Redacted Event Policy

Events and Webhooks

Explain how fingerprint events, webhook delivery, and report exports are protected, signed, redacted, and trace-linked.

Public-Safe Boundary

Local analysis works without login. Protected actions use PLATPHORM_API_KEY only.

Raw IPs, raw high-entropy component values, full visitor hashes, and unredacted JA4 digest metadata are excluded from public surfaces.

Public Events

Degraded

Public events expose only empty or aggregate redacted state unless a safe feed exists.

Webhook Delivery

Protected

Webhook mutation, replay, and test delivery require PLATPHORM_API_KEY and signature validation.

Trace Linkage

Active

Event APIs emit trace headers for operator evidence without exposing secrets or raw digest values.