and lists every leak channel it can find — with the raw XML evidence shown next to each finding. It never launches Excel and never touches your file.
Rewrite a clean copy
Per your policy (Send / Archive / Paranoid, or per-channel overrides), it rewrites a brand-new
_scrubbed.xlsx. Destructive actions must be previewed before they run. Your original stays put.
Re-scan & seal
The output file is scanned again and compared against the "before" snapshot. You get a report, a
before/after ledger, and a SHA-256 MANIFEST you can re-verify any time.
9 layers. ~50 leak channels.
Excel's built-in Document Inspector checks a handful of surface items. SheetScrub walks the whole package — including the caches that keep values you thought you deleted.
Package metadata
core.xml, app.xml, custom.xml, thumbnails — author, company, manager, revision history, Purview labels, ghost properties.
Workbook structure
Hidden / veryHidden sheets, hidden defined names, external links (+ their cached values), revision logs, protection hashes.
Sheet edges
Hidden rows/columns, the "junk past the print area", comments + authors, headers/footers with &[Path], hyperlinks, filter caches, number-format text traps.
Data caches
Orphaned shared strings, formula cached values, pivot caches, query tables, calc chain, the Power Pivot data model.
Connections & queries
Connection strings & credentials, SQL command text, Power Query M code (with inline data samples), Office add-ins.
Embedded objects & media
OLE embeddings (scanned recursively), image EXIF/GPS, text hidden in text boxes and shapes, stale chart caches.
Code & automation
VBA projects (comments hide paths and passwords), Excel 4.0 macro sheets, custom ribbon UI — with a safe .xlsm → .xlsx downgrade.
File system traces
NTFS alternate data streams (Zone.Identifier / download source), the file path itself, stray ~$ lock files.
Sensitive-word fishing
A dictionary you maintain (client names, project codes, old company names) swept across every XML file — the last net that catches anything the channel list missed.
Why not just use Document Inspector?
Because it has documented blind spots — and it can't hand you evidence.
| Excel Document Inspector | SheetScrub | |
|---|---|---|
| How it reads | Opens the file in Excel (a live Office process) | Static ZIP + XML parsing — never launches Excel |
| Depth | Surface items (comments, hidden rows, basic properties) | 9 layers / ~50 channels, incl. external-link caches, pivot caches, Power Query M, data model |
| Audit evidence | None | Before/after ledger + SHA-256 manifest + independent review records |
| Batch | One file at a time | Queue / batch |
| Reversible? | Saves in place | Always writes a new file; original untouched |
The part nobody else ships: proof
Every scrub produces an archivable evidence pack. Re-run the seal check any time to prove the pack hasn't been altered.
Evidence pack
Before → after ledger
| Channel | before | after | action |
|---|---|---|---|
| B1 hidden sheet | 1 | 0 | REMOVED |
| B3 external links | 3 | 0 | REMOVED+CONVERTED |
| A1 core props | 8 | 2 | REWRITTEN (allow-list) |
| D3 pivot cache | 402 | 0 | REMOVED |
| C3 comments | 11 | 0 | REMOVED |
Independent review: T1 7-Zip ✓ · T2 ExifTool ✓ · T3 Doc Inspector ✓
Three presets, full manual control
Pick a starting point, then override any channel. Destructive actions always show their consequences before they run.
Send Default
Clear the outward-facing sensitive layers, keep formulas and features working. For the file you're about to email.
Archive
Remove all metadata but preserve workbook structure and refresh behaviour. For long-term retention.
Paranoid
Maximum scrub — connections, the data model, Power Query. May break refresh; requires typing SCRUB to arm.
Free trial
- Single file up to 50 MB
- Audit report view is disabled
- No multi-file batch scrubbing
- 30 days from first start — the full version removes all three limits.
Downloads
Windows and macOS. (No Linux build.) Installers will appear here at launch — each with a version history and a stable "latest" link. A Microsoft Store listing is planned for Windows.
Permanent latest links (live once SheetScrub ships):
/api/downloads/latest?slug=sheetscrub&platform=windows
/api/downloads/latest?slug=sheetscrub&platform=macos ·
update checks: /api/software/latest?slug=sheetscrub&platform=…
One price. Yours forever.
SheetScrub — Full Version
- 9-layer / ~50-channel deep scan
- Clean rewrite — originals never overwritten
- Audit report view + evidence pack
- Batch queue & per-channel policy
- Independent review (7-Zip · ExifTool · Doc Inspector)
- Free updates within 1.x
Payment handled securely by Creem (merchant of record). Card · Apple Pay · Google Pay. Your license key arrives by email and in your account.
Installers are on the way — your key is ready the moment the first build ships.
Questions, answered
How is this different from Excel's Document Inspector?
Document Inspector runs inside Excel, checks a handful of surface items, and leaves no trail. SheetScrub parses the file statically (no Excel process), walks ~50 channels including the caches that still hold values you deleted, and produces a hash-sealed evidence report. See the comparison table above.
Does SheetScrub modify or upload my file?
No. It opens the original read-only and always writes a new _scrubbed.xlsx beside it — your
source file is never overwritten. Everything runs locally; the app only goes online for trial/license
verification and update checks.
Which files does it handle?
Modern Excel packages: .xlsx and .xlsm (macro workbooks are cleaned and downgraded
to .xlsx). Legacy .xls and encrypted workbooks are detected and flagged — you'd
re-save them first.
Will scrubbing break my workbook?
Output is structurally validated so Excel still opens it. Some channels are inherently destructive — those actions are clearly marked and must be previewed before running; the Send preset leaves formulas and features intact.
What's the trial limit?
The 30-day trial caps a single file at 50 MB, hides the audit report, and disables multi-file batch scrubbing. The full license removes all three.
Is the report legal advice?
No. The evidence pack is a processing record — timestamps, hashes, operator, before/after state — designed to support audit narratives. It is not a legal opinion.