32 lines
1.2 KiB
Markdown
32 lines
1.2 KiB
Markdown
# Chanora Diagnostic Redaction Audit Report
|
|
|
|
**Document status:** DV meeting baseline candidate
|
|
**Date:** 2026-05-29
|
|
|
|
## 1. Scope
|
|
|
|
This report defines the diagnostic redaction audit required before enabling diagnostics for external testers or public release.
|
|
|
|
## 2. Redaction Targets
|
|
|
|
| Data class | Required handling |
|
|
|---|---|
|
|
| Server passwords | Redact before export |
|
|
| Identity/private-key material | Redact before export |
|
|
| Tokens and known secrets | Redact through known-secret registry |
|
|
| Host/IP/email/path values | Redact or minimize according to diagnostic policy |
|
|
| User text content | Avoid unnecessary capture; redact when classified as sensitive |
|
|
|
|
## 3. Evidence Required
|
|
|
|
| Evidence | Required result |
|
|
|---|---|
|
|
| Unit tests | Redactor removes sample secrets and registered known secrets |
|
|
| Export demo | User-initiated export produces a JSON bundle without sample secrets |
|
|
| Manual review | Reviewer inspects candidate export before external release |
|
|
| Privacy alignment | Privacy policy describes user-initiated diagnostic sharing |
|
|
|
|
## 4. DV Conclusion
|
|
|
|
Audit expectations are defined. Candidate export evidence must be attached before external tester release.
|