Schema validation
Checks whether the authored case follows the PII contract before its observations are evaluated.
Evaluation
Choose a domain to understand how its test inputs are authored, varied and evaluated. A method listed here is not a claim that it ran or that a product passed.
Methods for secrets, harmless lookalikes and changes to credential-bearing text. Open a card for its procedure and recorded evidence.
Does the scanner tell a secret from its harmless twin?
View method →Does the scanner leave harmless look-alikes alone?
View method →Does a scanner find the same thing when only the surrounding text changes?
View method →Does a scanner still find a value that was altered but is still valid?
View method →Where does another scanner report something different from redact-secret?
View method →Did the frozen candidate run its holdout cases?
View method →Methods for personal-data type, location, sensitivity and context. Coverage and measurement are recorded separately for each population.
Checks whether the authored case follows the PII contract before its observations are evaluated.
Uses a reference validator to check the authored personal-data type and compares the scanner’s observation with that expectation.
Checks whether the same kind of personal data is treated according to its authored sensitivity and surrounding context.
Checks authored harmless values that resemble personal data, keeping type and sensitivity expectations separate.
Checks values that can match competing identifier formats, against the authored family and jurisdiction expectations.
Applies recorded changes to an authored input and evaluates each generated variant against its expected result.
Compares scanner observations with authored reference evidence and validator observations.