Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
1,440 test files. Secrets in formats the provider itself documents. Expected: hidden.
Show the 891 files with different results
2 / 2
Safe text that must be left alone
167 test files. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.
Show the 6 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
468 test files whose provider family one of flare-redact’s rules targets. Secrets in formats the provider itself documents. Expected: hidden.
Show the 43 files with different results
2 / 2
Safe text that must be left alone
65 test files whose provider family one of flare-redact’s rules targets. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.
Show the 4 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
548 test files. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.
Show the 351 files with different results
2 / 2
Safe text that must be left alone
1,866 test files. Look-alikes and near misses of those formats. Expected: left alone.
Show the 78 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
195 test files whose provider family one of flare-redact’s rules targets. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.
Show the 35 files with different results
2 / 2
Safe text that must be left alone
555 test files whose provider family one of flare-redact’s rules targets. Look-alikes and near misses of those formats. Expected: left alone.
Show the 58 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
Hidden by default
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
1,006 test files. Values this project’s own masking policy hides. Expected: hidden.
Show the 553 files with different results
2 / 2
Safe text that must be left alone
1,880 test files. Text this project’s policy leaves alone. Expected: left alone.
Show the 49 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
Hidden by default
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Runtime library
flare-redact1.6.1
Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.
Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
365 test files whose provider family one of flare-redact’s rules targets. Values this project’s own masking policy hides. Expected: hidden.
Show the 30 files with different results
2 / 2
Safe text that must be left alone
339 test files whose provider family one of flare-redact’s rules targets. Text this project’s policy leaves alone. Expected: left alone.
Show the 28 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
1,440 test files. Secrets in formats the provider itself documents. Expected: hidden.
Show the 487 files with different results
2 / 2
Safe text that must be left alone
167 test files. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.
Show the 10 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
635 test files whose provider family one of gitleaks’ rules targets. Secrets in formats the provider itself documents. Expected: hidden.
Show the 89 files with different results
2 / 2
Safe text that must be left alone
56 test files whose provider family one of gitleaks’ rules targets. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.
Show the 5 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
548 test files. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.
Show the 157 files with different results
2 / 2
Safe text that must be left alone
1,866 test files. Look-alikes and near misses of those formats. Expected: left alone.
Show the 115 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
268 test files whose provider family one of gitleaks’ rules targets. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.
Show the 40 files with different results
2 / 2
Safe text that must be left alone
825 test files whose provider family one of gitleaks’ rules targets. Look-alikes and near misses of those formats. Expected: left alone.
Show the 75 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
Hidden by default
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
1,006 test files. Values this project’s own masking policy hides. Expected: hidden.
Show the 466 files with different results
2 / 2
Safe text that must be left alone
1,880 test files. Text this project’s policy leaves alone. Expected: left alone.
Show the 55 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
Hidden by default
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
gitleaks8.30.1
Built to find secrets in git history, files and directories before they are committed.
Ran as: Directory scan · default rules
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
517 test files whose provider family one of gitleaks’ rules targets. Values this project’s own masking policy hides. Expected: hidden.
Show the 174 files with different results
2 / 2
Safe text that must be left alone
576 test files whose provider family one of gitleaks’ rules targets. Text this project’s policy leaves alone. Expected: left alone.
Show the 16 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
1,440 test files. Secrets in formats the provider itself documents. Expected: hidden.
Show the 844 files with different results
2 / 2
Safe text that must be left alone
167 test files. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.
Show the 4 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
722 test files whose provider family one of trufflehog’s rules targets. Secrets in formats the provider itself documents. Expected: hidden.
Show the 156 files with different results
2 / 2
Safe text that must be left alone
73 test files whose provider family one of trufflehog’s rules targets. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.
Show the 2 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
548 test files. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.
Show the 314 files with different results
2 / 2
Safe text that must be left alone
1,866 test files. Look-alikes and near misses of those formats. Expected: left alone.
Show the 66 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
336 test files whose provider family one of trufflehog’s rules targets. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.
Show the 102 files with different results
2 / 2
Safe text that must be left alone
1,045 test files whose provider family one of trufflehog’s rules targets. Look-alikes and near misses of those formats. Expected: left alone.
Show the 56 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
Hidden by default
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
1,006 test files. Values this project’s own masking policy hides. Expected: hidden.
Show the 837 files with different results
2 / 2
Safe text that must be left alone
1,880 test files. Text this project’s policy leaves alone. Expected: left alone.
Show the 43 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
Hidden by default
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.
Ran as: Published npm package · default detectors
Measured in this run, 2026-10-07
Repository scanner
trufflehog3.97.4
Built to find and verify secrets in repositories and other sources. Verification is off here.
Ran as: Filesystem scan · verification disabled
Observed in the official run sha256:4bec6e539482…, 2026-10-07
Read this first
1 / 2
Secrets that must be hidden
519 test files whose provider family one of trufflehog’s rules targets. Values this project’s own masking policy hides. Expected: hidden.
Show the 403 files with different results
2 / 2
Safe text that must be left alone
631 test files whose provider family one of trufflehog’s rules targets. Text this project’s policy leaves alone. Expected: left alone.
