Redaction

Seamward's privacy posture is structural, not best-effort: the observation envelope has no field for payload values or request headers, so shipping them is not a configuration mistake you can make. This page explains what does leave your process, what the redaction policy actually controls, and how to verify both.

What never leaves

  • Payload values. The collector derives the payload's structure (field names and types) and its fingerprint, then discards the body. Every envelope records storage: "none".
  • Request and response headers. They are never read into the envelope at all.
  • Raw identifiers. Anything you pass as sourceEventId, idempotencyKey, or businessObjectId is converted to a keyed sha256: hash inside your process. The hash key is derived from your ingest token and never transmitted.

What ships

For the payload {"candidateId": "cand_812", "status": "hired"} the envelope carries only:

Code example

{  "storage": "none",  "schemaFingerprint": "sha256:...",  "schemaShape": {    "kind": "object",    "fields": {      "candidateId": { "kind": "string" },      "status": { "kind": "string" }    }  },  "redactionPolicyVersion": "seamward-default-v1"}

Field names remain visible because contract-drift detection needs them; field values are gone before the observation is queued. If a field name itself is sensitive in your domain, rename it in your handler before observation, because structure is what Seamward sees.

The policy

Code example

policy: {  version: "candidate-api-v1",  dropFields: ["full_name", "email", "phone_number"],  hashFields: ["candidate_external_id"],}

Be precise about what each part controls:

  • version is the part that ships. It is stamped into every envelope as redactionPolicyVersion, so evidence is traceable to the exact configuration that produced it. Change the version whenever you change the policy.
  • dropFields and hashFields configure optional local helpers: redactPayload and redactHeaders in Node.js, or Redactor::payload() and Redactor::headers() in PHP. Apply them only to your own logging or storage pipelines. They are not what keeps values out of envelopes; the schema already guarantees that. The helpers always drop the five credential headers (authorization, proxy-authorization, cookie, set-cookie, x-api-key) regardless of policy.
  • In Node.js, a custom policy replaces the default (seamward-default-v1: drops password, access_token, refresh_token, authorization, cookie, set-cookie) rather than merging with it; spread the defaults in if you want both. PHP and Laravel default to shape-only-v1 with empty dropFields and hashFields lists, so pass the complete lists you want when constructing a RedactionPolicy.

Verify redaction

Trust, then verify, with your own traffic:

  1. Send a safe test payload containing representative sensitive fields through the instrumented handler.
  2. Open the resulting observation in Seamward and inspect its structural evidence.
  3. Confirm you see field names and types only: no values anywhere, and identifiers only as sha256: hashes.
  4. If your domain treats certain field names as sensitive, confirm how they appear and adjust your handler before production traffic.

Do not disable redaction or log request bodies to troubleshoot delivery; the troubleshooting guide covers every delivery failure without either.

Next steps