Skip to content
Benchmarks

EVALUATION METHOD

Differential

The canonical input of each case is read by redact-secret and by each peer, and the ranges each one reports are compared. A difference is review evidence. A peer is not ground truth and a difference is not a failure of either tool.

  • Run 6183a594 · 2026-10-10
  • redact-secret 0.1.0-beta.14 · Published npm package · default detectors
  • Accounting v1.1

1 · How it runs

Where does another scanner report something different from redact-secret?

  1. InputThe canonical input of each case, unchanged.
  2. ChangeNone.
  3. Checkredact-secret and the peer report the same ranges, or they differ in one of the stated ways. A difference is queued for review.
Inputs
6,441
Peers
3
Suites
75

2 · Recorded now

Where the ranges differ

redact-secret against each peer, input by input. Peers are columns here, and redact-secret is the reference every row is read from.
Differences between redact-secret and each peer
What was comparedgitleaks8.30.1trufflehog3.97.4flare-redact1.6.1
What each tool reported
No difference foundThe same ranges, or none from either, and no family difference where families could be compared4,497 of 6,4413,743 of 6,4413,490 of 6,441
Ranges differBoth reported something, and not the same ranges89 of 6,44167 of 6,441385 of 6,441
Only redact-secret reportedredact-secret reported a range the peer did not1,107 of 6,4412,416 of 6,4412,344 of 6,441
Only the peer reportedThe peer reported a range redact-secret did not234 of 6,44175 of 6,44194 of 6,441
Same ranges, different familyThe ranges match and the families they map to differ514 of 6,441140 of 6,441128 of 6,441
Family classification
ComparableRanges match and every range maps to a familyNot listed: the same comparisons as the rows above, split by family. Open a count above.1,425 of 6,441460 of 6,441407 of 6,441
Not comparableNothing to compare, an unmapped range, or ranges that differNot listed: the same comparisons as the rows above, split by family. Open a count above.5,016 of 6,4415,981 of 6,4416,034 of 6,441

Inputs that fell in that row, of the inputs both tools completed.

A count opens the comparisons behind it, from this run only. A zero has none to open. Which tool is right is decided in the review ledger (benchmarks/review-ledger.json), never on these pages.

Differences are review evidence

7,593 comparisons recorded a difference and are queued for review. Which tool is right is not decided here.

3 · How to read it

Reading differential

  • Rows are exclusive: an input falls in one of the first five rows. The classification rows are a second view of the same inputs, not more of them.
  • Family classification can be not comparable even when the ranges compare, for instance when a family is not mapped.

4 · Exact inputs

Where the cases come from

6,441 inputs read by this method. Synthetic content only.

Suites

Every case comes from a published suite. Open a suite to read its fixtures.

