Skip to content

Policies

Redactum includes 197 built-in patterns across 28 categories for comprehensive detection of personal, financial, and technical sensitive data.

From API keys and database credentials to personal information and financial data, each policy is designed to catch real-world patterns while minimizing false positives. Use them individually or combine categories to match your security requirements.

Developer Identifiers

PolicyExample Match
GOOGLE_CLOUD_PROJECT_IDgcp-project-id: my-project-123456
KAFKA_BOOTSTRAP_SERVERkafka-broker1.example.com:9092
CONTAINER_REGISTRYus.gcr.io/my-project/my-image:latest
GIT_SSH_URLgit@github.com:user/repo.git
API_ENDPOINT_URLhttps://api.example.com/v1/users
KUBERNETES_SECRETkubernetes-secret: my-secret.default
BUILD_NUMBERBUILD-2024.1.123
VERSION_TAGv1.2.3
COMMIT_HASHcommit: a1b2c3d4e5f6789012345678901234567890abcd
PR_ISSUE_NUMBERPR #1234
JIRA_TICKETPROJ-1234
FIREBASE_CONFIGmy-app-default-rtdb.us-central1.firebaseio.com
SUPABASE_URLhttps://abcdefghijklmnopqrst.supabase.co
AUTH0_DOMAINmyapp.auth0.com
NETLIFY_SITE_ID12345678-1234-1234-1234-123456789012
VERCEL_DEPLOYMENT_URLhttps://my-app-git-main-myteam.vercel.app

Developer Secrets

PolicyExample Match
BASE64_URL_PARAMhttps://example.com?token=aGVsbG93b3JsZHNlY3JldGtleXZhbHVl
DOCKER_PASSWORD_FLAGdocker login -u user -p mysecretpass123
ENVIRONMENT_VARIABLE_SECRETexport API_KEY=sk-1234567890abcdef
SERVICE_ACCOUNT_EMAILservice-account@my-project.iam.gserviceaccount.com
SONARQUBE_TOKENsqp_1234567890abcdef1234567890abcdef12345678
LAUNCHDARKLY_SDK_KEYsdk-12345678-1234-1234-1234-123456789012
SEGMENT_WRITE_KEYsegment-writekey: 1234567890abcdefghijklmnop123456
MIXPANEL_API_SECRETmixpanel-secret: 1234567890abcdef1234567890abcdef
ALGOLIA_API_KEYalgolia-api-key: 1234567890abcdef1234567890abcdef
ELASTIC_CLOUD_IDelastic-cloud-id: dXMtZWFzdC0xLmF3cy5mb3VuZC5pbyRjZWM2ZjI2MWE3NGJmMjRjZTMzYmI4ODExYjg0Mjk0ZiRjNmMyY2E2ZDA0MjI0OWFmMGNjN2Q3YTllOTYyNTc0Mw==

Database Credentials

PolicyExample Match
DATABASE_URLpostgres://user:pass@host:5432/dbname
MONGODB_CONNECTION_STRINGmongodb://user:pass@host:27017/database
REDIS_CONNECTION_STRINGredis://user:password@localhost:6379/0
ELASTICSEARCH_URLhttps://elastic:password@localhost:9200
RABBITMQ_CONNECTION_STRINGamqp://user:password@localhost:5672/
POSTGRESQL_CONNECTION_STRINGpostgresql://user:password@localhost:5432/dbname
MYSQL_CONNECTION_STRINGmysql://user:password@localhost:3306/database
CASSANDRA_CONNECTION_STRINGcassandra://user:pass@host:9042/keyspace
JDBC_CONNECTION_STRINGjdbc:mysql://dbuser:dbpass@localhost:3306/mydb
SMTP_CONNECTION_STRINGsmtp://user:password@smtp.gmail.com:587

Cloud Credentials

PolicyExample Match
AZURE_SUBSCRIPTION_ID12345678-1234-1234-1234-123456789012
HEROKU_API_KEY12345678-1234-1234-1234-123456789012
DIGITALOCEAN_TOKENdop_v1_1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef
RAILWAY_TOKEN12345678-1234-1234-1234-123456789012
GCP_SERVICE_ACCOUNT_KEYmy-service-account@my-project.iam.gserviceaccount.com
AWS_ACCOUNT_IDaws-account-id: 123456789012
GCP_API_KEYAIzaSyDdI0hCZtE6vySjMm-WEfRq3CPzqKqqsHI
AZURE_STORAGE_CONNECTION_STRINGDefaultEndpointsProtocol=https;AccountName=myaccount;AccountKey=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ABCDEFGHIJKLMNOPQRSTUV==;EndpointSuffix=core.windows.net

