Ready. Aim. Redactifire!

SELF-HOSTED  ·  REDACT PII, CUI, OUO & ANYTHING ELSE

Ship logs.
Not leaks.

Privacy-first, self-hosted leak prevention: Redactifire finds and masks PII, CUI, OUO, and other sensitive data in log files, HAR captures, and support bundles — deterministically and consistently, entirely inside your own network.

THE 3 AM SCENARIO

Production is down. Support needs your logs. You can't just send them.

A major defect just took a system offline and your team can't diagnose it alone — but the logs that would explain what's happening are full of usernames, IPs, hostnames, and account data nobody outside your network is allowed to see. You need to get someone real information, fast, without waiting on legal or exposing customer data to do it.

THE OLD WAY

Hand-editing the logs

Search-and-replace by eye, under pressure, while the system is still down. Miss one IP and you've leaked something anyway. Redact too aggressively and the file's useless for actually diagnosing the defect.

THE OLD WAY

A custom script

Works today. Breaks the next time the log format changes or a new field shows up. Someone has to own it forever, and at 3 AM during an outage is exactly when nobody wants to be debugging their own redaction tooling too.

REDACTIFIRE

Point it at the file

Get a consistently sanitized log back in minutes, with an audit trail proving exactly what was masked and how. No script to maintain, no manual pass, no guessing whether you caught everything.

HOW IT WORKS

Every entity, typed and tracked.

Redactifire doesn't just find-and-replace. It classifies each match — email, hostname, IP, SSN, credit card, user ID — and remembers the mapping, so the same value redacts the same way every time, across every file in the job.

Redactifire — Sanitize
Redactifire's Detected Entities view (raw log text, each PII type highlighted in its own color) directly above the Sanitized Preview (the same text with values masked).

FEATURES

Built for logs that actually matter.

Consistent pseudonymization

The same email becomes the same masked value every time. Your support team can still trace an issue through a ticket and correlate what's going wrong — without ever seeing who it belongs to.

Every redaction mode you need

Suppress, pseudonymize, or partially mask — down to which octet of an IP address or which digits of an SSN or credit card number survive.

Selective redaction

Exempt specific values from an otherwise type-wide rule — redact every email address except the one your vendor actually needs to see.

Cherry-pick what gets missed Coming soon

Highlight anything detection didn't catch and mark it yourself — it's redacted from then on, everywhere it appears.

Save your mappings and settings

Redaction rules, presets, and per-value overrides persist across sessions. Set it up once, sanitize the next file in seconds.

Live preview

Change the text or the rules and watch the sanitized output update instantly — no re-run, no guessing what a mode change will do.

Works across every file

Upload a whole batch at once — the same value redacts identically across every file in the session, so cross-referencing stays possible.

LDAP-aware

Point it at your directory to recognize real usernames and groups, even when they never match a regex on their own.

Authentication

Local accounts today, plus LDAP/Active Directory bind auth with group-based access and admin control already built in. OIDC support is next on the roadmap.

Full audit trail

Every job keeps its original text, sanitized output, and complete Decoder Ring — so you can prove exactly what was masked, long after the fact.

Better support, happier vendors

Redacted logs your vendor can still act on mean faster turnaround for you — and faster issue resolution for your users.

Extremely fast deployment

One Docker container, one command. Point it at your own LDAP and you're sanitizing real data in minutes, not a procurement cycle.

TRY IT

Hover to see what stays, and what doesn't.

Every value below is real. Hover any cell to see exactly what leaves your network.

Redaction level IPV4 EMAIL HOSTNAME SSN
Partial
192.168.1.45 xxx.xxx.xxx.45
jdoe@corp.com jd**@corp.com
backup-node01.corp.com backup-xxxxx.corp.com
118-42-9013 xxx-xx-9013
Pseudonymize
192.168.1.45 10.242.88.17
jdoe@corp.com user1@example1.com
backup-node01.corp.com fffffffffffff.llll.fff
118-42-9013 042-19-7735
Full
192.168.1.45 [REDACTED]
jdoe@corp.com [REDACTED]
backup-node01.corp.com [REDACTED]
118-42-9013 [REDACTED]

hover any cell to reveal

WHY SELF-HOSTED

Security first. Your data, your infrastructure, your call.

Redactifire runs entirely on infrastructure you control — on-prem, air-gapped, or your own cloud tenancy in a hybrid setup. Nothing about your logs or the sensitive values inside them is ever processed by us or anyone else.

Security-first by design

No multi-tenant SaaS backend in the middle means one less system to trust and one less place a breach elsewhere can reach your data.

You control your data

Your logs and the PII inside them never leave your network to be processed by a third party. That control is the point, not a side effect.

Take as much or as little risk as you want

Run fully air-gapped for your most sensitive data, or deploy in your own cloud account for a lighter footprint — hybrid works fine. You choose the tradeoff.

Redactifire — Decoder Ring
Redactifire's Decoder Ring, an auditable table mapping every original value to its redacted replacement, with per-type color coding and per-value mode controls.

One example: the Decoder Ring — the auditable mapping of every original value to its redacted replacement — is exactly as sensitive as the data it protects, so it's stored locally and never transmitted anywhere either.

Redactifire runs where your data already lives.

Self-hosted. Docker-ready. Nothing to trust but your own infrastructure.