Skip to content
Benchmarks

Comparison · One pair at a time

How long does it take? It depends on the text.

redact-secret and flare-redact ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.

  • redact-secret · Default
  • flare-redact · defaults
  • Thin line: shortest to longest timed call

redact-secret0.1.0-beta.14npm

Setting: Default (no PII)

Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.

Turns on no PII family.

flare-redact1.6.1npm

Setting: defaults

Package flare-redact. Timed call: redact(), synchronous.

No options passed: the library runs as installed.

Every text, one scale

Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.

redact-secret1.2 to 20.0 ms across 6 texts
flare-redact2.2 to 9.6 ms across 6 texts

1 / 2

Text with personal data

Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.

  1. Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.real-looking-values · 128.0 KiB · each line repeated 512 times
    redact-secret1.9 ms67.9 MB/s · 12 runs1.8 to 2.0 msHid 0 of 8 values: this setting has none of them switched on
    flare-redact5.1 ms25.3 MB/s · 12 runs4.8 to 8.3 msHid 4 of 8 values
  2. Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.validator-heavy · 92.5 KiB · each line repeated 512 times
    redact-secret1.2 ms78.0 MB/s · 12 runs1.1 to 3.2 msHid 0 of 8 values: this setting has none of them switched on
    flare-redact2.2 ms41.6 MB/s · 12 runs2.1 to 5.9 msHid 3 of 8 values

    The two ranges overlap: these times are not read as different.

  3. Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.multilingual-context · 147.0 KiB · each line repeated 512 times
    redact-secret2.4 ms61.3 MB/s · 12 runs2.2 to 3.3 msHid 0 of 9 values: this setting has none of them switched on
    flare-redact4.8 ms30.9 MB/s · 12 runs4.6 to 5.4 msHid 4 of 9 values

2 / 2

Text with credentials

Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.

  1. Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.credentials-real · 287.5 KiB · each line repeated 512 times
    redact-secret20.0 ms13.7 MB/s · 12 runs17.4 to 725 msHid 8 of 8 values
    flare-redact9.6 ms29.7 MB/s · 12 runs8.5 to 117 msHid 8 of 8 values

    The two ranges overlap: these times are not read as different.

  2. Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.credentials-fake · 164.0 KiB · each line repeated 512 times
    redact-secret6.2 ms26.8 MB/s · 12 runs6.0 to 23.6 msHid 0 of 8 values
    flare-redact4.1 ms39.8 MB/s · 12 runs3.9 to 15.1 msHid 5 of 8 values

    The two ranges overlap: these times are not read as different.

  3. Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.credentials-context · 285.0 KiB · each line repeated 512 times
    redact-secret18.9 ms15.0 MB/s · 12 runs17.2 to 28.8 msHid 6 of 8 values
    flare-redact7.6 ms36.6 MB/s · 12 runs6.3 to 10.7 msHid 6 of 8 values

redact-secret on its own

The throughput the Performance page records for the Node surface, whole and in 4 KiB pieces.
This is another run, on another machine, with another protocol than the pair above, so it is not set beside those times and is not drawn on the same axis. Read it on its own.
redact-secret on its own
Textredact-secret, usual time95th percentileSpeed
scale-logs-small-wholeOne-shot scan2.1 ms2.0 to 2.3 ms2.3 ms31.6 MB/s5 runs
scale-logs-medium-fixed4096Chunked incremental (4 KiB)13.8 ms13.8 to 13.9 ms13.9 ms19.0 MB/s5 runs

Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.

Not measured for this pair

Questions a pair page can answer once a run times both libraries on them. Each is a dashed “Not measured”, never a zero.
  1. How big is the text?

    The same kind of text at 64 KiB, 256 KiB and 10 MiB.

    Not measured

    The separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

  2. What does the text look like?

    One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.

    Not measured

    The pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.

    Recorded Default pair texts and run

    Workload expansion #571

    Neutral engine capability handoff #68

  3. Text built to slow scanners down

    Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.

