Skip to content
Benchmarks

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real sensitive values?

Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.

Does it catch real sensitive values? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
IP addressHidden: shown as <SECRET_1>Left as isHidden: shown as [IPV4_7853]
EmailHidden: shown as <SECRET_1>Hidden: shown as ***@***Hidden: shown as [EMAIL_9874]
Card numberHidden: shown as <SECRET_1>Hidden: shown as **** **** **** Hidden: shown as [CREDIT_CARD_3168]
Bank accountHidden: shown as <SECRET_1>Hidden: shown as [REDACTED IBAN]Hidden: shown as [IBAN_5258]
US Social Security no.Switch offLeft as isLeft as is
US phone numberHidden: shown as <SECRET_1>Left as isHidden: shown as [PHONE_UK_4232]
Email, Korean labelHidden: shown as <SECRET_1>Hidden: shown as ***@***Hidden: shown as [EMAIL_9340]
Phone, Korean labelHidden: shown as <SECRET_1>Left as isHidden: shown as [PHONE_UK_4232]
Hidden88%7 of 850%4 of 888%7 of 8
Usual timems17.19.4673
SpeedMB per second7.313.60.2

real-looking-values · 128.0 KiB · each line repeated 512 times

2 / 3

Does it redact fake values?

Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.

Does it redact fake values? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
Example IP addressLeft as isLeft as isHidden: shown as [IPV4_3267]
example.com emailLeft as isHidden: shown as ***@***Left as is
Test card numberLeft as isHidden: shown as **** **** **** Hidden: shown as [CREDIT_CARD_3326]
Textbook bank accountHidden: shown as <SECRET_1>Hidden: shown as [REDACTED IBAN]Hidden: shown as [IBAN_0830]
Social Security no.Switch offLeft as isLeft as is
555 phone numberLeft as isLeft as isHidden: shown as [PHONE_UK_7432]
Card no., wrong check digitLeft as isLeft as isLeft as is
SSN starting 000Switch offLeft as isLeft as is
Hidden13%1 of 838%3 of 850%4 of 8
Usual timems6.43.5472
SpeedMB per second14.427.10.2

validator-heavy · 92.5 KiB · each line repeated 512 times

3 / 3

Does it understand context?

The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.

Does it understand context? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
Email, English labelLeft as isHidden: shown as ***@***Left as is
Email, Korean labelLeft as isHidden: shown as ***@***Left as is
Email, Korean label, decomposed formLeft as isHidden: shown as ***@***Left as is
Phone, English labelLeft as isLeft as isHidden: shown as [PHONE_UK_7432]
Phone, Korean labelLeft as isLeft as isHidden: shown as [PHONE_UK_7432]
Email and phone, one lineLeft as isPartly hidden: shown as ***@***Partly hidden: shown as [PHONE_UK_7432]
SSN after “example”Switch offLeft as isLeft as is
IP after “documentation”Left as isLeft as isHidden: shown as [IPV4_3267]
Hidden0%0 of 944%4 of 944%4 of 9
Usual timems8.66.7614
SpeedMB per second17.422.40.2

multilingual-context · 147.0 KiB · each line repeated 512 times

About the libraries

About the libraries
Factredact-secretflare-redactOpenRedaction
Version0.1.0-beta.14 npm1.6.1 npm1.1.5 npm
Package@redact-secret/coreflare-redact@openredaction/core
Call timedscanAndRedact()synchronousredact()synchronousdetect()asynchronous: returns a Promise
Runs inNode.js 20, 22, 24; browsers and Cloudflare Workers through WebAssemblyfrom package metadata and documentationNode.js 20 or later; browsers and edge runtimesfrom package metadata and documentationNode.js 20 or later; browser support not documentedfrom package metadata and documentation
Install size1,885.9 KiB packed5,128.3 KiB unpacked: core, WebAssembly and one platform add-on (linux x64 glibc)231.0 KiB packed926.8 KiB unpacked: one package756.4 KiB packed3,711.5 KiB unpacked: one package
Dependencies1 dependency (@redact-secret/wasm); 8 optional platform add-onsNoneNone required; 3 optional peers (mammoth, pdf-parse, tesseract.js)
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII setting (pii:global). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real sensitive values?

Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.

Does it catch real sensitive values? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
Usual timems17.19.4673
SpeedMB per second7.313.60.2

real-looking-values · 128.0 KiB · each line repeated 512 times

2 / 3

Does it redact fake values?

Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.

Does it redact fake values? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
Usual timems6.43.5472
SpeedMB per second14.427.10.2

validator-heavy · 92.5 KiB · each line repeated 512 times

3 / 3

Does it understand context?

The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.

Does it understand context? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
Usual timems8.66.7614
SpeedMB per second17.422.40.2

multilingual-context · 147.0 KiB · each line repeated 512 times

About the libraries

About the libraries
Factredact-secretflare-redactOpenRedaction
Version0.1.0-beta.14 npm1.6.1 npm1.1.5 npm
Package@redact-secret/coreflare-redact@openredaction/core
Call timedscanAndRedact()synchronousredact()synchronousdetect()asynchronous: returns a Promise
Runs inNode.js 20, 22, 24; browsers and Cloudflare Workers through WebAssemblyfrom package metadata and documentationNode.js 20 or later; browsers and edge runtimesfrom package metadata and documentationNode.js 20 or later; browser support not documentedfrom package metadata and documentation
Install size1,885.9 KiB packed5,128.3 KiB unpacked: core, WebAssembly and one platform add-on (linux x64 glibc)231.0 KiB packed926.8 KiB unpacked: one package756.4 KiB packed3,711.5 KiB unpacked: one package
Dependencies1 dependency (@redact-secret/wasm); 8 optional platform add-onsNoneNone required; 3 optional peers (mammoth, pdf-parse, tesseract.js)
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII setting (pii:global). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real sensitive values?

Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.

Does it catch real sensitive values? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
IP addressHidden: shown as <SECRET_1>Left as isHidden: shown as [IPV4_7853]
EmailHidden: shown as <SECRET_1>Hidden: shown as ***@***Hidden: shown as [EMAIL_9874]
Card numberHidden: shown as <SECRET_1>Hidden: shown as **** **** **** Hidden: shown as [CREDIT_CARD_3168]
Bank accountHidden: shown as <SECRET_1>Hidden: shown as [REDACTED IBAN]Hidden: shown as [IBAN_5258]
US Social Security no.Switch offLeft as isLeft as is
US phone numberHidden: shown as <SECRET_1>Left as isHidden: shown as [PHONE_UK_4232]
Email, Korean labelHidden: shown as <SECRET_1>Hidden: shown as ***@***Hidden: shown as [EMAIL_9340]
Phone, Korean labelHidden: shown as <SECRET_1>Left as isHidden: shown as [PHONE_UK_4232]
Hidden88%7 of 850%4 of 888%7 of 8

real-looking-values · 128.0 KiB · each line repeated 512 times

2 / 3

Does it redact fake values?

Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.

Does it redact fake values? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
Example IP addressLeft as isLeft as isHidden: shown as [IPV4_3267]
example.com emailLeft as isHidden: shown as ***@***Left as is
Test card numberLeft as isHidden: shown as **** **** **** Hidden: shown as [CREDIT_CARD_3326]
Textbook bank accountHidden: shown as <SECRET_1>Hidden: shown as [REDACTED IBAN]Hidden: shown as [IBAN_0830]
Social Security no.Switch offLeft as isLeft as is
555 phone numberLeft as isLeft as isHidden: shown as [PHONE_UK_7432]
Card no., wrong check digitLeft as isLeft as isLeft as is
SSN starting 000Switch offLeft as isLeft as is
Hidden13%1 of 838%3 of 850%4 of 8

validator-heavy · 92.5 KiB · each line repeated 512 times

3 / 3

Does it understand context?

The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.

