Ready. Aim. Redactifire!
Ship logs.
Not leaks.
Redactifire finds and masks PII, CUI, and OUO in log files, HAR captures, and support bundles. It runs inside your own network, and a value gets the same replacement in every file of a job.
THE 3 AM SCENARIO
Production is down. Support needs your logs. You can't just send them.
A major defect just took a system offline, and your team can't diagnose it alone. The logs that would explain it are full of usernames, IP addresses, host names, and account data that nobody outside your network may see. You need to get useful information to someone fast, without waiting on legal or exposing customer data.
Hand-editing the logs
You search and replace by eye, under pressure, while the system is still down. Miss one IP address and you've leaked it anyway. Redact too much and the file is no use for diagnosing the defect.
A custom script
It works today and breaks the next time the log format changes or a new field appears. Someone has to maintain it for good, and 3 AM during an outage is the worst time to debug your own redaction tooling.
Point it at the file
You get a sanitized log back in minutes, with an audit trail that shows what was masked and how. You don't maintain a script or make a manual pass.
HOW IT WORKS
Every entity, typed and tracked.
Redactifire classifies each match (email address, host name, IP address, SSN, credit card, user ID) and remembers the mapping, so a value redacts the same way in every file of the job.
-
Ready.
Drop in log files, HAR captures, or a ZIP support bundle.
-
Aim.
Pick a profile, from Light to Max, or tune each entity type.
-
Redactifire!
Check every value side by side, then export the clean files and the Decoder Ring.
FEATURES
Built for the logs you have to send out.
TRY IT
See what stays, and what doesn't.
Each cell shows what leaves your network with that starter profile. Hover or tap a cell to see the original value.
| Profile | IPV4 | HOSTNAME | SSN | |
|---|---|---|---|---|
| Light |
192.168.1.45
nnn.vvv.1.45
|
jdoe@corp.com
jxxx@corp.com
|
backup-node01.corp.com
server1.example1.com
|
999-99-9876
xxx-xx-9876
|
| Medium |
192.168.1.45
10.183.34.95
|
jdoe@corp.com
user1@example1.com
|
backup-node01.corp.com
ggg.ggg.ttt
|
999-99-9876
[REDACTED]
|
| Max |
192.168.1.45
[REDACTED]
|
jdoe@corp.com
[REDACTED]
|
backup-node01.corp.com
[REDACTED]
|
999-99-9876
[REDACTED]
|
hover any cell to see the original
WHY REDACTIFIRE VS. OTHERS
Purposefully crafted and thoughtfully designed.
Most redaction tools are made for general documents, or they break the structure of a log. We built Redactifire for one problem: the days you lose waiting for security approval before you can send a log file to a vendor.
Deterministic pseudonymization
Elsewhere Generic scrubbers replace every value with the same [REDACTED] block, which breaks the links between events. A vendor engineer can no longer follow one IP address or user from file to file.
Redactifire Each value gets the same fake replacement in every file of the batch. Your vendor can still find the root cause and never sees your real infrastructure.
Knows your LDAP and Active Directory names
Elsewhere Pattern-only tools catch what looks like an email address, IP address, or SSN. An internal username like jsmith_admin matches no pattern, so it goes through untouched.
Redactifire Connect it to your LDAP or Active Directory server, and it recognizes real usernames and security groups that match no pattern. It works on every job once the directory is turned on and reachable. On an air-gapped network, list known user and group names in a profile instead.
The local Decoder Ring
Elsewhere Before compliance approves an export, they need proof of what changed. Most SaaS redaction tools make you send the logs to their cloud service to get that proof.
Redactifire Redactifire creates and stores the mapping table inside your own network. Compliance can see what was masked, and security knows the logs never left.
Small, and made for logs
Elsewhere Some PII engines are developer APIs that you must build a UI around. Others are large suites for documents, video, and audio, with features a log engineer will never use.
Redactifire Redactifire is one Docker container with a full UI, made for log files, HAR captures, and diagnostic data. There's less to configure and fewer edge cases, and it runs in under 5 minutes.
You no longer have to redact files by hand, line by line, under pressure, and hope you caught everything before the file left the building. Redactifire does that job for you.
WHY SELF-HOSTED
Your data stays on infrastructure you control.
Redactifire runs on your own servers: on premises, air-gapped, in your own cloud tenancy, or a mix of these. We never process your logs or the values in them, and neither does anyone else.
No shared service in the middle
There's no multi-tenant SaaS back end, so you have one less system to trust, and a breach somewhere else can't reach your data.
You control your data
Your logs and the PII in them never leave your network for a third party to process.
You choose the tradeoff
Run fully air-gapped for your most sensitive data, or deploy in your own cloud account for a lighter footprint. A mix of both also works.
The Decoder Ring maps every original value to its replacement, so it is as sensitive as the data it protects. Redactifire keeps it on your server and never sends it anywhere.
Redactifire runs where your data already lives.
It runs in Docker or Kubernetes on your own servers, so the only infrastructure you have to trust is yours.
Meet Terry.
Our pteredactyl. Always on redaction duty, so you don't have to be.