redact-secret · Evaluation · Qualification
unkey-root-key
Taxonomy families: unkey · Root key (unkey_). The status and its evidence, then what each scanner recorded per population.
Support status of the product
Provisional The product’s qualification, derived by the adapter. It is not a scanner observation.
- Route
- No route
- Evidence tier
- T1
- Evidence basis
- provider-documented
- Contract tier
- T1
- Fixture profile claimed
- stable-documented
- Fixture profile cells met
- None
Why the status is not stable
- documented.minimumPositiveCases: 0 < 6 — The documented profile requires six independently authored positive or supported-context fixtures.
- documented.minimumPositiveAxes: 0 < 4 — Positive coverage must span four source-context axes rather than repeat one serialization.
- documented.minimumBenignCases: 0 < 8 — Eight independent benign controls are required by the documented fixture profile.
- documented.minimumControlAxes: 0 < 4 — Benign coverage must span four reviewed confusion axes.
- documented.minimumTwinPairs: 0 < 5 — Five authored positive/negative twin pairs are required by the documented fixture profile.
- benign.minimumCases: 0 < 5 — Five benign controls is the minimum sample to claim the detector stays quiet on adjacent, non-secret shapes for this family.
- benign.minimumAxes: 0 < 3 (axes present: none) — A bare case count is satisfied by five copies of the same near-miss and proves nothing about diversity. Staged at 2 immediately after #91 merged (the minimum then met by every family reading stable: gitlab-token, npm-token), per docs/decisions/2026-09-21-measure-benign-axis-diversity.md's ratchet plan. Raised to 3 once #93 (#90's part A3) authored the missing placeholder/reference axes for the 23 families that previously carried only a same-axis near-miss pair, plus one reference control each for gitlab-token and npm-token so the ratchet lands with zero regressions; measured via `npm run eval:classify` immediately before this value changed.
Evidence the status was judged on
Floors and fixture-profile cells are read from public-evidence-snapshot alone; a gate reads each gate-bearing population on its own.
- Scored cases
- 0
- Positive cases
- 0
- Positive context axes
- 0
- Benign controls
- 0
- Benign control axes
- 0
- Twin pairs
- 0
- Metamorphic critical failures
- 0
- Mutation unresolved critical
- 0
- Differential unresolved disagreements
- 0
Zero-tolerance gates
The classifier receives the worst gate-bearing population, never a sum. Each population is shown on its own.
| Population | Twin pairs that did not discriminate | Benign controls flagged |
|---|---|---|
public-evidence-snapshot | No pair | No control |
regression-corpus | No pair | No control |
Scanner observations
What each scanner recorded for this family, per population. These are counts and carry no support status; a case that is pending or not measured is not a miss.
| Population | Scanner | Cases | Positive spans | Span outcomes | Leaked | Benign controls flagged | Twin pairs discriminated | Pending / not measured |
|---|---|---|---|---|---|---|---|---|
policy-corpuspolicy route | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
Cases
Each case of this family, per population, with what every scanner recorded for it and the case’s own facts.