Does it understand context? What each library hid, and how long it took. Not a ranking.
redact-secretpii:globalflare-redactOpenRedaction
Email, English labelLeft as isHidden: shown as ***@***Left as is
Email, Korean labelLeft as isHidden: shown as ***@***Left as is
Email, Korean label, decomposed formLeft as isHidden: shown as ***@***Left as is
Phone, English labelLeft as isLeft as isHidden: shown as [PHONE_UK_7432]
Phone, Korean labelLeft as isLeft as isHidden: shown as [PHONE_UK_7432]
Email and phone, one lineLeft as isPartly hidden: shown as ***@***Partly hidden: shown as [PHONE_UK_7432]
SSN after “example”Switch offLeft as isLeft as is
IP after “documentation”Left as isLeft as isHidden: shown as [IPV4_3267]
Hidden0%0 of 944%4 of 944%4 of 9

multilingual-context · 147.0 KiB · each line repeated 512 times

About the libraries

About the libraries
Factredact-secretflare-redactOpenRedaction
Version0.1.0-beta.14 npm1.6.1 npm1.1.5 npm
Package@redact-secret/coreflare-redact@openredaction/core
Call timedscanAndRedact()synchronousredact()synchronousdetect()asynchronous: returns a Promise
Runs inNode.js 20, 22, 24; browsers and Cloudflare Workers through WebAssemblyfrom package metadata and documentationNode.js 20 or later; browsers and edge runtimesfrom package metadata and documentationNode.js 20 or later; browser support not documentedfrom package metadata and documentation
Install size1,885.9 KiB packed5,128.3 KiB unpacked: core, WebAssembly and one platform add-on (linux x64 glibc)231.0 KiB packed926.8 KiB unpacked: one package756.4 KiB packed3,711.5 KiB unpacked: one package
Dependencies1 dependency (@redact-secret/wasm); 8 optional platform add-onsNoneNone required; 3 optional peers (mammoth, pdf-parse, tesseract.js)
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the PII setting (pii:global). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real sensitive values?

Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.

Does it catch real sensitive values? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
IP addressSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
EmailSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Card numberSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Bank accountSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
US Social Security no.Switch offSwitch offHidden: shown as <SECRET_1>
US phone numberSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Email, Korean labelSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Phone, Korean labelSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Hidden0%0 of 888%7 of 8100%8 of 8
Usual timems1.917.117.8
SpeedMB per second67.97.37.2

real-looking-values · 128.0 KiB · each line repeated 512 times

2 / 3

Does it redact fake values?

Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.

Does it redact fake values? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Example IP addressSwitch offLeft as isLeft as is
example.com emailSwitch offLeft as isLeft as is
Test card numberSwitch offLeft as isLeft as is
Textbook bank accountSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Social Security no.Switch offSwitch offHidden: shown as <SECRET_1>
555 phone numberSwitch offLeft as isLeft as is
Card no., wrong check digitSwitch offLeft as isLeft as is
SSN starting 000Switch offSwitch offLeft as is
Hidden0%0 of 813%1 of 825%2 of 8
Usual timems1.26.47.8
SpeedMB per second78.014.412.1

validator-heavy · 92.5 KiB · each line repeated 512 times

3 / 3

Does it understand context?

The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.

Does it understand context? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Email, English labelSwitch offLeft as isLeft as is
Email, Korean labelSwitch offLeft as isLeft as is
Email, Korean label, decomposed formSwitch offLeft as isLeft as is
Phone, English labelSwitch offLeft as isLeft as is
Phone, Korean labelSwitch offLeft as isLeft as is
Email and phone, one lineSwitch offLeft as isLeft as is
SSN after “example”Switch offSwitch offLeft as is
IP after “documentation”Switch offLeft as isLeft as is
Hidden0%0 of 90%0 of 90%0 of 9
Usual timems2.48.611.8
SpeedMB per second61.317.411.8

multilingual-context · 147.0 KiB · each line repeated 512 times

About the settings

About the settings
FactDefaultPIIPII + US
Selectorsnonepii:globalpii:global, pii:us
Turns onno PII familyemail, iban, network address, payment card, phoneemail, iban, network address, payment card, phone, ssn
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real sensitive values?

Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.

Does it catch real sensitive values? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Usual timems1.917.117.8
SpeedMB per second67.97.37.2

real-looking-values · 128.0 KiB · each line repeated 512 times

2 / 3

Does it redact fake values?

Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.

Does it redact fake values? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Usual timems1.26.47.8
SpeedMB per second78.014.412.1

validator-heavy · 92.5 KiB · each line repeated 512 times

3 / 3

Does it understand context?

The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.

Does it understand context? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Usual timems2.48.611.8
SpeedMB per second61.317.411.8

multilingual-context · 147.0 KiB · each line repeated 512 times

About the settings

About the settings
FactDefaultPIIPII + US
Selectorsnonepii:globalpii:global, pii:us
Turns onno PII familyemail, iban, network address, payment card, phoneemail, iban, network address, payment card, phone, ssn
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real sensitive values?

Made-up emails, card numbers, bank accounts and phone numbers that look like the real thing.

Does it catch real sensitive values? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
IP addressSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
EmailSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Card numberSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Bank accountSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
US Social Security no.Switch offSwitch offHidden: shown as <SECRET_1>
US phone numberSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Email, Korean labelSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Phone, Korean labelSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Hidden0%0 of 888%7 of 8100%8 of 8

real-looking-values · 128.0 KiB · each line repeated 512 times

2 / 3

Does it redact fake values?

Values made for examples and testing, like example.com emails and test card numbers, plus look-alikes that fail a basic check.

Does it redact fake values? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Example IP addressSwitch offLeft as isLeft as is
example.com emailSwitch offLeft as isLeft as is
Test card numberSwitch offLeft as isLeft as is
Textbook bank accountSwitch offHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Social Security no.Switch offSwitch offHidden: shown as <SECRET_1>
555 phone numberSwitch offLeft as isLeft as is
Card no., wrong check digitSwitch offLeft as isLeft as is
SSN starting 000Switch offSwitch offLeft as is
Hidden0%0 of 813%1 of 825%2 of 8

validator-heavy · 92.5 KiB · each line repeated 512 times

3 / 3

Does it understand context?

The same kind of fake values, now next to English and Korean labels, and next to words like “example” that say it is not real.

Does it understand context? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Email, English labelSwitch offLeft as isLeft as is
Email, Korean labelSwitch offLeft as isLeft as is
Email, Korean label, decomposed formSwitch offLeft as isLeft as is
Phone, English labelSwitch offLeft as isLeft as is
Phone, Korean labelSwitch offLeft as isLeft as is
Email and phone, one lineSwitch offLeft as isLeft as is
SSN after “example”Switch offSwitch offLeft as is
IP after “documentation”Switch offLeft as isLeft as is
Hidden0%0 of 90%0 of 90%0 of 9

multilingual-context · 147.0 KiB · each line repeated 512 times

About the settings

About the settings
FactDefaultPIIPII + US
Selectorsnonepii:globalpii:global, pii:us
Turns onno PII familyemail, iban, network address, payment card, phoneemail, iban, network address, payment card, phone, ssn
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real secrets?

Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.

Does it catch real secrets? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
.env, AWS access keyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
.env, GitHub tokenHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Command line, Slack tokenHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
HTTP header, bearer JWTHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
HTTP header, API keyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
.env, Stripe secret keyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Connection stringHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Command line, npm tokenHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Hidden100%8 of 8100%8 of 8100%8 of 8
Usual timems20.022.521.9
SpeedMB per second13.713.113.2

credentials-real · 287.5 KiB · each line repeated 512 times

2 / 3

Does it redact fake secrets?

Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.

