Redaction, Masking & Zero Raw Leak Guarantee¶
How typesafe-eval sanitizes documents before network evaluation to protect sensitive credentials and personal data.
The Zero Raw Leak Guarantee¶
typesafe-eval guarantees that raw credentials, secret keys, and personal phone/email strings never leave your machine:
- Local Redaction: Regex engines and rules identify secrets and personal contacts entirely on your local machine before any network request is formed.
- Payload Sanitization: The payload transmitted to the TypeSafe System One API replaces sensitive values with synthetic tokens (e.g.,
[SECRET_1],[EMAIL_1]). - Safe Diagnostics: In JSON output, metadata, and error messages, raw secrets are never displayed. Only masked placeholders (e.g.
[REDACTED_AWS_KEY]) are emitted.
Sanitization Order & Prose Comment Stripping¶
To ensure maximum safety, sanitization follows a strict two-stage sequence:
- Secret & PII Detection (First): Regex detectors identify secrets, API keys, credentials, and PII across the entire document text (including within HTML comments). This guarantees that even secrets hidden inside HTML comments are flagged as violations.
- Prose Comment Stripping (Second): HTML comments in regular prose are stripped from the payload before contextual evaluation or transmission to the TypeSafe System One API.
By default (strip_prose_comments=True):
- The credential AKIAIOSFODNN7EXAMPLE is caught in stage 1, registered as a violation, and masked.
- The prose comment <!-- ... --> is then stripped from the evaluation payload sent to the API.
- Fenced code blocks are preserved: Comments inside fenced markdown code blocks (e.g. ```html <!-- safe comment --> ```) are preserved untouched so technical code examples are not corrupted.