Comparison · One pair at a time
How long does it take? It depends on the text.
redact-secret and flare-redact ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.
redact-secret0.1.0-beta.14npm
Setting: Default (no PII)
Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.
Turns on no PII family.
flare-redact1.6.1npm
Setting: defaults
Package flare-redact. Timed call: redact(), synchronous.
No options passed: the library runs as installed.
Read this first
- The libraries do different jobs on the same text: each finds and replaces what its own rules look for. So every time comes with what the call did, how many of the text’s values it hid.
- Only times from one run are set side by side. flare-redact is timed again in every run, so its numbers move a little when you switch the redact-secret setting. Times from different runs, machines or CPUs are not comparable, and neither are these and the Performance page’s.
- Between the runs, the same flare-redact call on the same text moved by up to 84% (most on real-looking-values). Within a run, a library's timed calls span a range, the thin line. Where the two ranges overlap, or the two times are closer than that run-to-run movement on the same text, the row says so and the times are not read as different.
- Times are absolute and recorded, not graded. Nothing here is a ranking.
Every text, one scale
Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.
1 / 2
Text with personal data
Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.
- Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.
real-looking-values · 128.0 KiB · each line repeated 512 timesredact-secret1.9 ms67.9 MB/s · 12 runs1.8 to 2.0 msHid 0 of 8 values: this setting has none of them switched onflare-redact5.1 ms25.3 MB/s · 12 runs4.8 to 8.3 msHid 4 of 8 values - Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.
validator-heavy · 92.5 KiB · each line repeated 512 timesredact-secret1.2 ms78.0 MB/s · 12 runs1.1 to 3.2 msHid 0 of 8 values: this setting has none of them switched onflare-redact2.2 ms41.6 MB/s · 12 runs2.1 to 5.9 msHid 3 of 8 valuesThe two ranges overlap: these times are not read as different.
- Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.
multilingual-context · 147.0 KiB · each line repeated 512 timesredact-secret2.4 ms61.3 MB/s · 12 runs2.2 to 3.3 msHid 0 of 9 values: this setting has none of them switched onflare-redact4.8 ms30.9 MB/s · 12 runs4.6 to 5.4 msHid 4 of 9 values
2 / 2
Text with credentials
Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.
- Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.
credentials-real · 287.5 KiB · each line repeated 512 timesredact-secret20.0 ms13.7 MB/s · 12 runs17.4 to 725 msHid 8 of 8 valuesflare-redact9.6 ms29.7 MB/s · 12 runs8.5 to 117 msHid 8 of 8 valuesThe two ranges overlap: these times are not read as different.
- Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.
credentials-fake · 164.0 KiB · each line repeated 512 timesredact-secret6.2 ms26.8 MB/s · 12 runs6.0 to 23.6 msHid 0 of 8 valuesflare-redact4.1 ms39.8 MB/s · 12 runs3.9 to 15.1 msHid 5 of 8 valuesThe two ranges overlap: these times are not read as different.
- Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.
credentials-context · 285.0 KiB · each line repeated 512 timesredact-secret18.9 ms15.0 MB/s · 12 runs17.2 to 28.8 msHid 6 of 8 valuesflare-redact7.6 ms36.6 MB/s · 12 runs6.3 to 10.7 msHid 6 of 8 values
redact-secret on its own
| Text | redact-secret, usual time | 95th percentile | Speed |
|---|---|---|---|
scale-logs-small-wholeOne-shot scan | 2.1 ms2.0 to 2.3 ms | 2.3 ms | 31.6 MB/s5 runs |
scale-logs-medium-fixed4096Chunked incremental (4 KiB) | 13.8 ms13.8 to 13.9 ms | 13.9 ms | 19.0 MB/s5 runs |
Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.
Not measured for this pair
How big is the text?
The same kind of text at 64 KiB, 256 KiB and 10 MiB.
Not measuredThe separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.
What does the text look like?
One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.
Not measuredThe pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.
Text built to slow scanners down
Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.
Not measuredThe registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.
How many secrets does it hold?
The same mixed text with none, one and eight secrets per KiB.
Not measuredNo committed run varies the number of secrets in one text for both libraries. Tracked in #571.
Does it arrive whole or in pieces?
The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.
Not measuredThe separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.
How this was measured
- Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
- Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
- Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
- OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
- redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
- Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
- One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
- Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
- The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.
