redact-secret · Evaluation · Qualification
square-token
Taxonomy families: square · Access token (EAAA). The status and its evidence, then what each scanner recorded per population.
Support status of the product
Provisional The product’s qualification, derived by the adapter. It is not a scanner observation.
- Route
- No route
- Evidence tier
- T1
- Evidence basis
- provider-documented
- Contract tier
- T1
- Fixture profile claimed
- stable-documented
- Fixture profile cells met
- None
Why the status is not stable
- documented.minimumPositiveCases: 0 < 6 — The documented profile requires six independently authored positive or supported-context fixtures.
- documented.minimumPositiveAxes: 0 < 4 — Positive coverage must span four source-context axes rather than repeat one serialization.
- documented.minimumBenignCases: 0 < 8 — Eight independent benign controls are required by the documented fixture profile.
- documented.minimumControlAxes: 0 < 4 — Benign coverage must span four reviewed confusion axes.
- documented.minimumTwinPairs: 0 < 5 — Five authored positive/negative twin pairs are required by the documented fixture profile.
- benign.minimumCases: 0 < 5 — Five benign controls is the minimum sample to claim the detector stays quiet on adjacent, non-secret shapes for this family.
- benign.minimumAxes: 0 < 3 (axes present: none) — A bare case count is satisfied by five copies of the same near-miss and proves nothing about diversity. Staged at 2 immediately after #91 merged (the minimum then met by every family reading stable: gitlab-token, npm-token), per docs/decisions/2026-09-21-measure-benign-axis-diversity.md's ratchet plan. Raised to 3 once #93 (#90's part A3) authored the missing placeholder/reference axes for the 23 families that previously carried only a same-axis near-miss pair, plus one reference control each for gitlab-token and npm-token so the ratchet lands with zero regressions; measured via `npm run eval:classify` immediately before this value changed.
Evidence the status was judged on
Floors and fixture-profile cells are read from public-evidence-snapshot alone; a gate reads each gate-bearing population on its own.
- Scored cases
- 0
- Positive cases
- 0
- Positive context axes
- 0
- Benign controls
- 0
- Benign control axes
- 0
- Twin pairs
- 0
- Metamorphic critical failures
- 0
- Mutation unresolved critical
- 0
- Differential unresolved disagreements
- 0
Zero-tolerance gates
The classifier receives the worst gate-bearing population, never a sum. Each population is shown on its own.
| Population | Twin pairs that did not discriminate | Benign controls flagged |
|---|---|---|
public-evidence-snapshot | No pair | No control |
regression-corpus | No pair | No control |
Scanner observations
What each scanner recorded for this family, per population. These are counts and carry no support status; a case that is pending or not measured is not a miss.
| Population | Scanner | Cases | Positive spans | Span outcomes | Leaked | Benign controls flagged | Twin pairs discriminated | Pending / not measured |
|---|---|---|---|---|---|---|---|---|
policy-corpuspolicy route | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
Cases
Each case of this family, per population, with what every scanner recorded for it and the case’s own facts.