Comparison
Feature comparison
What each project says it can do, from its own documentation. Read on 2026-09-30. A mark means listed only; “tested” means a committed test checks it.
| Feature | redact-secret0.1.0-beta.14 | flare-redact1.6.1 | OpenRedaction1.1.5 |
|---|---|---|---|
| WHERE IT RUNS | |||
| Node.js | Yes. Node.js 20, 22 and 24; native add-on with WebAssembly fallback tested | Yes. Node 20 or later tested | Yes. Node 20 or later (engines field) tested |
| Web browser | Yes. WebAssembly build; needs ES2022 | Yes. Listed: browser and edge runtimes | Not listed. Not documented; the main entry imports Node built-ins, a separate lite entry does not tested |
| Edge runtimes | Opt-in or partly. Cloudflare Workers is supported; Vercel Edge is not | Yes. Listed: edge runtimes | Not listed. — |
| Python | Yes. PyPI package | Opt-in or partly. Separate SDK, installed from git | Not listed. — |
| Rust | Yes. crates.io crate; the core is written in Rust | Opt-in or partly. Separate SDK, installed from git | Not listed. — |
| Go | Not listed. — | Opt-in or partly. Separate SDK | Not listed. — |
| Command line | Yes. Checks files and staged diffs; redacts one file or standard input | Yes. CLI: scan, redact, gateway | Not listed. No bin entry in the package |
| As a separate service | Not listed. Runs inside your process | Yes. Docker sidecar gateway | Opt-in or partly. REST API, described for the larger openredaction package |
| WHAT IT FINDS | |||
| Passwords and API keys | Yes. 173 credential families from 92 providers | Yes. Tokens, keys, JWTs and connection strings, listed by detector | Yes. API keys, OAuth tokens, JWT and bearer tokens |
| Emails, cards and IBANs | Opt-in or partly. Opt-in personal-data switch; provisional | Yes. On by default | Yes. Listed: email, credit cards, IBANs |
| Phone numbers | Opt-in or partly. Opt-in; +1 / NANP numbers only | Opt-in or partly. Opt-in (phone) | Yes. US, UK and international |
| IP addresses | Opt-in or partly. Opt-in network address family | Opt-in or partly. Opt-in (network): IPs, MAC addresses, coordinates | Not listed. Not listed in its README |
| National ID numbers | Opt-in or partly. US Social Security numbers only, opt-in, pending | Opt-in or partly. Opt-in; 15 countries listed, checksum-validated | Yes. 50+ countries listed |
| Names and street addresses | Not listed. — | Opt-in or partly. Opt-in contextual detectors: names, street addresses, dates of birth | Opt-in or partly. Names listed; street addresses not listed |
| Your own formats | Yes. Declarative rulesets: data, no code callbacks | Yes. Custom detectors and allow-lists | Not listed. Not listed in its README |
| HOW IT HIDES THINGS | |||
| What hidden text looks like | Yes. <SECRET_1> tested | Yes. b***@*** tested | Yes. [EMAIL_9619] tested |
| Keep a hint (last 4 digits) | Not listed. Placeholder formatter sees finding metadata, not the value | Yes. The default: masks keep a hint | Yes. Mask-middle and mask-all modes |
| Same value, same stand-in | Opt-in or partly. Same input, same output; one placeholder per value is not stated | Yes. Hash, pseudonym and surrogate modes; one placeholder per value in a vault | Yes. Deterministic placeholders |
| Get the originals back | Opt-in or partly. Separate opt-in vault package; in-memory packages beta, persistent server profile alpha | Yes. Vault, with optional AES-GCM persistence | Yes. Result carries a redaction map; restore() in the package types |
| Warn or block instead of hiding | Yes. Policy: redact, block, warn or allow; a callback or declarative action-policy rules | Yes. Middleware actions: redact, observe or block | Not listed. Not listed in its README |
| HOW IT FITS INTO AN APP | |||
| Text that arrives in pieces | Yes. Same result as scanning it whole tested | Yes. Secrets split across chunks tested | Opt-in or partly. A StreamingDetector class is exported; its behaviour is not documented |
| Logs | Yes. Pino and Python logging adapters, separate packages | Yes. Pino, Winston and console | Not listed. Not listed in its README |
| Tracing | Yes. OpenTelemetry span processor, separate package | Opt-in or partly. Generic boundary for telemetry exporters | Not listed. Not listed in its README |
| LLM prompts and agent tools | Opt-in or partly. MCP and AI-context packages, separate repository; not covered by Stable contract 1 | Yes. Wraps OpenAI and Anthropic clients, tool calls and MCP | Not listed. Not listed in its README |
| JSON, CSV and spreadsheets | Not listed. Works on text | Opt-in or partly. Objects, JSON and CSV; spreadsheets not listed | Yes. JSON, CSV and XLSX |
| Audit log and multiple tenants | Not listed. — | Opt-in or partly. Gateway audit line with counts; tenants not listed | Yes. SQLite or PostgreSQL audit log; multi-tenancy |
| Answers right away (no waiting) | Yes. Synchronous call after one initialize() tested | Yes. Synchronous call tested | Not listed. Returns a promise tested |
| SAFETY | |||
| Results never repeat the secret | Yes. Findings carry position and type only tested | Yes. scan() leaves values out by default tested | Not listed. Result includes the original text and a value map tested |
| No network calls or telemetry | Yes. Stated | Not listed. Not stated | Not listed. Not stated |
Where this comes from
- redact-secret 0.1.0-beta.14 (the published @redact-secret/core, tag v0.1.0-beta.14): the package README, the repository README and its guides at that tag. Adapters and the vault ship as separate packages and say so in the cell. Package README, Repository README, CLI guide, Rulesets guide, Streaming guide.
- flare-redact 1.6.1: the README at tag v1.6.1, which is the README shipped in the npm package, and its package.json. README, package.json.
- OpenRedaction @openredaction/core 1.1.5: the README shipped in the npm package, its package.json and its type declarations. The README describes the larger openredaction package; where a feature is listed only for that package, or not at all, the cell says so. README, Type declarations, package.json.
- A dash means not listed in the documentation read, or not stated. It does not say the library cannot do it.
- “tested” means a test in this repository runs the pinned version on every CI run and checks the claim (tests/feature-claims.test.mjs). Everything else is what the project says about itself.