Skip to content
Benchmarks

EVALUATION METHOD

Benign

Controls that resemble secrets but are not: placeholders, references, near misses, public identifiers, encoded values and ordinary text. None is transformed. Each should produce no finding.

  • Run 6183a594 · 2026-10-10
  • redact-secret 0.1.0-beta.14 · Published npm package · default detectors
  • Accounting v1.1

1 · How it runs

Does the scanner leave harmless look-alikes alone?

  1. InputA control from a named taxonomy, read as authored.
  2. ChangeNone. The control is not transformed.
  3. CheckThe scanner reports nothing on it. A control is counted once per scanner, however many findings it gets.
Controls
2,277
Taxonomies
12
Suites
69

2 · Recorded now

Which controls were flagged?

Controls by taxonomy, per scanner. Findings are not counted, only whether a control was flagged.
Benign: checks that did not hold, per scanner
Taxonomyredact-secret0.1.0-beta.14gitleaks8.30.1trufflehog3.97.4flare-redact1.6.1
Controls by family axis
Encoded value1 of 14719 of 1471 of 1472 of 147
Near miss0 of 51514 of 5157 of 51515 of 515
Ordinary prose0 of 1760 of 1760 of 1762 of 176
Placeholder3 of 55112 of 55111 of 55123 of 551
Public identifier0 of 34917 of 34911 of 34915 of 349
Reference0 of 4190 of 4190 of 4192 of 419
Real-world shapes, untargeted
Agent output0 of 200 of 200 of 200 of 20
Config0 of 201 of 201 of 201 of 20
Docs0 of 200 of 200 of 201 of 20
Lockfile0 of 201 of 200 of 200 of 20
Logs0 of 201 of 200 of 200 of 20
Source1 of 201 of 200 of 201 of 20
Untargeted, by policy action
Flagged with redact or blockOnly a scanner that reports a policy action has a count hereNot listed: these controls are the untargeted taxonomy rows above, split by the action a finding carried. Open a count there.0 of 120No checkNo checkNo check
Flagged with warn onlyAccepted by the product policy on ordinary proseNot listed: these controls are the untargeted taxonomy rows above, split by the action a finding carried. Open a count there.1 of 120No checkNo checkNo check

Controls flagged, of the controls in that taxonomy.

A count opens the checks behind it: the ones that did not hold, from this run only. "Needs review" opens the checks that wait for a person. A zero has none to open, and a scanner that did not run has none to list.

3 · How to read it

Reading benign

  • The taxonomy rows split one set of controls, so read a number inside its row. They are not added up here.
  • Real-world-shaped controls are measured apart from every family: a flag there is discovery evidence about ordinary content, not about a family. A warn-only finding on ordinary prose is accepted by the product policy, so the last group separates the actions that gate from the ones that only warn.

4 · Exact inputs

Where the cases come from

2,277 controls read by this method. Synthetic content only.

Suites

Every case comes from a published suite. Open a suite to read its fixtures.