Comparison · One pair at a time
How long does it take? It depends on the text.
redact-secret and flare-redact ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.
redact-secret0.1.0-beta.14npm
Setting: PII (pii:global)
Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.
Turns on: email, iban, network address, payment card, phone.
flare-redact1.6.1npm
Setting: defaults
Package flare-redact. Timed call: redact(), synchronous.
No options passed: the library runs as installed.
Read this first
- The libraries do different jobs on the same text: each finds and replaces what its own rules look for. So every time comes with what the call did, how many of the text’s values it hid.
- Only times from one run are set side by side. flare-redact is timed again in every run, so its numbers move a little when you switch the redact-secret setting. Times from different runs, machines or CPUs are not comparable, and neither are these and the Performance page’s.
- Between the runs, the same flare-redact call on the same text moved by up to 84% (most on real-looking-values). Within a run, a library's timed calls span a range, the thin line. Where the two ranges overlap, or the two times are closer than that run-to-run movement on the same text, the row says so and the times are not read as different.
- Times are absolute and recorded, not graded. Nothing here is a ranking.
Every text, one scale
Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.
1 / 2
Text with personal data
Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.
- Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.
real-looking-values · 128.0 KiB · each line repeated 512 timesredact-secret17.1 ms7.3 MB/s · 12 runs14.7 to 21.2 msHid 7 of 8 valuesflare-redact9.4 ms13.6 MB/s · 12 runs6.7 to 12.3 msHid 4 of 8 valuesThe two times are closer than flare-redact moved between runs on this text (84%): not read as different.
- Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.
validator-heavy · 92.5 KiB · each line repeated 512 timesredact-secret6.4 ms14.4 MB/s · 12 runs5.8 to 14.5 msHid 1 of 8 valuesflare-redact3.5 ms27.1 MB/s · 12 runs2.9 to 4.4 msHid 3 of 8 values - Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.
multilingual-context · 147.0 KiB · each line repeated 512 timesredact-secret8.6 ms17.4 MB/s · 12 runs7.9 to 10.1 msHid 0 of 9 valuesflare-redact6.7 ms22.4 MB/s · 12 runs6.3 to 9.5 msHid 4 of 9 valuesThe two ranges overlap: these times are not read as different.
2 / 2
Text with credentials
Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.
- Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.
credentials-real · 287.5 KiB · each line repeated 512 timesredact-secret22.5 ms13.1 MB/s · 12 runs20.3 to 27.4 msHid 8 of 8 valuesflare-redact11.5 ms25.3 MB/s · 12 runs9.8 to 21.4 msHid 8 of 8 valuesThe two ranges overlap: these times are not read as different.
- Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.
credentials-fake · 164.0 KiB · each line repeated 512 timesredact-secret7.0 ms23.9 MB/s · 12 runs6.5 to 8.1 msHid 0 of 8 valuesflare-redact4.5 ms34.9 MB/s · 12 runs3.9 to 7.6 msHid 5 of 8 valuesThe two ranges overlap: these times are not read as different.
- Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.
credentials-context · 285.0 KiB · each line repeated 512 timesredact-secret21.2 ms13.0 MB/s · 12 runs17.0 to 43.1 msHid 6 of 8 valuesflare-redact7.5 ms35.2 MB/s · 12 runs6.4 to 17.0 msHid 6 of 8 valuesThe two ranges overlap: these times are not read as different.
redact-secret on its own
| Text | redact-secret, usual time | 95th percentile | Speed |
|---|---|---|---|
scale-logs-small-wholeOne-shot scan | 2.1 ms2.0 to 2.3 ms | 2.3 ms | 31.6 MB/s5 runs |
scale-logs-medium-fixed4096Chunked incremental (4 KiB) | 13.8 ms13.8 to 13.9 ms | 13.9 ms | 19.0 MB/s5 runs |
Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.
Not measured for this pair
How big is the text?
The same kind of text at 64 KiB, 256 KiB and 10 MiB.
Not measuredThe separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.
What does the text look like?
One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.
Not measuredThe pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.
Text built to slow scanners down
Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.
Not measuredThe registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.
How many secrets does it hold?
The same mixed text with none, one and eight secrets per KiB.
Not measuredNo committed run varies the number of secrets in one text for both libraries. Tracked in #571.