Show the 75 suites
Suites the cases come from
SuiteInputs
Reviewed credential formatscommon-formats150
Detection accuracyaccuracy10
GitHub token contextstoken-contexts10
Credential formatscredential-formats42
Context & boundariescontext-edges173
Negative controlsnegative-controls24
SendGrid regressionssendgrid-regressions49
Reference syntaxreference-syntax26
Beta.3 regressionsmilestone-6-closed92
Detector coveragedetector-coverage1,416
Untargeted real-world shapesreal-world-shapes120
Beta.8 low-coverage hardening (#207)beta8-207348
Beta.8 documented-stable hardening (#209)beta8-20968
Beta.8 AI inference arrival evidence (#208)beta8-20896
Beta.8 · LangSmith and Langfuse arrival evidencebeta8-21048
Beta.8 developer credential arrival evidence (#211)beta8-211130
Beta.8 second-wave arrival evidence (#212)beta8-212171
Beta.8 legacy-stable profile restoration (#213, set a)beta8-213a33
Beta.8 stable restoration evidence (#213, 213c)beta8-213c98
Beta.8 documented-stable restoration, batch b (#213)beta8-213b59
Beta.8 empirical-route fixture debt (#213, 213d)beta8-213d149
Beta.8 context-twin debt for the legacy Datadog application key (#213, 213e)beta8-213e12
Beta.8 replacement fixtures for provider-undecided properties (#213, 213f)beta8-213f18
Beta.8 evidence for Travis CI, Neon, Postman collection access keys and the Mailgun key triplet (#259)beta8-259122
Beta.8 empirical fixture-floor raise for ten T2 families (#263)beta8-263104
Beta.10 evidence for the Anthropic api01/admin01 prefixes and the OpenAI admin key (#384, slice a)beta8-384a83
Beta.10 evidence for the Amazon Bedrock long-term and short-term API keys (#384, slice b)beta8-384b53
Beta.10 evidence for the ElevenLabs API key (#384, slice c)beta8-384c30
Beta.10 evidence for the Together AI and Tavily API keys (#384, slice d)beta8-384d74
Beta.10 evidence for keyword-gated Mistral, Cohere, Deepgram, AI21 and Exa keys (#384, slice e)beta8-384e249
Beta.11 independent family evidence for fifteen selected credential families (#379)beta8-379202
Beta.11 evidence for Convex deployment and admin keys with a hex body (#436, slice a)beta8-436a33
Beta.11 evidence for the 1Password service-account token (#436, slice b)beta8-436b31
Beta.11 evidence for the Inngest signing key (#436, slice c)beta8-436c32
Beta.11 evidence for the Resend API key (#436, slice d)beta8-436d34
Beta.11 evidence for the Apify API token (#436, slice e)beta8-436e30
Beta.11 evidence for the Weights & Biases wandb_v1_ API key (#436, slice f)beta8-436f27
Beta.11 evidence for Doppler tokens (#434, slice a)beta8-434a260
Beta.11 evidence for the Trigger.dev secret key and PAT (#434, slice b)beta8-434b70
Beta.11 evidence for the E2B API key (#434, slice c)beta8-434c35
Beta.11 evidence for the PostHog personal and project secret API keys (#434, slice d)beta8-434d72
Beta.11 evidence for the Helicone read-write and write-only keys (#434, slice e)beta8-434e73
Beta.11 evidence for the Firecrawl API key (#434, slice f)beta8-434f40
Beta.11 evidence for the Composio project, org and user API keys (#434, slice g)beta8-434g112
Beta.11 replacement near-miss controls for the redact-secret#948 relabel (948)beta8-9489
Beta.12 evidence for the Daytona API key (#464, slice a)beta8-464a38
Beta.12 evidence for the ClickHouse Cloud API key secret (#464, slice b)beta8-464b37
Beta.12 evidence for the NVIDIA API key (#464, slice c)beta8-464c31
Beta.12 evidence for the Browserbase API key (bb_live_) (#464, slice d)beta8-464d31
Beta.12 evidence for the Cerebras inference API key (#464, slice e)beta8-464e40
Beta.12 evidence for the RunPod API key (#464, slice f)beta8-464f30
Beta.12 evidence for the Bitwarden Secrets Manager access token (#528, slice a)beta8-528a38
Beta.12 evidence for Polar organization access tokens and API credentials (#528, slice b)beta8-528b59
Beta.12 evidence for SonarQube user and analysis tokens (#528, slice c)beta8-528c60
Beta.12 evidence for the RubyGems.org API key (#528, slice d)beta8-528d31
Beta.12 evidence for the Clojars deploy token (#528, slice e)beta8-528e29
Beta.12 evidence for crates.io API and trusted-publishing tokens (#528, slice f)beta8-528f58
Beta.12 evidence for Dynatrace access and platform tokens (#528, slice g)beta8-528g33
Beta.12 evidence for the Paddle Billing API key (#528, slice h)beta8-528h33
Beta.12 evidence for Honeycomb ingest keys (#528, slice i)beta8-528i31
Beta.12 evidence for Axiom API and personal tokens (#528, slice j)beta8-528j54
Beta.12 evidence for the AWS IAM user secret access key (#528, #1012 slice a)beta8-1012a51
Beta.12 evidence for the Google OAuth client secret (#528, #1012 slice b)beta8-1012b32
Beta.12 evidence for the routable GitLab personal access token (#528, #1012 slice c)beta8-1012c31
Beta.12 evidence for the AWS STS temporary access key id (#528, #1012 slice d)beta8-1012d29
Beta.12 evidence for Vercel personal, app access and app refresh tokens (#528, #1012 slice e)beta8-1012e120
Beta.14 evidence for the Square access token and OAuth application secret (#583, slice a)beta8-583a75
Beta.14 evidence for the Xata API key (#583, slice b)beta8-583b46
Beta.14 evidence for the Sourcegraph access token (#583, slice c)beta8-583c38
Beta.14 evidence for the Unkey root key (#583, slice d)beta8-583d55
Beta.14 evidence for the Buildkite token (#583, slice e)beta8-583e61
Beta.14 evidence for the Pydantic Logfire token (#583, slice f)beta8-583f50
Beta.14 evidence for the Mapbox secret access token (#583, slice g)beta8-583g40
Beta.14 evidence for the Fly.io access token (#583, slice h)beta8-583h44
Public policy qualification controls for bounded T3 credentials (#365)policy-qualified-credentials19