    Not measured

    The registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  4. How many secrets does it hold?

    The same mixed text with none, one and eight secrets per KiB.

    Not measured

    No committed run varies the number of secrets in one text for both libraries. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  5. Does it arrive whole or in pieces?

    The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.

    Not measured

    The separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

How this was measured

  • Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
  • Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
  • Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
  • OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
  • redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
  • Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
  • One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
  • Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
  • The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.

Comparison · One pair at a time

How long does it take? It depends on the text.

redact-secret and flare-redact ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.

  • redact-secret · PII
  • flare-redact · defaults
  • Thin line: shortest to longest timed call

redact-secret0.1.0-beta.14npm

Setting: PII (pii:global)

Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.

Turns on: email, iban, network address, payment card, phone.

flare-redact1.6.1npm

Setting: defaults

Package flare-redact. Timed call: redact(), synchronous.

No options passed: the library runs as installed.

Every text, one scale

Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.

redact-secret6.4 to 22.5 ms across 6 texts
flare-redact3.5 to 11.5 ms across 6 texts

1 / 2

Text with personal data

Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.

  1. Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.real-looking-values · 128.0 KiB · each line repeated 512 times
    redact-secret17.1 ms7.3 MB/s · 12 runs14.7 to 21.2 msHid 7 of 8 values
    flare-redact9.4 ms13.6 MB/s · 12 runs6.7 to 12.3 msHid 4 of 8 values

    The two times are closer than flare-redact moved between runs on this text (84%): not read as different.

  2. Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.validator-heavy · 92.5 KiB · each line repeated 512 times
    redact-secret6.4 ms14.4 MB/s · 12 runs5.8 to 14.5 msHid 1 of 8 values
    flare-redact3.5 ms27.1 MB/s · 12 runs2.9 to 4.4 msHid 3 of 8 values
  3. Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.multilingual-context · 147.0 KiB · each line repeated 512 times
    redact-secret8.6 ms17.4 MB/s · 12 runs7.9 to 10.1 msHid 0 of 9 values
    flare-redact6.7 ms22.4 MB/s · 12 runs6.3 to 9.5 msHid 4 of 9 values

    The two ranges overlap: these times are not read as different.

2 / 2

Text with credentials

Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.

  1. Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.credentials-real · 287.5 KiB · each line repeated 512 times
    redact-secret22.5 ms13.1 MB/s · 12 runs20.3 to 27.4 msHid 8 of 8 values
    flare-redact11.5 ms25.3 MB/s · 12 runs9.8 to 21.4 msHid 8 of 8 values

    The two ranges overlap: these times are not read as different.

  2. Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.credentials-fake · 164.0 KiB · each line repeated 512 times
    redact-secret7.0 ms23.9 MB/s · 12 runs6.5 to 8.1 msHid 0 of 8 values
    flare-redact4.5 ms34.9 MB/s · 12 runs3.9 to 7.6 msHid 5 of 8 values

    The two ranges overlap: these times are not read as different.

  3. Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.credentials-context · 285.0 KiB · each line repeated 512 times
    redact-secret21.2 ms13.0 MB/s · 12 runs17.0 to 43.1 msHid 6 of 8 values
    flare-redact7.5 ms35.2 MB/s · 12 runs6.4 to 17.0 msHid 6 of 8 values

    The two ranges overlap: these times are not read as different.

redact-secret on its own

The throughput the Performance page records for the Node surface, whole and in 4 KiB pieces.
This is another run, on another machine, with another protocol than the pair above, so it is not set beside those times and is not drawn on the same axis. Read it on its own.
redact-secret on its own
Textredact-secret, usual time95th percentileSpeed
scale-logs-small-wholeOne-shot scan2.1 ms2.0 to 2.3 ms2.3 ms31.6 MB/s5 runs
scale-logs-medium-fixed4096Chunked incremental (4 KiB)13.8 ms13.8 to 13.9 ms13.9 ms19.0 MB/s5 runs

Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.