Show the 69 suites
Suites the cases come from
SuiteControls
Detection accuracyaccuracy5
GitHub token contextstoken-contexts2
Negative controlsnegative-controls24
SendGrid regressionssendgrid-regressions8
Reference syntaxreference-syntax20
Beta.3 regressionsmilestone-6-closed59
Detector coveragedetector-coverage624
Untargeted real-world shapesreal-world-shapes120
Beta.8 low-coverage hardening (#207)beta8-207125
Beta.8 documented-stable hardening (#209)beta8-20920
Beta.8 AI inference arrival evidence (#208)beta8-20836
Beta.8 · LangSmith and Langfuse arrival evidencebeta8-21022
Beta.8 developer credential arrival evidence (#211)beta8-21149
Beta.8 second-wave arrival evidence (#212)beta8-21278
Beta.8 legacy-stable profile restoration (#213, set a)beta8-213a12
Beta.8 stable restoration evidence (#213, 213c)beta8-213c24
Beta.8 documented-stable restoration, batch b (#213)beta8-213b20
Beta.8 empirical-route fixture debt (#213, 213d)beta8-213d61
Beta.8 evidence for Travis CI, Neon, Postman collection access keys and the Mailgun key triplet (#259)beta8-25953
Beta.10 evidence for the Anthropic api01/admin01 prefixes and the OpenAI admin key (#384, slice a)beta8-384a28
Beta.10 evidence for the Amazon Bedrock long-term and short-term API keys (#384, slice b)beta8-384b21
Beta.10 evidence for the ElevenLabs API key (#384, slice c)beta8-384c10
Beta.10 evidence for the Together AI and Tavily API keys (#384, slice d)beta8-384d28
Beta.10 evidence for keyword-gated Mistral, Cohere, Deepgram, AI21 and Exa keys (#384, slice e)beta8-384e102
Beta.11 independent family evidence for fifteen selected credential families (#379)beta8-37983
Beta.11 evidence for Convex deployment and admin keys with a hex body (#436, slice a)beta8-436a10
Beta.11 evidence for the 1Password service-account token (#436, slice b)beta8-436b9
Beta.11 evidence for the Inngest signing key (#436, slice c)beta8-436c10
Beta.11 evidence for the Resend API key (#436, slice d)beta8-436d9
Beta.11 evidence for the Apify API token (#436, slice e)beta8-436e10
Beta.11 evidence for the Weights & Biases wandb_v1_ API key (#436, slice f)beta8-436f8
Beta.11 evidence for Doppler tokens (#434, slice a)beta8-434a70
Beta.11 evidence for the Trigger.dev secret key and PAT (#434, slice b)beta8-434b21
Beta.11 evidence for the E2B API key (#434, slice c)beta8-434c10
Beta.11 evidence for the PostHog personal and project secret API keys (#434, slice d)beta8-434d22
Beta.11 evidence for the Helicone read-write and write-only keys (#434, slice e)beta8-434e20
Beta.11 evidence for the Firecrawl API key (#434, slice f)beta8-434f10
Beta.11 evidence for the Composio project, org and user API keys (#434, slice g)beta8-434g30
Beta.11 replacement near-miss controls for the redact-secret#948 relabel (948)beta8-9489
Beta.12 evidence for the Daytona API key (#464, slice a)beta8-464a10
Beta.12 evidence for the ClickHouse Cloud API key secret (#464, slice b)beta8-464b11
Beta.12 evidence for the NVIDIA API key (#464, slice c)beta8-464c11
Beta.12 evidence for the Browserbase API key (bb_live_) (#464, slice d)beta8-464d10
Beta.12 evidence for the Cerebras inference API key (#464, slice e)beta8-464e9
Beta.12 evidence for the RunPod API key (#464, slice f)beta8-464f8
Beta.12 evidence for the Bitwarden Secrets Manager access token (#528, slice a)beta8-528a11
Beta.12 evidence for Polar organization access tokens and API credentials (#528, slice b)beta8-528b17
Beta.12 evidence for SonarQube user and analysis tokens (#528, slice c)beta8-528c18
Beta.12 evidence for the RubyGems.org API key (#528, slice d)beta8-528d9
Beta.12 evidence for the Clojars deploy token (#528, slice e)beta8-528e9
Beta.12 evidence for crates.io API and trusted-publishing tokens (#528, slice f)beta8-528f17
Beta.12 evidence for Dynatrace access and platform tokens (#528, slice g)beta8-528g9
Beta.12 evidence for the Paddle Billing API key (#528, slice h)beta8-528h9
Beta.12 evidence for Honeycomb ingest keys (#528, slice i)beta8-528i9
Beta.12 evidence for Axiom API and personal tokens (#528, slice j)beta8-528j16
Beta.12 evidence for the AWS IAM user secret access key (#528, #1012 slice a)beta8-1012a19
Beta.12 evidence for the Google OAuth client secret (#528, #1012 slice b)beta8-1012b11
Beta.12 evidence for the routable GitLab personal access token (#528, #1012 slice c)beta8-1012c9
Beta.12 evidence for the AWS STS temporary access key id (#528, #1012 slice d)beta8-1012d11
Beta.12 evidence for Vercel personal, app access and app refresh tokens (#528, #1012 slice e)beta8-1012e42
Beta.14 evidence for the Square access token and OAuth application secret (#583, slice a)beta8-583a21
Beta.14 evidence for the Xata API key (#583, slice b)beta8-583b16
Beta.14 evidence for the Sourcegraph access token (#583, slice c)beta8-583c12
Beta.14 evidence for the Unkey root key (#583, slice d)beta8-583d13
Beta.14 evidence for the Buildkite token (#583, slice e)beta8-583e15
Beta.14 evidence for the Pydantic Logfire token (#583, slice f)beta8-583f14
Beta.14 evidence for the Mapbox secret access token (#583, slice g)beta8-583g10
Beta.14 evidence for the Fly.io access token (#583, slice h)beta8-583h13
Public policy qualification controls for bounded T3 credentials (#365)policy-qualified-credentials6