Does it arrive whole or in pieces?
The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.
Not measuredThe separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.
How this was measured
- Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
- Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
- Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
- OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
- redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII setting (pii:global). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
- Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
- One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
- Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
- The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.
Comparison · One pair at a time
How long does it take? It depends on the text.
redact-secret and flare-redact ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.
redact-secret0.1.0-beta.14npm
Setting: PII + US (adds pii:us)
Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.
Turns on: email, iban, network address, payment card, phone, ssn.
flare-redact1.6.1npm
Setting: defaults
Package flare-redact. Timed call: redact(), synchronous.
No options passed: the library runs as installed.
Read this first
- The libraries do different jobs on the same text: each finds and replaces what its own rules look for. So every time comes with what the call did, how many of the text’s values it hid.
- Only times from one run are set side by side. flare-redact is timed again in every run, so its numbers move a little when you switch the redact-secret setting. Times from different runs, machines or CPUs are not comparable, and neither are these and the Performance page’s.
- Between the runs, the same flare-redact call on the same text moved by up to 84% (most on real-looking-values). Within a run, a library's timed calls span a range, the thin line. Where the two ranges overlap, or the two times are closer than that run-to-run movement on the same text, the row says so and the times are not read as different.
- Times are absolute and recorded, not graded. Nothing here is a ranking.
Every text, one scale
Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.
1 / 2
Text with personal data
Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.
- Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.
real-looking-values · 128.0 KiB · each line repeated 512 timesredact-secret17.8 ms7.2 MB/s · 12 runs16.3 to 25.0 msHid 8 of 8 valuesflare-redact8.2 ms15.5 MB/s · 12 runs6.4 to 20.8 msHid 4 of 8 valuesThe two ranges overlap: these times are not read as different.
- Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.
validator-heavy · 92.5 KiB · each line repeated 512 timesredact-secret7.8 ms12.1 MB/s · 12 runs6.8 to 10.1 msHid 2 of 8 valuesflare-redact2.9 ms32.0 MB/s · 12 runs2.8 to 3.8 msHid 3 of 8 values - Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.
multilingual-context · 147.0 KiB · each line repeated 512 timesredact-secret11.8 ms11.8 MB/s · 12 runs8.6 to 132 msHid 0 of 9 valuesflare-redact8.5 ms17.6 MB/s · 12 runs5.5 to 64.3 msHid 4 of 9 valuesThe two ranges overlap: these times are not read as different.
2 / 2
Text with credentials
Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.
- Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.
credentials-real · 287.5 KiB · each line repeated 512 timesredact-secret21.9 ms13.2 MB/s · 12 runs19.8 to 25.8 msHid 8 of 8 valuesflare-redact10.0 ms28.2 MB/s · 12 runs9.3 to 13.5 msHid 8 of 8 values - Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.
credentials-fake · 164.0 KiB · each line repeated 512 timesredact-secret6.8 ms23.0 MB/s · 12 runs6.2 to 8.0 msHid 0 of 8 valuesflare-redact4.4 ms34.5 MB/s · 12 runs3.7 to 6.2 msHid 5 of 8 valuesThe two ranges overlap: these times are not read as different.
- Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.
credentials-context · 285.0 KiB · each line repeated 512 timesredact-secret18.3 ms15.9 MB/s · 12 runs16.8 to 34.0 msHid 6 of 8 valuesflare-redact6.7 ms42.3 MB/s · 12 runs6.1 to 21.8 msHid 6 of 8 valuesThe two ranges overlap: these times are not read as different.
redact-secret on its own
| Text | redact-secret, usual time | 95th percentile | Speed |
|---|---|---|---|
scale-logs-small-wholeOne-shot scan | 2.1 ms2.0 to 2.3 ms | 2.3 ms | 31.6 MB/s5 runs |
scale-logs-medium-fixed4096Chunked incremental (4 KiB) | 13.8 ms13.8 to 13.9 ms | 13.9 ms | 19.0 MB/s5 runs |
Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.
Not measured for this pair
How big is the text?
The same kind of text at 64 KiB, 256 KiB and 10 MiB.
Not measuredThe separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.
What does the text look like?
One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.
Not measuredThe pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.
Text built to slow scanners down
Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.
Not measuredThe registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.
How many secrets does it hold?
The same mixed text with none, one and eight secrets per KiB.