Not measured for this pair

Questions a pair page can answer once a run times both libraries on them. Each is a dashed “Not measured”, never a zero.
  1. How big is the text?

    The same kind of text at 64 KiB, 256 KiB and 10 MiB.

    Not measured

    The separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

  2. What does the text look like?

    One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.

    Not measured

    The pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.

    Recorded PII pair texts and run

    Workload expansion #571

    Neutral engine capability handoff #68

  3. Text built to slow scanners down

    Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.

    Not measured

    The registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  4. How many secrets does it hold?

    The same mixed text with none, one and eight secrets per KiB.

    Not measured

    No committed run varies the number of secrets in one text for both libraries. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  5. Does it arrive whole or in pieces?

    The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.

    Not measured

    The separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

How this was measured

  • Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
  • Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
  • Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
  • OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
  • redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII setting (pii:global). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
  • Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
  • One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
  • Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
  • The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.

Comparison · One pair at a time

How long does it take? It depends on the text.

redact-secret and flare-redact ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.

  • redact-secret · PII + US
  • flare-redact · defaults
  • Thin line: shortest to longest timed call

redact-secret0.1.0-beta.14npm

Setting: PII + US (adds pii:us)

Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.

Turns on: email, iban, network address, payment card, phone, ssn.

flare-redact1.6.1npm

Setting: defaults

Package flare-redact. Timed call: redact(), synchronous.

No options passed: the library runs as installed.

Every text, one scale

Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.

redact-secret6.8 to 21.9 ms across 6 texts
flare-redact2.9 to 10.0 ms across 6 texts

1 / 2

Text with personal data

Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.

  1. Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.real-looking-values · 128.0 KiB · each line repeated 512 times
    redact-secret17.8 ms7.2 MB/s · 12 runs16.3 to 25.0 msHid 8 of 8 values
    flare-redact8.2 ms15.5 MB/s · 12 runs6.4 to 20.8 msHid 4 of 8 values

    The two ranges overlap: these times are not read as different.

  2. Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.validator-heavy · 92.5 KiB · each line repeated 512 times
    redact-secret7.8 ms12.1 MB/s · 12 runs6.8 to 10.1 msHid 2 of 8 values
    flare-redact2.9 ms32.0 MB/s · 12 runs2.8 to 3.8 msHid 3 of 8 values
  3. Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.multilingual-context · 147.0 KiB · each line repeated 512 times
    redact-secret11.8 ms11.8 MB/s · 12 runs8.6 to 132 msHid 0 of 9 values
    flare-redact8.5 ms17.6 MB/s · 12 runs5.5 to 64.3 msHid 4 of 9 values

    The two ranges overlap: these times are not read as different.

2 / 2

Text with credentials

Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.

  1. Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.credentials-real · 287.5 KiB · each line repeated 512 times
    redact-secret21.9 ms13.2 MB/s · 12 runs19.8 to 25.8 msHid 8 of 8 values
    flare-redact10.0 ms28.2 MB/s · 12 runs9.3 to 13.5 msHid 8 of 8 values
  2. Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.credentials-fake · 164.0 KiB · each line repeated 512 times
    redact-secret6.8 ms23.0 MB/s · 12 runs6.2 to 8.0 msHid 0 of 8 values
    flare-redact4.4 ms34.5 MB/s · 12 runs3.7 to 6.2 msHid 5 of 8 values

    The two ranges overlap: these times are not read as different.

  3. Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.credentials-context · 285.0 KiB · each line repeated 512 times
    redact-secret18.3 ms15.9 MB/s · 12 runs16.8 to 34.0 msHid 6 of 8 values
    flare-redact6.7 ms42.3 MB/s · 12 runs6.1 to 21.8 msHid 6 of 8 values

    The two ranges overlap: these times are not read as different.

redact-secret on its own

The throughput the Performance page records for the Node surface, whole and in 4 KiB pieces.
This is another run, on another machine, with another protocol than the pair above, so it is not set beside those times and is not drawn on the same axis. Read it on its own.
redact-secret on its own
Textredact-secret, usual time95th percentileSpeed
scale-logs-small-wholeOne-shot scan2.1 ms2.0 to 2.3 ms2.3 ms31.6 MB/s5 runs
scale-logs-medium-fixed4096Chunked incremental (4 KiB)13.8 ms13.8 to 13.9 ms13.9 ms19.0 MB/s5 runs

Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.

