The product
Privacy
How passwords, tokens, and other secrets in a request are kept out of a timeline.
Removed before it leaves your app
Redaction runs inside your process, before an event is queued. A value that matches a rule below never reaches Bugwalk, so it cannot leak from storage: we never received it. The rules cannot be turned off. You can add names on top of them. You cannot subtract.
Email addresses are kept. Naming a person by email is the point of identify(), and People search uses it.
Headers that are dropped
These headers are removed from the request and the response. They are not replaced with a mask, because a mask would still show that the header was there. Matching ignores case.
authorization, proxy-authorization, cookie, set-cookie, x-api-key, x-auth-token, x-csrf-token, x-xsrf-token, and x-bugwalk-key.
Field names that are dropped
Names are normalised first: lowercased, with spaces, hyphens, and underscores removed. user_password, userPassword, and USER-PASSWORD are the same field. The field is removed at every depth of a body, including inside arrays.
A long, unambiguous name is dropped when it appears anywhere in the field name: password, passwd, secret, credential, apikey, accesstoken, refreshtoken, idtoken, authtoken, bearertoken, sessiontoken, authorization, privatekey, clientsecret, creditcard, cardnumber, securitycode, aadhaar, and passport.
A short name is dropped only when the whole field is that name, so pan does not delete company and ssn does not delete classname: token, key, ssn, pan, cvv, cvc, pin, and otp.
On a URL, the parameter stays and the value becomes [redacted]. Removing the parameter would change the shape of the URL, and issues group on that shape.
Values that are replaced
Every remaining string is scanned. A match is replaced in place and the rest of the string stays, so a log line can still be read.
A PEM private key becomes [redacted:key]. A JWT (a string starting with eyJ and two more segments) becomes [redacted:jwt]. Known token prefixes, including sk_live_, sk_test_, ghp_, gho_, github_pat_, xoxb-, and AKIA, become [redacted:token]. A 13 to 19 digit number that passes the Luhn check becomes [redacted:card], which is what leaves order numbers and timestamps alone. An Indian PAN becomes [redacted:pan]. A grouped Aadhaar number becomes [redacted:aadhaar].
What is never read
No SDK reads form field values, other than the visible text of a clicked button or link. It does not read localStorage, sessionStorage, IndexedDB, keystrokes, or environment variables. Request bodies on GET and HEAD are not captured.
Request and response bodies are captured only when the app opts in with captureBodies: true, only for JSON, and only up to 8 KB. The same field rules still apply.
Fields you choose not to keep
Project, Privacy takes extra field names, one per line. Those names are dropped from request and response bodies, headers, query values, and person traits before the event is stored. The same list applies to OpenTelemetry attributes, matching the attribute key or its last segment.
account_number and accountNumber are one entry. The list does not turn off the rules above. A name you add is extra. Clearing the list goes back to the built-in rules only.
beforeSend still runs in your app, after the built-in rules and before the batch is sent. Return null from it to drop an event entirely.