API Keys

PolicyExample Match
OPENAI_API_KEYsk-1234567890abcdefghijklmnopqrstuvwxyz
ANTHROPIC_API_KEYsk-ant-api03-abcdefghijklmnopqrstuvwxyz1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ123456789012345678901234567890
GITHUB_TOKENghp_abcdefghijklmnopqrstuvwxyz1234567890
GITHUB_FINE_GRAINED_TOKENgithub_pat_1234567890ABCDEFGHIJ_1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXY
STRIPE_KEYsk_live_1234567890abcdefghijklmnop
JWT_TOKENeyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
API_KEY_GENERICapi_key: 1234567890abcdefghij
PASSWORD_ASSIGNMENTpassword = "P@ssw0rd123!"
GOOGLE_API_KEYAIzaSyDdI0hCZtE6vySjMm-WEfRq3CPzqKqqsHI
SLACK_TOKENxoxb-123456789012-123456789012-abcdefghijklmnopqrstuvwx
PAYPAL_CLIENT_IDAQkquBDf1zctJOWGKWUEtKXm6qVhueUEMvXO_-MCI4DQQ4-LWvkDLIN2fGsdabcdefghijklmnopqrstu
TWILIO_API_KEYSK1234567890abcdef1234567890abcdef
SENDGRID_API_KEYSG.abcdefghijklmnopqrstuvwxyz1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ1234
CLOUDFLARE_API_TOKEN1234567890abcdefghijklmnopqrstuvwxyz1234

AWS Credentials

PolicyExample Match
AWS_ACCESS_KEYAKIAIOSFODNN7EXAMPLE
AWS_SECRET_KEYwJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
AWS_SESSION_TOKENFQoGZXIvYXdzEBYaDKJHabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789abcdefghijklmnopqrstuvwx

Private Keys

PolicyExample Match
RSA_PRIVATE_KEY-----BEGIN RSA PRIVATE KEY----- MIIEpAIBAAKCAQEA... -----END RSA PRIVATE KEY-----
EC_PRIVATE_KEY-----BEGIN EC PRIVATE KEY----- MHcCAQEEIA... -----END EC PRIVATE KEY-----
OPENSSH_PRIVATE_KEY-----BEGIN OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEA... -----END OPENSSH PRIVATE KEY-----
GENERIC_PRIVATE_KEY-----BEGIN PRIVATE KEY----- MIIEvQIBADANBgkqhkiG9w0BAQ... -----END PRIVATE KEY-----

CI/CD Secrets

PolicyExample Match
JENKINS_TOKENjenkins-token: 11a1234567890abcdef1234567890abcd
CIRCLECI_TOKENcircleci-token: 1234567890abcdef1234567890abcdef12345678
TRAVIS_CI_TOKENtravis-token: 1234567890abcdefghijkl
GITLAB_TOKENglpat-abcdefghijklmnopqrst
GITLAB_CI_TOKENCI_JOB_TOKEN: 1234567890abcdef
AZURE_DEVOPS_TOKENazdo-token: 1234567890abcdefghijklmnopqrstuvwxyz1234567890abcdef
BITBUCKET_TOKENbitbucket-token: 1234567890abcdefghij

Monitoring Secrets

PolicyExample Match
SENTRY_DSNhttps://1234567890abcdef1234567890abcdef@1a2b3c.ingest.sentry.io/1234567
NEW_RELIC_LICENSE_KEYnewrelic-key: 1234567890abcdef1234567890abcdef12345678
DATADOG_API_KEYdatadog-key: 1234567890abcdef1234567890abcdef
PAGERDUTY_INTEGRATION_KEYpagerduty-key: 1234567890abcdef1234567890abcdef
GRAFANA_API_KEYglsa_1234567890abcdefghijklmnopqrstuv_1a2b3c4d
PROMETHEUS_REMOTE_WRITEremote_write_url: https://prometheus-us-central1.grafana.net/api/v1/write
SPLUNK_HEC_TOKENSplunk 12345678-1234-1234-1234-123456789012
SUMO_LOGIC_COLLECTORhttps://collectors.us2.sumologic.com/receiver/v1/http/1234567890ABCDEF
BUGSNAG_API_KEYbugsnag-api-key: 1234567890abcdef1234567890abcdef
ROLLBAR_ACCESS_TOKENrollbar-access-token: 1234567890abcdef1234567890abcdef
AIRBRAKE_API_KEYairbrake-api-key: 1234567890abcdef1234567890abcdef
LOGDNA_INGESTION_KEYlogdna-ingestion-key: 1234567890abcdef1234567890abcdef
LOGGLY_TOKENloggly-token: 12345678-1234-1234-1234-123456789012
PAPERTRAIL_TOKENpapertrail-token: 1234567890abcdef1234567890abcdef