Not measured for this pair

Questions a pair page can answer once a run times both libraries on them. Each is a dashed “Not measured”, never a zero.
  1. How big is the text?

    The same kind of text at 64 KiB, 256 KiB and 10 MiB.

    Not measured

    The separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

  2. What does the text look like?

    One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.

    Not measured

    The pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.

    Recorded PII + US pair texts and run

    Workload expansion #571

    Neutral engine capability handoff #68

  3. Text built to slow scanners down

    Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.

    Not measured

    The registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  4. How many secrets does it hold?

    The same mixed text with none, one and eight secrets per KiB.

    Not measured

    No committed run varies the number of secrets in one text for both libraries. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  5. Does it arrive whole or in pieces?

    The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.

    Not measured

    The separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

How this was measured

  • Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
  • Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
  • Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
  • OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
  • redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII + US setting (pii:global, pii:us). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
  • Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
  • One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
  • Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
  • The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.

Comparison · One pair at a time

How long does it take? It depends on the text.

redact-secret and OpenRedaction ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.

  • redact-secret · Default
  • OpenRedaction · defaults
  • Thin line: shortest to longest timed call

redact-secret0.1.0-beta.14npm

Setting: Default (no PII)

Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.

Turns on no PII family.

OpenRedaction1.1.5npm

Setting: defaults

Package @openredaction/core. Timed call: detect(), asynchronous, returns a Promise.

No options passed: the library runs as installed.

Every text, one scale

Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.

redact-secret1.2 to 20.0 ms across 6 texts
OpenRedaction234 to 1,407 ms across 6 texts

1 / 2

Text with personal data

Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.

  1. Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.real-looking-values · 128.0 KiB · each line repeated 512 times
    redact-secret1.9 ms67.9 MB/s · 12 runs1.8 to 2.0 msHid 0 of 8 values: this setting has none of them switched on
    OpenRedaction377 ms0.3 MB/s · 12 runs249 to 413 msHid 7 of 8 values
  2. Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.validator-heavy · 92.5 KiB · each line repeated 512 times
    redact-secret1.2 ms78.0 MB/s · 12 runs1.1 to 3.2 msHid 0 of 8 values: this setting has none of them switched on
    OpenRedaction271 ms0.3 MB/s · 12 runs265 to 593 msHid 4 of 8 values
  3. Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.multilingual-context · 147.0 KiB · each line repeated 512 times
    redact-secret2.4 ms61.3 MB/s · 12 runs2.2 to 3.3 msHid 0 of 9 values: this setting has none of them switched on
    OpenRedaction386 ms0.4 MB/s · 12 runs381 to 1,976 msHid 4 of 9 values

2 / 2

Text with credentials

Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.

  1. Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.credentials-real · 287.5 KiB · each line repeated 512 times
    redact-secret20.0 ms13.7 MB/s · 12 runs17.4 to 725 msHid 8 of 8 values
    OpenRedaction1,407 ms0.2 MB/s · 12 runs1,033 to 4,383 msHid 8 of 8 values
  2. Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.credentials-fake · 164.0 KiB · each line repeated 512 times
    redact-secret6.2 ms26.8 MB/s · 12 runs6.0 to 23.6 msHid 0 of 8 values
    OpenRedaction234 ms0.7 MB/s · 12 runs226 to 590 msHid 2 of 8 values
  3. Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.credentials-context · 285.0 KiB · each line repeated 512 times
    redact-secret18.9 ms15.0 MB/s · 12 runs17.2 to 28.8 msHid 6 of 8 values
    OpenRedaction1,009 ms0.3 MB/s · 12 runs914 to 1,495 msHid 4 of 8 values