Show the 24 files with different results
Where this comes from
- redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
- trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
- Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
- Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Ran as: PII switched on (pii:global, pii:us) · published package
Run 2026-10-07
Runtime library
flare-redact1.6.1
Ran as: Defaults · published package
Run 2026-10-07
Read this first
Runtime preview, not peer accuracy measurement. These are the made-up texts from the runtime comparison, counted by text. Separate bounded local default type/range observations are listed on the PII evaluation page when validated. Reserved or example values follow authored neutral expectations; changed output cannot establish truth.
1 / 3
Personal data that looks real
8 texts. Made-up emails, cards, bank accounts, phone numbers and a US SSN that look like the real thing. Expected: hidden.
Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.
Hidden by redact-secret, not hidden by flare-redact4
- IP address
- US Social Security no.
- US phone number
- Phone, Korean label
Hidden by flare-redact, not hidden by redact-secret0
None. All 4 texts flare-redact hid, redact-secret hid too.
2 / 3
Values made for examples, or failing a basic check
8 texts. Standards reserve some of these for examples: example.com, 555 phone numbers, documentation IP ranges, test card numbers. redact-secret leaves reserved values alone on purpose. Other tools may hide them on purpose. Neither is marked right here. Expected: depends on the rule, so no percentage.
Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.
Hidden by redact-secret, not hidden by flare-redact1
- Social Security no.
Hidden by flare-redact, not hidden by redact-secret2
- example.com email
- Test card number
3 / 3
Values with words around them
8 texts. The same kind of made-up values next to English and Korean labels, and next to words like “example” that say they are not real. Expected: depends on the rule, so no percentage.
Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.
Hidden by redact-secret, not hidden by flare-redact0
None. redact-secret has no texts hidden here.
Hidden by flare-redact, not hidden by redact-secret3
- Email, English label
- Email, Korean label
- Email, Korean label, decomposed form
Where this comes from
- Full peer accuracy qualification remains unready. Bounded local default type/range observations preserve unsupported sensitivity, action and context quantities as withheld. Local peer scope and public artifacts.
- redact-secret 0.1.0-beta.14 with pii:global and pii:us, and flare-redact 1.6.1 at its defaults, each on the same made-up texts, run 2026-10-07 (benchmarks/inputs/runtime/runtime-comparison-pii-global-us.json). The inputs are described by kind only; their text is never published.
- “Hidden” means every value in the text came back replaced. Partly hidden counts as “Left some or all”.
- The same texts and outcomes, with times, are on the runtime comparison. Open the runtime comparison.
Comparison
Put one tool next to redact-secret
Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.
Runtime library
redact-secret0.1.0-beta.14
Ran as: PII switched on (pii:global, pii:us) · published package
Run 2026-10-07
Runtime library
OpenRedaction1.1.5
Ran as: Defaults · published package
Run 2026-10-07
Read this first
Runtime preview, not peer accuracy measurement. These are the made-up texts from the runtime comparison, counted by text. Separate bounded local default type/range observations are listed on the PII evaluation page when validated. Reserved or example values follow authored neutral expectations; changed output cannot establish truth.
1 / 3
Personal data that looks real
8 texts. Made-up emails, cards, bank accounts, phone numbers and a US SSN that look like the real thing. Expected: hidden.
Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.
Hidden by redact-secret, not hidden by OpenRedaction1
- US Social Security no.
Hidden by OpenRedaction, not hidden by redact-secret0
None. All 7 texts OpenRedaction hid, redact-secret hid too.
2 / 3
Values made for examples, or failing a basic check
8 texts. Standards reserve some of these for examples: example.com, 555 phone numbers, documentation IP ranges, test card numbers. redact-secret leaves reserved values alone on purpose. Other tools may hide them on purpose. Neither is marked right here. Expected: depends on the rule, so no percentage.
Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.
Hidden by redact-secret, not hidden by OpenRedaction1
- Social Security no.
Hidden by OpenRedaction, not hidden by redact-secret3
- Example IP address
- Test card number
- 555 phone number
3 / 3
Values with words around them
8 texts. The same kind of made-up values next to English and Korean labels, and next to words like “example” that say they are not real. Expected: depends on the rule, so no percentage.
Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.
Hidden by redact-secret, not hidden by OpenRedaction0
None. redact-secret has no texts hidden here.
Hidden by OpenRedaction, not hidden by redact-secret3
- Phone, English label
- Phone, Korean label
- IP after “documentation”
Where this comes from
- Full peer accuracy qualification remains unready. Bounded local default type/range observations preserve unsupported sensitivity, action and context quantities as withheld. Local peer scope and public artifacts.
- redact-secret 0.1.0-beta.14 with pii:global and pii:us, and OpenRedaction 1.1.5 at its defaults, each on the same made-up texts, run 2026-10-07 (benchmarks/inputs/runtime/runtime-comparison-pii-global-us.json). The inputs are described by kind only; their text is never published.
- “Hidden” means every value in the text came back replaced. Partly hidden counts as “Left some or all”.
- The same texts and outcomes, with times, are on the runtime comparison. Open the runtime comparison.