Files
git.stella-ops.org/docs/modules/notify/security/redaction-catalog.md
2025-12-25 10:54:10 +02:00

459 B

Redaction and PII catalog (NR7)

  • Classify merge fields: identifiers (hash), secrets (strip), PII (mask), operational metadata (retain).
  • Storage and previews must use redacted forms by default; full bodies allowed only with Notify.Audit permission.
  • Log payloads must omit secrets; hashes use BLAKE3-256 over UTF-8 normalized values.
  • Fixtures under docs/modules/notify/fixtures/redaction/ show expected redacted shapes for templates and receipts.