Skip to content
Architecture/architecture/
Architecture contents

Architecture

The rules are written once

Detection, overlap resolution, policy and redaction happen inside one Rust core, and JavaScript, Python, Rust and the CLI all call it. This section covers what that core decides, how well those decisions are measured, and what the text passes through on its way in.

One core, four surfaces.

Each language gets a thin translation layer and no copy of the rules, so JavaScript and Python cannot quietly disagree about what a secret is.

The engine

What decides

The evidence

Why those decisions can be trusted

The boundaries

Outside the core, in their own repositories

In one line

Four repositories, one direction

Dependencies run one way. The vault may use the core's public API; the core and the adapters never depend on the vault. Because of that, installing the scanner never creates a recoverable copy of your secrets.

RepositoryOwnsMust not own
redact-secretDetection, overlap resolution, policy, redaction, safe metadata, placeholdersRestoration storage, restore authorization, any dependency on the vault
redact-secret-vaultMapping lifecycle, opaque tokens, restore checks, storage extension pointsDetection rules, PII classification, changes to core policy
redact-secret-adaptersHost integrations for logs, traces, AI context and MCPRestoration, or emitting mapped plaintext to observability
redact-secret-benchmarksDetection and support evidenceTreating restoration success as detection accuracy

Sources for this section. The core from README.md and ARCHITECTURE.md; family counts and statuses from the generated docs/support-matrix.md; versions from the package registries; methods and taxonomy from docs/specs/ in the benchmarks repository. Each page states its own sources.