Does it redact fake secrets? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
PlaceholderLeft as isLeft as isLeft as is
Angle-bracket placeholderLeft as isLeft as isLeft as is
AWS documentation keyLeft as isLeft as isLeft as is
Public by design, Stripe publishable keyLeft as isLeft as isLeft as is
Too short GitHub tokenLeft as isLeft as isLeft as is
Wrong letters, AWS-style keyLeft as isLeft as isLeft as is
Repeated characterLeft as isLeft as isLeft as is
Hash, not a secretLeft as isLeft as isLeft as is
Hidden0%0 of 80%0 of 80%0 of 8
Usual timems6.27.06.8
SpeedMB per second26.823.923.0

credentials-fake · 164.0 KiB · each line repeated 512 times

3 / 3

Does it understand context?

Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.

Does it understand context? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
SentenceHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Log lineHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
CodeHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
JSON bodyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Example in a commentHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Test fixture commentHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Commit hashLeft as isLeft as isLeft as is
Request idLeft as isLeft as isLeft as is
Hidden75%6 of 875%6 of 875%6 of 8
Usual timems18.921.218.3
SpeedMB per second15.013.015.9

credentials-context · 285.0 KiB · each line repeated 512 times

About the settings

About the settings
FactDefaultPIIPII + US
Selectorsnonepii:globalpii:global, pii:us
Turns onno PII familyemail, iban, network address, payment card, phoneemail, iban, network address, payment card, phone, ssn
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Every line of these credential texts carries a secret, so each call finds and replaces thousands of them. The times are for text that dense, so they are not comparable with the speeds on the Performance page, which times a different text.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real secrets?

Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.

Does it catch real secrets? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Usual timems20.022.521.9
SpeedMB per second13.713.113.2

credentials-real · 287.5 KiB · each line repeated 512 times

2 / 3

Does it redact fake secrets?

Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.

Does it redact fake secrets? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Usual timems6.27.06.8
SpeedMB per second26.823.923.0

credentials-fake · 164.0 KiB · each line repeated 512 times

3 / 3

Does it understand context?

Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.

Does it understand context? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
Usual timems18.921.218.3
SpeedMB per second15.013.015.9

credentials-context · 285.0 KiB · each line repeated 512 times

About the settings

About the settings
FactDefaultPIIPII + US
Selectorsnonepii:globalpii:global, pii:us
Turns onno PII familyemail, iban, network address, payment card, phoneemail, iban, network address, payment card, phone, ssn
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Every line of these credential texts carries a secret, so each call finds and replaces thousands of them. The times are for text that dense, so they are not comparable with the speeds on the Performance page, which times a different text.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real secrets?

Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.

Does it catch real secrets? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
.env, AWS access keyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
.env, GitHub tokenHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Command line, Slack tokenHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
HTTP header, bearer JWTHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
HTTP header, API keyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
.env, Stripe secret keyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Connection stringHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Command line, npm tokenHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Hidden100%8 of 8100%8 of 8100%8 of 8

credentials-real · 287.5 KiB · each line repeated 512 times

2 / 3

Does it redact fake secrets?

Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.

Does it redact fake secrets? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
PlaceholderLeft as isLeft as isLeft as is
Angle-bracket placeholderLeft as isLeft as isLeft as is
AWS documentation keyLeft as isLeft as isLeft as is
Public by design, Stripe publishable keyLeft as isLeft as isLeft as is
Too short GitHub tokenLeft as isLeft as isLeft as is
Wrong letters, AWS-style keyLeft as isLeft as isLeft as is
Repeated characterLeft as isLeft as isLeft as is
Hash, not a secretLeft as isLeft as isLeft as is
Hidden0%0 of 80%0 of 80%0 of 8

credentials-fake · 164.0 KiB · each line repeated 512 times

3 / 3

Does it understand context?

Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.

Does it understand context? What each redact-secret setting hid, and how long it took. Not a ranking.
Defaultno PIIPIIpii:globalPII + USadds pii:us
SentenceHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Log lineHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
CodeHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
JSON bodyHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Example in a commentHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Test fixture commentHidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>Hidden: shown as <SECRET_1>
Commit hashLeft as isLeft as isLeft as is
Request idLeft as isLeft as isLeft as is
Hidden75%6 of 875%6 of 875%6 of 8

credentials-context · 285.0 KiB · each line repeated 512 times

About the settings

About the settings
FactDefaultPIIPII + US
Selectorsnonepii:globalpii:global, pii:us
Turns onno PII familyemail, iban, network address, payment card, phoneemail, iban, network address, payment card, phone, ssn
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Every line of these credential texts carries a secret, so each call finds and replaces thousands of them. The times are for text that dense, so they are not comparable with the speeds on the Performance page, which times a different text.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real secrets?

Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.

Does it catch real secrets? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
.env, AWS access keyHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [AWS_KEY_5692]
.env, GitHub tokenHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [GITHUB_TOKEN_0852]
Command line, Slack tokenHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [SLACK_TOKEN_4831]
HTTP header, bearer JWTHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [AUTH_6553] [JWT_1006]
HTTP header, API keyHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [API_KEY_5282]
.env, Stripe secret keyHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [STRIPE_KEY_4672]
Connection stringHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [DB_CONN_4622]
Command line, npm tokenHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [NPM_TOKEN_8044]
Hidden100%8 of 8100%8 of 8100%8 of 8
Usual timems20.09.61,407
SpeedMB per second13.729.70.2

credentials-real · 287.5 KiB · each line repeated 512 times

2 / 3

Does it redact fake secrets?

Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.

Does it redact fake secrets? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
PlaceholderLeft as isHidden: shown as ***Left as is
Angle-bracket placeholderLeft as isHidden: shown as ***Left as is
AWS documentation keyLeft as isHidden: shown as ***Hidden: shown as [AWS_KEY_4884]
Public by design, Stripe publishable keyLeft as isLeft as isHidden: shown as [STRIPE_KEY_3790]
Too short GitHub tokenLeft as isHidden: shown as ***Left as is
Wrong letters, AWS-style keyLeft as isLeft as isLeft as is
Repeated characterLeft as isHidden: shown as ***Left as is
Hash, not a secretLeft as isLeft as isLeft as is
Hidden0%0 of 863%5 of 825%2 of 8
Usual timems6.24.1234
SpeedMB per second26.839.80.7

credentials-fake · 164.0 KiB · each line repeated 512 times

3 / 3

Does it understand context?

Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.

Does it understand context? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
SentenceHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [GITHUB_TOKEN_7924]
Log lineHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [NAME_9305]=[GITHUB_TOKEN_4441]
CodeHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [AWS_KEY_2662]
JSON bodyHidden: shown as <SECRET_1>Hidden: shown as ***Left as is
Example in a commentHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [GITHUB_TOKEN_9363]
Test fixture commentHidden: shown as <SECRET_1>Hidden: shown as ***Partly hidden: shown as [LAB_5432]
Commit hashLeft as isLeft as isLeft as is
Request idLeft as isLeft as isLeft as is
Hidden75%6 of 875%6 of 850%4 of 8
Usual timems18.97.61,009
SpeedMB per second15.036.60.3

credentials-context · 285.0 KiB · each line repeated 512 times

About the libraries

About the libraries
Factredact-secretflare-redactOpenRedaction
Version0.1.0-beta.14 npm1.6.1 npm1.1.5 npm
Package@redact-secret/coreflare-redact@openredaction/core
Call timedscanAndRedact()synchronousredact()synchronousdetect()asynchronous: returns a Promise
Runs inNode.js 20, 22, 24; browsers and Cloudflare Workers through WebAssemblyfrom package metadata and documentationNode.js 20 or later; browsers and edge runtimesfrom package metadata and documentationNode.js 20 or later; browser support not documentedfrom package metadata and documentation
Install size1,885.9 KiB packed5,128.3 KiB unpacked: core, WebAssembly and one platform add-on (linux x64 glibc)231.0 KiB packed926.8 KiB unpacked: one package756.4 KiB packed3,711.5 KiB unpacked: one package
Dependencies1 dependency (@redact-secret/wasm); 8 optional platform add-onsNoneNone required; 3 optional peers (mammoth, pdf-parse, tesseract.js)
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Every line of these credential texts carries a secret, so each call finds and replaces thousands of them. The times are for text that dense, so they are not comparable with the speeds on the Performance page, which times a different text.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real secrets?

Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.

Does it catch real secrets? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
Usual timems20.09.61,407
SpeedMB per second13.729.70.2

credentials-real · 287.5 KiB · each line repeated 512 times

2 / 3

Does it redact fake secrets?

Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.

Does it redact fake secrets? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
Usual timems6.24.1234
SpeedMB per second26.839.80.7

credentials-fake · 164.0 KiB · each line repeated 512 times

3 / 3

Does it understand context?

Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.

Does it understand context? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
Usual timems18.97.61,009
SpeedMB per second15.036.60.3

credentials-context · 285.0 KiB · each line repeated 512 times

About the libraries

About the libraries
Factredact-secretflare-redactOpenRedaction
Version0.1.0-beta.14 npm1.6.1 npm1.1.5 npm
Package@redact-secret/coreflare-redact@openredaction/core
Call timedscanAndRedact()synchronousredact()synchronousdetect()asynchronous: returns a Promise
Runs inNode.js 20, 22, 24; browsers and Cloudflare Workers through WebAssemblyfrom package metadata and documentationNode.js 20 or later; browsers and edge runtimesfrom package metadata and documentationNode.js 20 or later; browser support not documentedfrom package metadata and documentation
Install size1,885.9 KiB packed5,128.3 KiB unpacked: core, WebAssembly and one platform add-on (linux x64 glibc)231.0 KiB packed926.8 KiB unpacked: one package756.4 KiB packed3,711.5 KiB unpacked: one package
Dependencies1 dependency (@redact-secret/wasm); 8 optional platform add-onsNoneNone required; 3 optional peers (mammoth, pdf-parse, tesseract.js)
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Every line of these credential texts carries a secret, so each call finds and replaces thousands of them. The times are for text that dense, so they are not comparable with the speeds on the Performance page, which times a different text.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.

Comparison

Runtime comparison

What each library did to each value in the same made-up text, and how long one redact call took. Outcomes and times are recorded, not graded. Nothing here is ranked.

Compare two across many texts →

  • Hidden
  • Partly
  • Left as is
  • Switch off

1 / 3

Does it catch real secrets?

Made-up API keys and tokens in the places people paste them: a .env file, a command line, an HTTP header.

Does it catch real secrets? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
.env, AWS access keyHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [AWS_KEY_5692]
.env, GitHub tokenHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [GITHUB_TOKEN_0852]
Command line, Slack tokenHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [SLACK_TOKEN_4831]
HTTP header, bearer JWTHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [AUTH_6553] [JWT_1006]
HTTP header, API keyHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [API_KEY_5282]
.env, Stripe secret keyHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [STRIPE_KEY_4672]
Connection stringHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [DB_CONN_4622]
Command line, npm tokenHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [NPM_TOKEN_8044]
Hidden100%8 of 8100%8 of 8100%8 of 8

credentials-real · 287.5 KiB · each line repeated 512 times

2 / 3

Does it redact fake secrets?

Placeholders like YOUR_TOKEN_HERE, keys that are public by design, and look-alikes that are too short or use the wrong letters.

Does it redact fake secrets? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
PlaceholderLeft as isHidden: shown as ***Left as is
Angle-bracket placeholderLeft as isHidden: shown as ***Left as is
AWS documentation keyLeft as isHidden: shown as ***Hidden: shown as [AWS_KEY_4884]
Public by design, Stripe publishable keyLeft as isLeft as isHidden: shown as [STRIPE_KEY_3790]
Too short GitHub tokenLeft as isHidden: shown as ***Left as is
Wrong letters, AWS-style keyLeft as isLeft as isLeft as is
Repeated characterLeft as isHidden: shown as ***Left as is
Hash, not a secretLeft as isLeft as isLeft as is
Hidden0%0 of 863%5 of 825%2 of 8

credentials-fake · 164.0 KiB · each line repeated 512 times

3 / 3

Does it understand context?

Real secrets inside sentences, logs and code, next to look-alikes whose surroundings say they are not secrets.

