What is secrets exfiltration?
Credentials leave via repos, CI logs, container layers, or deleted forks — detect, rotate, and close the path.
Read guideWeb Security
How secrets leave the process, why environment variables are a weak store, and how to redact sensitive fields in logs.
Sensitive data and secrets are values that grant access or identify a person: API keys, tokens, passwords, card numbers, and government IDs. Exfiltration is the movement of those values out of the intended boundary – into a log, a ticket, a model prompt, or an attacker-controlled host. Environment variables are convenient for local development and a poor production store: they are inherited by every child process, dumped in crash reports, and visible to every library in the process. Detection and redaction belong in the request path and in the logger, not only in a post-incident search.
Start with secrets exfiltration for the threat model. Use the environment-variable guide when the store is the problem, and the log-redaction guide when the leak path is observability.
Credentials leave via repos, CI logs, container layers, or deleted forks — detect, rotate, and close the path.
Read guideProduction secrets in env vars are plaintext with no audit trail. Store an ID and fetch at runtime instead.
Read guideImplement slog.LogValuer on types that hold secrets so only allow-listed fields are logged.
Read guideProduction PII detection: placement, latency budgets, fail-open versus fail-closed, staged rollout, and review questions.
Read guide