redact-secret on its own

The throughput the Performance page records for the Node surface, whole and in 4 KiB pieces.
This is another run, on another machine, with another protocol than the pair above, so it is not set beside those times and is not drawn on the same axis. Read it on its own.
redact-secret on its own
Textredact-secret, usual time95th percentileSpeed
scale-logs-small-wholeOne-shot scan2.1 ms2.0 to 2.3 ms2.3 ms31.6 MB/s5 runs
scale-logs-medium-fixed4096Chunked incremental (4 KiB)13.8 ms13.8 to 13.9 ms13.9 ms19.0 MB/s5 runs

Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.

Not measured for this pair

Questions a pair page can answer once a run times both libraries on them. Each is a dashed “Not measured”, never a zero.
  1. How big is the text?

    The same kind of text at 64 KiB, 256 KiB and 10 MiB.

    Not measured

    The separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

  2. What does the text look like?

    One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.

    Not measured

    The pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.

    Recorded Default pair texts and run

    Workload expansion #571

    Neutral engine capability handoff #68

  3. Text built to slow scanners down

    Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.

    Not measured

    The registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  4. How many secrets does it hold?

    The same mixed text with none, one and eight secrets per KiB.

    Not measured

    No committed run varies the number of secrets in one text for both libraries. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  5. Does it arrive whole or in pieces?

    The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.

    Not measured

    The separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

How this was measured

  • Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
  • Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
  • Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
  • OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
  • redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
  • Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
  • One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
  • Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
  • The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.

Comparison · One pair at a time

How long does it take? It depends on the text.

redact-secret and OpenRedaction ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.

  • redact-secret · PII
  • OpenRedaction · defaults
  • Thin line: shortest to longest timed call

redact-secret0.1.0-beta.14npm

Setting: PII (pii:global)

Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.

Turns on: email, iban, network address, payment card, phone.

OpenRedaction1.1.5npm

Setting: defaults

Package @openredaction/core. Timed call: detect(), asynchronous, returns a Promise.

No options passed: the library runs as installed.

Every text, one scale

Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.

redact-secret6.4 to 22.5 ms across 6 texts
OpenRedaction250 to 1,430 ms across 6 texts

1 / 2

Text with personal data

Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.

  1. Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.real-looking-values · 128.0 KiB · each line repeated 512 times
    redact-secret17.1 ms7.3 MB/s · 12 runs14.7 to 21.2 msHid 7 of 8 values
    OpenRedaction673 ms0.2 MB/s · 12 runs460 to 1,826 msHid 7 of 8 values
  2. Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.validator-heavy · 92.5 KiB · each line repeated 512 times
    redact-secret6.4 ms14.4 MB/s · 12 runs5.8 to 14.5 msHid 1 of 8 values
    OpenRedaction472 ms0.2 MB/s · 12 runs405 to 779 msHid 4 of 8 values
  3. Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.multilingual-context · 147.0 KiB · each line repeated 512 times
    redact-secret8.6 ms17.4 MB/s · 12 runs7.9 to 10.1 msHid 0 of 9 values
    OpenRedaction614 ms0.2 MB/s · 12 runs585 to 794 msHid 4 of 9 values

2 / 2

Text with credentials

Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.

  1. Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.credentials-real · 287.5 KiB · each line repeated 512 times
    redact-secret22.5 ms13.1 MB/s · 12 runs20.3 to 27.4 msHid 8 of 8 values
    OpenRedaction1,430 ms0.2 MB/s · 12 runs1,307 to 3,159 msHid 8 of 8 values
  2. Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.credentials-fake · 164.0 KiB · each line repeated 512 times
    redact-secret7.0 ms23.9 MB/s · 12 runs6.5 to 8.1 msHid 0 of 8 values
    OpenRedaction250 ms0.7 MB/s · 12 runs232 to 400 msHid 2 of 8 values
  3. Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.credentials-context · 285.0 KiB · each line repeated 512 times
    redact-secret21.2 ms13.0 MB/s · 12 runs17.0 to 43.1 msHid 6 of 8 values
    OpenRedaction1,144 ms0.2 MB/s · 12 runs872 to 1,778 msHid 4 of 8 values