Does it understand context? What each library hid, and how long it took. Not a ranking.
redact-secretno PIIflare-redactOpenRedaction
SentenceHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [GITHUB_TOKEN_7924]
Log lineHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [NAME_9305]=[GITHUB_TOKEN_4441]
CodeHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [AWS_KEY_2662]
JSON bodyHidden: shown as <SECRET_1>Hidden: shown as ***Left as is
Example in a commentHidden: shown as <SECRET_1>Hidden: shown as ***Hidden: shown as [GITHUB_TOKEN_9363]
Test fixture commentHidden: shown as <SECRET_1>Hidden: shown as ***Partly hidden: shown as [LAB_5432]
Commit hashLeft as isLeft as isLeft as is
Request idLeft as isLeft as isLeft as is
Hidden75%6 of 875%6 of 850%4 of 8

credentials-context · 285.0 KiB · each line repeated 512 times

About the libraries

About the libraries
Factredact-secretflare-redactOpenRedaction
Version0.1.0-beta.14 npm1.6.1 npm1.1.5 npm
Package@redact-secret/coreflare-redact@openredaction/core
Call timedscanAndRedact()synchronousredact()synchronousdetect()asynchronous: returns a Promise
Runs inNode.js 20, 22, 24; browsers and Cloudflare Workers through WebAssemblyfrom package metadata and documentationNode.js 20 or later; browsers and edge runtimesfrom package metadata and documentationNode.js 20 or later; browser support not documentedfrom package metadata and documentation
Install size1,885.9 KiB packed5,128.3 KiB unpacked: core, WebAssembly and one platform add-on (linux x64 glibc)231.0 KiB packed926.8 KiB unpacked: one package756.4 KiB packed3,711.5 KiB unpacked: one package
Dependencies1 dependency (@redact-secret/wasm); 8 optional platform add-onsNoneNone required; 3 optional peers (mammoth, pdf-parse, tesseract.js)
  • Run 2026-10-07
  • linux arm64 · Node v22.22.2 · Apple M4 (Docker Desktop linux/arm64 VM) · 4 CPUs
  • Each time is the middle of 12 runs

Informational only: no pass/fail verdict, no ranking assertion (this repository measures and records; see AGENTS.md Boundary rule).

OpenRedaction's detect() is Promise-returning (asynchronous); flare-redact's redact() and redact-secret's scanAndRedact() are synchronous. Each is timed with performance.now() around the actual call, awaited where applicable, so the OpenRedaction figures include at least one Node event-loop microtask tick that the other two tools' figures do not.

redact-secret is measured from the published @redact-secret/core npm package 0.1.0-beta.14 (the pinned release, built from product commit 0c62fd38bca75c5b28b042dc79789b708ebf1d17), not a local build; PII is selected through initialize({ pii }). This run used the Default setting (no PII selectors). flare-redact and OpenRedaction are measured from their published npm packages at their package defaults, so their columns do not change with the setting; they are timed in every setting's run as a reference for how much the machine varied between runs.

Workloads are the ones in qualification/runtime-comparison-v2.json: validator-heavy and multilingual-context are the v1 workloads rendered byte-identically, the others are new and synthetic. Credential values are generated from a seed at run time and never stored; a value that reaches a recorded outcome is replaced by its index.

One setting is measured per process because redact-secret accepts one PII selection per process. The tools run in-process, interleaved round-robin per workload, after two discarded warmup calls each, and each time is the median of the recorded samples.

Outcomes come from one untimed call per distinct line, outside the timed calls. A value counts as hidden when it no longer appears verbatim in the returned text. Outcomes are recorded, never graded.

Every line of these credential texts carries a secret, so each call finds and replaces thousands of them. The times are for text that dense, so they are not comparable with the speeds on the Performance page, which times a different text.

Between the 3 runs the same flare-redact and OpenRedaction calls on the same text moved by up to 108% (most on multilingual-context, OpenRedaction). Read a difference in time smaller than that as noise, not as a result.