Not measuredNo committed run varies the number of secrets in one text for both libraries. Tracked in #571.
Does it arrive whole or in pieces?
The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.
Not measuredThe separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.
How this was measured
- Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
- Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
- Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
- OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
- redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII + US setting (pii:global, pii:us). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
- Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
- One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
- Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
- The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.
Comparison · One pair at a time
How long does it take? It depends on the text.
redact-secret and OpenRedaction ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.
redact-secret0.1.0-beta.14npm
Setting: Default (no PII)
Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.
Turns on no PII family.
OpenRedaction1.1.5npm
Setting: defaults
Package @openredaction/core. Timed call: detect(), asynchronous, returns a Promise.
No options passed: the library runs as installed.
Read this first
- The libraries do different jobs on the same text: each finds and replaces what its own rules look for. So every time comes with what the call did, how many of the text’s values it hid.
- Only times from one run are set side by side. OpenRedaction is timed again in every run, so its numbers move a little when you switch the redact-secret setting. Times from different runs, machines or CPUs are not comparable, and neither are these and the Performance page’s.
- Between the runs, the same OpenRedaction call on the same text moved by up to 108% (most on multilingual-context). Within a run, a library's timed calls span a range, the thin line. Where the two ranges overlap, or the two times are closer than that run-to-run movement on the same text, the row says so and the times are not read as different.
- Times are absolute and recorded, not graded. Nothing here is a ranking.
Every text, one scale
Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.
1 / 2
Text with personal data
Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.
- Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.
real-looking-values · 128.0 KiB · each line repeated 512 timesredact-secret1.9 ms67.9 MB/s · 12 runs1.8 to 2.0 msHid 0 of 8 values: this setting has none of them switched onOpenRedaction377 ms0.3 MB/s · 12 runs249 to 413 msHid 7 of 8 values - Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.
validator-heavy · 92.5 KiB · each line repeated 512 timesredact-secret1.2 ms78.0 MB/s · 12 runs1.1 to 3.2 msHid 0 of 8 values: this setting has none of them switched onOpenRedaction271 ms0.3 MB/s · 12 runs265 to 593 msHid 4 of 8 values - Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.
multilingual-context · 147.0 KiB · each line repeated 512 timesredact-secret2.4 ms61.3 MB/s · 12 runs2.2 to 3.3 msHid 0 of 9 values: this setting has none of them switched onOpenRedaction386 ms0.4 MB/s · 12 runs381 to 1,976 msHid 4 of 9 values
2 / 2
Text with credentials
Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.
- Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.
credentials-real · 287.5 KiB · each line repeated 512 timesredact-secret20.0 ms13.7 MB/s · 12 runs17.4 to 725 msHid 8 of 8 valuesOpenRedaction1,407 ms0.2 MB/s · 12 runs1,033 to 4,383 msHid 8 of 8 values - Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.
credentials-fake · 164.0 KiB · each line repeated 512 timesredact-secret6.2 ms26.8 MB/s · 12 runs6.0 to 23.6 msHid 0 of 8 valuesOpenRedaction234 ms0.7 MB/s · 12 runs226 to 590 msHid 2 of 8 values - Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.
credentials-context · 285.0 KiB · each line repeated 512 timesredact-secret18.9 ms15.0 MB/s · 12 runs17.2 to 28.8 msHid 6 of 8 valuesOpenRedaction1,009 ms0.3 MB/s · 12 runs914 to 1,495 msHid 4 of 8 values
redact-secret on its own
| Text | redact-secret, usual time | 95th percentile | Speed |
|---|---|---|---|
scale-logs-small-wholeOne-shot scan | 2.1 ms2.0 to 2.3 ms | 2.3 ms | 31.6 MB/s5 runs |
scale-logs-medium-fixed4096Chunked incremental (4 KiB) | 13.8 ms13.8 to 13.9 ms | 13.9 ms | 19.0 MB/s5 runs |
Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.
Not measured for this pair
How big is the text?
The same kind of text at 64 KiB, 256 KiB and 10 MiB.
Not measuredThe separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.
What does the text look like?
One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.
Not measuredThe pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.
Text built to slow scanners down
Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.
Not measuredThe registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.
How many secrets does it hold?
The same mixed text with none, one and eight secrets per KiB.
Not measuredNo committed run varies the number of secrets in one text for both libraries. Tracked in #571.