Authentication Secrets

PolicyExample Match
OAUTH_CLIENT_IDclient_id: 1234567890-abcdefghijklmnopqrstuvwxyz
OAUTH_CLIENT_SECRETclient_secret: GOCSPX-1234567890abcdefghijklmnop
OAUTH_REFRESH_TOKENrefresh_token: 1//0gFU7abcdefghijklmnopqrstuvw
OAUTH_ACCESS_TOKENaccess_token: ya29.a0ARrdaMabcdefghijklmnopqr
BASIC_AUTH_HEADERAuthorization: Basic dXNlcjpwYXNzd29yZA==
BEARER_TOKEN_HEADERAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.dozjgNryP4J3jVmNHl0w5N_XgL0n3I9PlFUP0THsR8U
API_KEY_HEADERX-API-Key: 1234567890abcdefghijklmnopqrst
SESSION_ID_COOKIEsessionid=a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0
OKTA_API_TOKENokta-token: 001234567890aBcDeFgHiJkLmNoPqRsTuVwXyZ12
AUTH0_API_TOKENauth0-token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6Ik
KEYCLOAK_CLIENT_SECRETkeycloak-client-secret: 12345678-1234-1234-1234-123456789012

Webhook URLs

PolicyExample Match
WEBHOOK_URLhttps://hooks.example.com/webhook/1234567890abcdef
SLACK_WEBHOOKhttps://hooks.slack.com/services/T12345678/B1234567890/abcdefghijklmnopqrstuvwx
DISCORD_WEBHOOKhttps://discord.com/api/webhooks/123456789012345678/abcdefghijklmnopqrstuvwxyz1234567890abcdefghijklmnopqrstuvwxyz123456

Package Registries

PolicyExample Match
NPM_TOKENnpm_abcd1234efgh5678ijkl9012mnop3456qrst
PYPI_TOKENpypi-abcd1234efgh5678ijkl9012mnop3456qrstuvwx7890yzab1234cdef567
QUAY_IO_TOKENquay.io-token: 1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ123456
JFROG_ARTIFACTORY_TOKENAKCp1234567890abcdefghijklmnopqrstuvwxyz
NEXUS_REPOSITORY_TOKENnexus-token: 1234567890abcdef-1234-1234-1234

Container Registries

PolicyExample Match
DOCKER_REGISTRY_TOKENdckr_pat_abcd1234efgh5678ijkl9012mnop3456qrst
DOCKER_HUB_TOKENdckr_pat_abcd1234efgh5678ijkl9012mnop3456qrst

Infrastructure Secrets

PolicyExample Match
TERRAFORM_CLOUD_TOKEN12345678901234.atlasv1.123456789012345678901234567890123456789012345678901234
HASHICORP_VAULT_TOKENvault-token: s.1234567890abcdefghijklmnop
AWS_SECRETS_MANAGER_ARNarn:aws:secretsmanager:us-east-1:123456789012:secret:MySecret-abcdef
AZURE_KEY_VAULT_SECREThttps://myvault.vault.azure.net/secrets/MySecret/1234567890abcdef1234567890abcdef
GCP_SECRET_MANAGERprojects/123456/secrets/my-secret/versions/latest
KUBERNETES_CONFIGapiVersion: v1 kind: Config
HELM_REPOSITORY_CREDENTIALShelm-repo-password: 1234567890abcdef
ANSIBLE_VAULT_PASSWORDansible-vault-password-file: /path/to/vault-pass
CONSUL_TOKENconsul-token: 12345678-1234-1234-1234-123456789012
RANCHER_TOKENtoken-12abc:12345

Encryption Keys

PolicyExample Match
SSH_KEY_FINGERPRINTSHA256:1234567890abcdefghijklmnopqrstuvwxyz1234567
PGP_KEY_ID0x1234567890ABCDEF
AGE_SECRET_KEYAGE-SECRET-KEY-1QYQSZQGPQYQSZQGPQYQSZQGPQYQSZQGPQYQSZQGPQYQSZQGPQYQSZQGPQY
AGE_PUBLIC_KEYage1abcdefghijklmnopqrstuvwxyz1234567890abcdefghijklmnopqrstuv
AWS_KMS_KEY_IDarn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012
GCP_KMS_KEYprojects/my-project/locations/us-central1/keyRings/my-keyring/cryptoKeys/my-key
AZURE_KEY_IDENTIFIERhttps://myvault.vault.azure.net/keys/mykey/1234567890abcdef1234567890abcdef
MASTER_KEYmaster_key: YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXoxMjM0NTY3ODkwYWJjZGVmZ2g=