redact-secret on its own

The throughput the Performance page records for the Node surface, whole and in 4 KiB pieces.
This is another run, on another machine, with another protocol than the pair above, so it is not set beside those times and is not drawn on the same axis. Read it on its own.
redact-secret on its own
Textredact-secret, usual time95th percentileSpeed
scale-logs-small-wholeOne-shot scan2.1 ms2.0 to 2.3 ms2.3 ms31.6 MB/s5 runs
scale-logs-medium-fixed4096Chunked incremental (4 KiB)13.8 ms13.8 to 13.9 ms13.9 ms19.0 MB/s5 runs

Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.

Not measured for this pair

Questions a pair page can answer once a run times both libraries on them. Each is a dashed “Not measured”, never a zero.
  1. How big is the text?

    The same kind of text at 64 KiB, 256 KiB and 10 MiB.

    Not measured

    The separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

  2. What does the text look like?

    One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.

    Not measured

    The pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.

    Recorded PII pair texts and run

    Workload expansion #571

    Neutral engine capability handoff #68

  3. Text built to slow scanners down

    Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.

    Not measured

    The registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  4. How many secrets does it hold?

    The same mixed text with none, one and eight secrets per KiB.

    Not measured

    No committed run varies the number of secrets in one text for both libraries. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  5. Does it arrive whole or in pieces?

    The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.

    Not measured

    The separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

How this was measured

  • Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
  • Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
  • Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
  • OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
  • redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII setting (pii:global). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
  • Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
  • One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
  • Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
  • The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.

Comparison · One pair at a time

How long does it take? It depends on the text.

redact-secret and OpenRedaction ran the same texts in the same run. The time changes with the text, so every text is shown, on one shared scale. Times are recorded, not graded. Not a ranking.

  • redact-secret · PII + US
  • OpenRedaction · defaults
  • Thin line: shortest to longest timed call

redact-secret0.1.0-beta.14npm

Setting: PII + US (adds pii:us)

Package @redact-secret/core. Timed call: scanAndRedact(), synchronous.

Turns on: email, iban, network address, payment card, phone, ssn.

OpenRedaction1.1.5npm

Setting: defaults

Package @openredaction/core. Timed call: detect(), asynchronous, returns a Promise.

No options passed: the library runs as installed.

Every text, one scale

Each mark is one text, at its usual time. The wider a row spreads, the more that library’s time depends on the text.

redact-secret6.8 to 21.9 ms across 6 texts
OpenRedaction235 to 1,384 ms across 6 texts

1 / 2

Text with personal data

Made-up emails, card numbers, bank accounts, phone numbers and IP addresses, in three kinds of text.

  1. Does it catch real sensitive values?Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.real-looking-values · 128.0 KiB · each line repeated 512 times
    redact-secret17.8 ms7.2 MB/s · 12 runs16.3 to 25.0 msHid 8 of 8 values
    OpenRedaction684 ms0.2 MB/s · 12 runs493 to 987 msHid 7 of 8 values
  2. Does it redact fake values?Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.validator-heavy · 92.5 KiB · each line repeated 512 times
    redact-secret7.8 ms12.1 MB/s · 12 runs6.8 to 10.1 msHid 2 of 8 values
    OpenRedaction455 ms0.2 MB/s · 12 runs380 to 648 msHid 4 of 8 values
  3. Does it understand context?The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.multilingual-context · 147.0 KiB · each line repeated 512 times
    redact-secret11.8 ms11.8 MB/s · 12 runs8.6 to 132 msHid 0 of 9 values
    OpenRedaction802 ms0.2 MB/s · 12 runs642 to 1,849 msHid 4 of 9 values

2 / 2

Text with credentials

Made-up API keys and tokens in the places people paste them. Every line carries a secret, so each call finds and replaces thousands of them: these times are for text that dense.

