Skip to content
Architecture/architecture/how-it-works/
Architecture contents

01 · How it works

It finds passwords in text, and crosses them out.

The rest of this page is about doing that carefully.

At the boundary

Text in, the same text out

Secrets are allowed on one road only: from your credential manager, through a vault, to the provider. Redact Secret is a filter you install on every other road. Text goes in, the same text comes out, minus anything that looked like a credential.

Input and outputscanAndRedact()
Input
API_KEY=SYNTHETIC_REVOKED_CONTEXT_VALUE
Output
API_KEY=<SECRET_1>

The placeholder is only a label. Nothing turns it back into the key. If you need the original back, use the vault, which lives in a separate repository and has to be added on purpose.

The architecture

One brain, four mouths

The hard thinking happens once, in Rust. Every language gets a translator, not its own copy of the rules.

JS / NodeN-API addon
BrowserWebAssembly
PythonPyO3
CLIdirect

The Rust core

detect → resolve → policy → redact

Safe text and safe notesThe notes say where a secret was and what kind. They never contain the secret.
0network calls, file reads, env lookups or telemetry inside the core. Same input, same output, always.
1shared test corpus every language must pass identically, down to the character offsets.
4pipeline stages. Detection does not make policy decisions, and policy does not detect.

What is in the box

The feature set

Two sizes

Full knows every provider. Common keeps only the 6 structural detectors, for browsers and small agents: smaller, faster, and it adds no false alarms. The measurements are on the benchmarks site.

Runs in the browser

The same engine compiles to WebAssembly, so a key can be caught before it leaves the laptop. Cloudflare Workers is supported.

A CLI for CI

redact-secret checks files or a staged diff. Exit 0 clean, 1 found, 2 broken, and broken always outranks found.

Fails closed

64 MiB and 50,000 findings by default. Past either, you get an error, never a quietly truncated clean result.

Errors say nothing

Every error message is fixed text with no input in it. Your crash reports cannot leak what your scanner just caught.

Bring your own key format

Declare an in-house credential as a ruleset: plain text the core parses and matches itself, never a callback. The grammar is on the detection page.

Real logging and tracing packages

pino, Python logging and an OpenTelemetry span processor ship as versioned adapters from their own repository.

Personal data, opt in

Email, IBAN, payment card, phone, network address and US SSN families. Off by default on every surface.

The comparison

Most secret scanners guard a different door

Gitleaks, TruffleHog, detect-secrets and GitGuardian watch your code: did a developer commit a key? Redact Secret watches your traffic, at the moment text is about to be logged, stored, or handed to a model.

Code → commit → CIGitleaks, TruffleHog, detect-secrets, GitGuardian. Scans files and git history, before anything ships.
Running app → text in motionRedact Secret. Scans what your users, tools and models are saying, right now, in process.

They are not rivals. Run a repository scanner in CI and this in your request path.

Being honest

What it is not

Sources. Architecture, pipeline, profiles and limits from README.md and ARCHITECTURE.md; family counts and statuses from the generated docs/support-matrix.md; versions from docs/releases/status.md. Checked on 2026-09-28 against main at 9ab0fa0, 0.1.0-beta.10.