Insurance

PolicyExample Match
AUTO_INSURANCE_POLICYAuto Policy: POLAUTO123
HOME_INSURANCE_POLICYHome Policy: HOME2024789
LIFE_INSURANCE_POLICYLife Policy: LIFEPOL456
TRAVEL_INSURANCE_POLICYTravel Policy: TRV2024123
WORKERS_COMPENSATION_CLAIMWorkers Comp Claim: WC2024789
DISABILITY_INSURANCE_POLICYDisability Policy: DISPOL123
DENTAL_INSURANCE_POLICYDental Policy: DENT456123
VISION_INSURANCE_POLICYVision Policy: VIS789456
US_HEALTH_INSURANCE_POLICYPolicy H123456789
US_INSURANCE_GROUP_NUMBERGRP123456
US_INSURANCE_CLAIM_NUMBERClaim CLM2024123456
MEDICARE_NUMBER_US123-45-6789-A
MEDICAID_NUMBER_USMedicaid 123456789A
BCBS_MEMBER_IDBCBS XYZ123456789
AETNA_MEMBER_IDAetna W123456789
UNITEDHEALTH_MEMBER_IDUnited 901234567
UK_NHS_NUMBER123 456 7890
CANADIAN_HEALTH_CARD1234567890
AUSTRALIAN_MEDICARE_NUMBER1234 56789 0
GERMAN_HEALTH_INSURANCE_NUMBERA123456789
FRENCH_SOCIAL_SECURITY_NUMBER184127645108946
EUROPEAN_HEALTH_INSURANCE_CARDEHIC 801234567890123
WORKERS_COMPENSATION_CLAIMWorkers Comp Claim: WC2024789
DISABILITY_INSURANCE_POLICYDisability Policy: DISPOL123
DENTAL_INSURANCE_POLICYDental Policy: DENT456123
VISION_INSURANCE_POLICYVision Policy: VIS789456

Medical

PolicyExample Match
MEDICAL_RECORD_NUMBERMRN-123456
HEALTH_INSURANCE_IDInsurance HIB123456789

Financial

PolicyExample Match
CREDIT_CARD4111111111111111
CREDIT_CARD_WITH_SEPARATORS4111-1111-1111-1111
ROUTING_NUMBER_US021000021
IBANGB82WEST12345698765432
SWIFT_CODEBOFAUS3N
ACCOUNT_NUMBER_USAccount Number: 123456789012
ACH_ROUTING_NUMBERRouting Number: 021000021
CREDIT_CARD_CVVCVV: 123

Tax Identifiers

PolicyExample Match
US_EIN_WITH_LABELEIN: 12-3456789
US_EIN_PREFIXEDEIN 12-3456789
US_TIN_WITH_LABELTIN 12-3456789
US_EIN12-3456789
UK_VAT_NUMBERGB123456789
EU_VAT_NUMBERDE123456789
CANADIAN_BUSINESS_NUMBER123456789RC0001
AUSTRALIAN_ABN12 345 678 901
GERMAN_TAX_NUMBER12/345/67890
FRENCH_SIRET_NUMBER12345678901234
FRENCH_SIREN_NUMBER123456789

Government IDs

PolicyExample Match
US_DRIVER_LICENSED12345678
US_PASSPORT_NUMBERM12345678
NATIONAL_IDNational ID: ID123456789
PASSPORT_MRZP<USADOE<<JOHN<<<<<<<<<<<<<<<<<<<<<<<<<<<<< L898902C<3USA6908061M9511084710000307<715816
ITIN900-70-1234

Social Security Numbers

PolicyExample Match
SSN123-45-6789

Email

PolicyExample Match
EMAIL_ADDRESSjohn@example.com

Phone Numbers

PolicyExample Match
PHONE_NUMBER_UK+442071234567
PHONE_NUMBER_CANADIAN+1-416-555-0123
PHONE_NUMBER_INTERNATIONALCall +14155551234
PHONE_NUMBER_US555-123-4567

Geographic

PolicyExample Match
US_ZIP_CODE12345
CANADIAN_POSTAL_CODEK1A 0B1
UK_POSTCODESW1A 1AA
GPS_COORDINATES40.7128,-74.0060

Employee IDs

PolicyExample Match
EMPLOYEE_IDEMP 123456

Vehicles

PolicyExample Match
VIN1HGBH41JXMN109186
US_LICENSE_PLATEABC-1234

IP Addresses

PolicyExample Match
IPV4_ADDRESS192.168.1.1
IPV6_ADDRESS2001:0db8:85a3:0000:0000:8a2e:0370:7334

Digital Identity

PolicyExample Match
UUID550e8400-e29b-41d4-a716-446655440000
BITCOIN_ADDRESS1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
ETHEREUM_ADDRESS0x742d35Cc6634C0532925a3b844Bc9e7595f5a123
MAC_ADDRESS00:1B:44:11:3A:B7
SHA_HASH2fd4e1c67a2d28fced849ee1bb76e7391b93eb12