  1. Does it catch real secrets?Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.credentials-real · 287.5 KiB · each line repeated 512 times
    redact-secret21.9 ms13.2 MB/s · 12 runs19.8 to 25.8 msHid 8 of 8 values
    OpenRedaction1,384 ms0.2 MB/s · 12 runs1,258 to 2,239 msHid 8 of 8 values
  2. Does it redact fake secrets?Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.credentials-fake · 164.0 KiB · each line repeated 512 times
    redact-secret6.8 ms23.0 MB/s · 12 runs6.2 to 8.0 msHid 0 of 8 values
    OpenRedaction235 ms0.7 MB/s · 12 runs216 to 340 msHid 2 of 8 values
  3. Does it understand context?Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.credentials-context · 285.0 KiB · each line repeated 512 times
    redact-secret18.3 ms15.9 MB/s · 12 runs16.8 to 34.0 msHid 6 of 8 values
    OpenRedaction907 ms0.3 MB/s · 12 runs855 to 1,717 msHid 4 of 8 values

redact-secret on its own

The throughput the Performance page records for the Node surface, whole and in 4 KiB pieces.
This is another run, on another machine, with another protocol than the pair above, so it is not set beside those times and is not drawn on the same axis. Read it on its own.
redact-secret on its own
Textredact-secret, usual time95th percentileSpeed
scale-logs-small-wholeOne-shot scan2.1 ms2.0 to 2.3 ms2.3 ms31.6 MB/s5 runs
scale-logs-medium-fixed4096Chunked incremental (4 KiB)13.8 ms13.8 to 13.9 ms13.9 ms19.0 MB/s5 runs

Accepted run of product commit 0c62fd38bca7: 5 repetitions, AMD EPYC 7763 64-Core Processor, 4 CPUs, node-22.23.3, served by the N-API add-on.

Not measured for this pair

Questions a pair page can answer once a run times both libraries on them. Each is a dashed “Not measured”, never a zero.
  1. How big is the text?

    The same kind of text at 64 KiB, 256 KiB and 10 MiB.

    Not measured

    The separate own run records small whole-input and medium 4 KiB-piece profiles, changing size and dispatch together. It is not a controlled size sweep for this pair. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

  2. What does the text look like?

    One long line, hex ids, source code, CLI tables, invisible characters, personal data at the end of a long line.

    Not measured

    The pair above records six specific credential/PII texts. It does not cover this expanded shape matrix. Tracked in #571.

    Recorded PII + US pair texts and run

    Workload expansion #571

    Neutral engine capability handoff #68

  3. Text built to slow scanners down

    Patterns that once made a scanner re-read the same bytes many times, each one long line or one open assignment.

    Not measured

    The registered accepted own run has no adversarial profile. No committed pair run times these patterns. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  4. How many secrets does it hold?

    The same mixed text with none, one and eight secrets per KiB.

    Not measured

    No committed run varies the number of secrets in one text for both libraries. Tracked in #571.

    Workload expansion #571

    Neutral engine capability handoff #68

  5. Does it arrive whole or in pieces?

    The same text handed over at once, or streamed in 4 KiB or 64 KiB pieces.

    Not measured

    The separate own run records a medium 4 KiB-piece profile and a different small whole-input profile, not the same text across dispatch modes. No committed run times both libraries in pieces. Tracked in #571.

    Separate accepted own profiles and provenance

    Workload expansion #571

    Neutral engine capability handoff #68

How this was measured

  • Run of 2026-10-07: linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs.
  • Each time is the middle of 12 timed calls after 2 warm-up calls. The thin line runs from the shortest to the longest call. Calls took turns, one library after another, in one process.
  • Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).
  • OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.
  • redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII + US setting (pii:global, pii:us). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.
  • Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.
  • One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.
  • Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.
  • The texts are generated from the committed plan and are never published; only their kind and size are shown. Every value in them is made up.