Trust boundary
Security and trust boundary
Redaction helps only when the application routes sensitive text through the protected boundary and does not fall back to the original value.
01 · Security boundary
Caller responsibilities
Treat processing errors and blocked results as stop conditions. Never log diagnostics that echo the input or plaintext findings.
- Restrict bypass paths around the adapter or gateway.
- Keep provider credentials separate from model-bound text.
- Review downstream destinations that can append their own data after redaction.
- Use synthetic examples in tests and support reports.