Architecture
The rules are written once
Detection, overlap resolution, policy and redaction happen inside one Rust core, and JavaScript, Python, Rust and the CLI all call it. This section covers what that core decides, how well those decisions are measured, and what the text passes through on its way in.
One core, four surfaces.
Each language gets a thin translation layer and no copy of the rules, so JavaScript and Python cannot quietly disagree about what a secret is.
The engine
What decides
How it works
“What is this thing?”
Four surfaces over one core, the four pipeline stages, two build profiles, and why it guards a different door from a repository scanner.
/architecture/how-it-works/ 02How it detects
“How sure, and why?”
Five tiers of evidence, fixed tie-breakers, why there is no regex engine, and bringing your own ruleset.
/architecture/detection/The evidence
Why those decisions can be trusted
How a support claim is built
“What shipped, what does the world issue, how did each one measure?”
Three files answer three different questions. A support claim exists only after they are joined, so there is no place to type one by hand.
/architecture/support-claims/ 04Evaluation methods
“Ten ways to be wrong”
Write the answer first, then run it. A result is graded five ways over byte ranges, not two, and the scanner gets no vote.
/architecture/evaluation-methods/The boundaries
Outside the core, in their own repositories
Adapters
“Who fetches the text?”
Packages that sit between your host and the engine. They decide nothing, and when they fail they print a marker instead of the value.
/architecture/adapters/ 06Vault
“What if you need the original back?”
The core throws the original away. The vault is the one place allowed to keep it, and it is built to make that hard.
/architecture/vault/In one line
Four repositories, one direction
Dependencies run one way. The vault may use the core's public API; the core and the adapters never depend on the vault. Because of that, installing the scanner never creates a recoverable copy of your secrets.
| Repository | Owns | Must not own |
|---|---|---|
| redact-secret | Detection, overlap resolution, policy, redaction, safe metadata, placeholders | Restoration storage, restore authorization, any dependency on the vault |
| redact-secret-vault | Mapping lifecycle, opaque tokens, restore checks, storage extension points | Detection rules, PII classification, changes to core policy |
| redact-secret-adapters | Host integrations for logs, traces, AI context and MCP | Restoration, or emitting mapped plaintext to observability |
| redact-secret-benchmarks | Detection and support evidence | Treating restoration success as detection accuracy |