Does it arrive whole or in pieces?
The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.
Not measuredThe separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.
How this was measured
- Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
- Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
- Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
- OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
- redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
- Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
- One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
- Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
- The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.
Comparison · One pair at a time
How long does it take? It depends on the text.
redact-secret and OpenRedaction ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.
redact-secret0.1.0-beta.14npm
Setting: PII (pii:global)
Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.
Turns on: email, iban, network address, payment card, phone.
OpenRedaction1.1.5npm
Setting: defaults
Package @openredaction/core. Timed call: detect(), asynchronous, returns a Promise.
No options passed: the library runs as installed.
Read this first
- The libraries do different jobs on the same text: each finds and replaces what its own rules look for. So every time comes with what the call did, how many of the text’s values it hid.
- Only times from one run are set side by side. OpenRedaction is timed again in every run, so its numbers move a little when you switch the redact-secret setting. Times from different runs, machines or CPUs are not comparable, and neither are these and the Performance page’s.
- Between the runs, the same OpenRedaction call on the same text moved by up to 108% (most on multilingual-context). Within a run, a library's timed calls span a range, the thin line. Where the two ranges overlap, or the two times are closer than that run-to-run movement on the same text, the row says so and the times are not read as different.
- Times are absolute and recorded, not graded. Nothing here is a ranking.
Every text, one scale
Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.
1 / 2
Text with personal data
Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.
- Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.
real-looking-values · 128.0 KiB · each line repeated 512 timesredact-secret17.1 ms7.3 MB/s · 12 runs14.7 to 21.2 msHid 7 of 8 valuesOpenRedaction673 ms0.2 MB/s · 12 runs460 to 1,826 msHid 7 of 8 values - Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.
validator-heavy · 92.5 KiB · each line repeated 512 timesredact-secret6.4 ms14.4 MB/s · 12 runs5.8 to 14.5 msHid 1 of 8 valuesOpenRedaction472 ms0.2 MB/s · 12 runs405 to 779 msHid 4 of 8 values - Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.
multilingual-context · 147.0 KiB · each line repeated 512 timesredact-secret8.6 ms17.4 MB/s · 12 runs7.9 to 10.1 msHid 0 of 9 valuesOpenRedaction614 ms0.2 MB/s · 12 runs585 to 794 msHid 4 of 9 values
2 / 2
Text with credentials
Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.
- Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.
credentials-real · 287.5 KiB · each line repeated 512 timesredact-secret22.5 ms13.1 MB/s · 12 runs20.3 to 27.4 msHid 8 of 8 valuesOpenRedaction1,430 ms0.2 MB/s · 12 runs1,307 to 3,159 msHid 8 of 8 values - Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.
credentials-fake · 164.0 KiB · each line repeated 512 timesredact-secret7.0 ms23.9 MB/s · 12 runs6.5 to 8.1 msHid 0 of 8 valuesOpenRedaction250 ms0.7 MB/s · 12 runs232 to 400 msHid 2 of 8 values - Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.
credentials-context · 285.0 KiB · each line repeated 512 timesredact-secret21.2 ms13.0 MB/s · 12 runs17.0 to 43.1 msHid 6 of 8 valuesOpenRedaction1,144 ms0.2 MB/s · 12 runs872 to 1,778 msHid 4 of 8 values
redact-secret on its own
| Text | redact-secret, usual time | 95th percentile | Speed |
|---|---|---|---|
scale-logs-small-wholeOne-shot scan | 2.1 ms2.0 to 2.3 ms | 2.3 ms | 31.6 MB/s5 runs |
scale-logs-medium-fixed4096Chunked incremental (4 KiB) | 13.8 ms13.8 to 13.9 ms | 13.9 ms | 19.0 MB/s5 runs |
Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.
Not measured for this pair
How big is the text?
The same kind of text at 64 KiB, 256 KiB and 10 MiB.
Not measuredThe separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.
What does the text look like?
One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.
Not measuredThe pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.
Text built to slow scanners down
Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.
Not measuredThe registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.
How many secrets does it hold?
The same mixed text with none, one and eight secrets per KiB.
Not measuredNo committed run varies the number of secrets in one text for both libraries. Tracked in #571.
Does it arrive whole or in pieces?
The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.
Not measuredThe separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.
