Security boundary
What Redax protects, what it cannot promise, and the controls operators still own.
Why
Keep raw customer text outside the model boundary.
What
A local API that detects, replaces, and records safely.
How
Run it, send text, pass only the returned text onward.
The promise
Redax is a boundary for recognized sensitive text. It can detect configured patterns and optional local model entities, replace them, and return a safer string before your application calls a downstream model. It is not a complete data-loss-prevention system and it does not prove that every secret or identifier was found.
Threats it helps with
Structured identifiers in prompts and support text
Accidental PII transfer to a model provider
Unreviewed redaction behavior across application teams
Missing operational evidence about what the boundary changed
What remains your responsibility
OWNERUndetected PII, secrets, credentials, and new entity types
OWNERThe Redax host, container runtime, dependencies, and model files
OWNERNetwork egress, telemetry exporters, reverse proxies, and provider logs
OWNERRetention, access control, encryption, backups, and audit-log integrity
OWNERPrompt injection and unsafe instructions carried in otherwise redacted text
Production checklist
- 1.Pin the Redax image/package, model revision, and policy files.
- 2.Preload model files if your deployment must not fetch at startup.
- 3.Restrict egress and verify where metrics, traces, Redis, and logs are sent.
- 4.Protect /metrics, audit files, Redis, and any response or idempotency store.
- 5.Test representative Unicode, overlap, false-positive, and missed-entity cases before launch.
- 6.Treat readiness as a deployment gate and monitor fallback or detector errors.