Privacy Guide¶
Safedump is designed to capture debugging context without compromising privacy. This guide explains what's captured at each tier and how to configure Safedump for your environment.
Privacy Tiers¶
| Tier | Name | Captures | Safe to Share? |
|---|---|---|---|
| 0 | Minimal | Exception chain, stack frames (file, line, function, source lines). No variable values, no env var names, no argv | ✅ Yes |
| 1 | Standard (default) | Tier 0 + local variables (lists, dicts and strings as values; other objects as a short repr), env var names if include_env_names, argv if include_argv. All redacted |
✅ After visual review |
| 2 | Verbose | Tier 1 + objects expanded into their attributes (dataclass fields / instance __dict__), redacted the same way |
⚠️ Review before sharing |
| 3 | Full | Tier 2 + the module globals of the crash-site frame (modules, functions and classes are skipped), redacted | ⚠️ Review carefully |
| 4 | Debug | Tier 3 + environment variable values. Values whose name is on the denylist are replaced, and values matching secret patterns are scrubbed | ❌ Never share without manual audit |
Values are expanded up to max_depth levels and max_collection_items entries, and strings are cut to max_string_length characters. The cut happens after redaction, so a secret is never half-kept at the boundary.
What Gets Redacted (Tier 1+)¶
Variable Name Denylist¶
Variables whose names contain these patterns are redacted:
password, secret, token, key, api_key, credential, auth,
private_key, access_token, session_key, database_url, and more.
Matching uses tiered logic: ≤3-char patterns match exactly, 4-char patterns match word boundaries, ≥5-char patterns match substrings. This prevents false positives like keyboard matching key.
Credential Pattern Detection¶
Credentials found anywhere in a string are replaced with [REDACTED]. The rest of the string is kept, so an exception message stays readable. The search covers local values, nested inside lists and dicts, exception messages, argv and env var values. Known formats:
- AWS Access Keys (AKIA...)
- GitHub Tokens (ghp_...)
- Stripe Keys (sk_live_...)
- JWT Tokens (eyJ...)
- Generic API keys
Custom Redaction Rules¶
Add domain-specific rules:
safedump.configure(
redaction_rules=[
safedump.RedactionRule(r"PROPRIETARY-\d+", "[REDACTED]"),
safedump.RedactionRule(r"\b\d{3}-\d{2}-\d{4}\b", "[SSN REDACTED]", "values"),
]
)
What Is NEVER Captured (by default)¶
- Environment variable values (only at Tier 4)
- Command-line arguments (opt-in via
include_argv=True) - File contents
- Network traffic
- Keystrokes
before_capture Hook¶
For maximum control, use the before_capture hook to scrub data before Safedump processes it:
def my_scrubber(report):
# Remove sensitive frames or values
return report
safedump.configure(before_capture=my_scrubber)
Report Security¶
- Files saved with
0600permissions (owner read/write only) - Directory saved with
0700permissions - No network access — reports never leave your machine
- Redaction audit trail in every report records what was redacted and why
Sharing Guidance¶
- Always run
safedump viewfirst — visually inspect the report - Check the redactions section — see what was automatically scrubbed
- Use Tier 0 for public sharing — stack traces contain no variable data
- For bug reports — Tier 1 reports are generally safe after visual review
- Never share Tier 4 reports — they may contain environment variable values with credentials