How this was measured
- Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
- Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
- Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
- OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
- redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII setting (pii:global). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
- Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
- One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
- Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
- The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.
Comparison · One pair at a time
How long does it take? It depends on the text.
redact-secret and OpenRedaction ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.
redact-secret0.1.0-beta.14npm
Setting: PII + US (adds pii:us)
Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.
Turns on: email, iban, network address, payment card, phone, ssn.
OpenRedaction1.1.5npm
Setting: defaults
Package @openredaction/core. Timed call: detect(), asynchronous, returns a Promise.
No options passed: the library runs as installed.
Read this first
- The libraries do different jobs on the same text: each finds and replaces what its own rules look for. So every time comes with what the call did, how many of the text’s values it hid.
- Only times from one run are set side by side. OpenRedaction is timed again in every run, so its numbers move a little when you switch the redact-secret setting. Times from different runs, machines or CPUs are not comparable, and neither are these and the Performance page’s.
- Between the runs, the same OpenRedaction call on the same text moved by up to 108% (most on multilingual-context). Within a run, a library's timed calls span a range, the thin line. Where the two ranges overlap, or the two times are closer than that run-to-run movement on the same text, the row says so and the times are not read as different.
- Times are absolute and recorded, not graded. Nothing here is a ranking.
Every text, one scale
Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.
1 / 2
Text with personal data
Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.
- Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.
real-looking-values · 128.0 KiB · each line repeated 512 timesredact-secret17.8 ms7.2 MB/s · 12 runs16.3 to 25.0 msHid 8 of 8 valuesOpenRedaction684 ms0.2 MB/s · 12 runs493 to 987 msHid 7 of 8 values - Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.
validator-heavy · 92.5 KiB · each line repeated 512 timesredact-secret7.8 ms12.1 MB/s · 12 runs6.8 to 10.1 msHid 2 of 8 valuesOpenRedaction455 ms0.2 MB/s · 12 runs380 to 648 msHid 4 of 8 values - Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.
multilingual-context · 147.0 KiB · each line repeated 512 timesredact-secret11.8 ms11.8 MB/s · 12 runs8.6 to 132 msHid 0 of 9 valuesOpenRedaction802 ms0.2 MB/s · 12 runs642 to 1,849 msHid 4 of 9 values
2 / 2
Text with credentials
Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.
- Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.
credentials-real · 287.5 KiB · each line repeated 512 timesredact-secret21.9 ms13.2 MB/s · 12 runs19.8 to 25.8 msHid 8 of 8 valuesOpenRedaction1,384 ms0.2 MB/s · 12 runs1,258 to 2,239 msHid 8 of 8 values - Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.
credentials-fake · 164.0 KiB · each line repeated 512 timesredact-secret6.8 ms23.0 MB/s · 12 runs6.2 to 8.0 msHid 0 of 8 valuesOpenRedaction235 ms0.7 MB/s · 12 runs216 to 340 msHid 2 of 8 values - Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.
credentials-context · 285.0 KiB · each line repeated 512 timesredact-secret18.3 ms15.9 MB/s · 12 runs16.8 to 34.0 msHid 6 of 8 valuesOpenRedaction907 ms0.3 MB/s · 12 runs855 to 1,717 msHid 4 of 8 values
redact-secret on its own
| Text | redact-secret, usual time | 95th percentile | Speed |
|---|---|---|---|
scale-logs-small-wholeOne-shot scan | 2.1 ms2.0 to 2.3 ms | 2.3 ms | 31.6 MB/s5 runs |
scale-logs-medium-fixed4096Chunked incremental (4 KiB) | 13.8 ms13.8 to 13.9 ms | 13.9 ms | 19.0 MB/s5 runs |
Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.
Not measured for this pair
How big is the text?
The same kind of text at 64 KiB, 256 KiB and 10 MiB.
Not measuredThe separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.
What does the text look like?
One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.
Not measuredThe pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.
Text built to slow scanners down
Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.
Not measuredThe registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.
How many secrets does it hold?
The same mixed text with none, one and eight secrets per KiB.
Not measuredNo committed run varies the number of secrets in one text for both libraries. Tracked in #571.
Does it arrive whole or in pieces?
The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.
Not measuredThe separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.
How this was measured
- Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
- Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
- Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
- OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
- redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII + US setting (pii:global, pii:us). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
- Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
- One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
- Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
- The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.