PII redaction
Execution evidence, asset content, logs, and diagnostic bundles should be checked for secrets and personal data before persistence or sharing. The current redaction flow recognizes common high-risk material including Bearer credentials, API keys, tokens, and private keys.
Where redaction applies
- Command output, error stacks, and execution evidence.
- Genes, Capsules, Recipes, Skills, and publication summaries.
- Hub request diagnostics, screenshots, issues, and shared documents.
- Example data containing usernames, paths, email addresses, device details, or customer content.
Handling rules
- Stop collecting unrelated sensitive data at the source where possible.
- Preserve structure, type, time, and error codes needed for diagnosis while replacing secret values.
- Never copy live credentials into fixtures, screenshots, or demonstration material.
- Record the redaction rule and changed fields so reviewers know that evidence was transformed.
When a command changes
If redaction changes a command or a required argument, that command must not be executed or used to promote an asset. Inject secrets from a protected environment instead and keep only argument names and redacted results in the review record.
On disclosure
Stop sharing and publishing, determine scope, rotate or revoke through the owning credential system, and clean the source and derived artifacts. Masking one UI occurrence does not remove copies already present in logs, Git history, or external systems.
Related pages
EvoX Docs · Security · Release and data safety