04.03 / 45 min

Protect sensitive evidence

Use automatic redaction, encrypted project storage, retention limits, hash-only mode, and explicit reveal controls.

By the endRedact secrets by defaultChoose full versus hash-only evidenceVerify protected storage
Controlled exercise

Use only the Academy Lab on 127.0.0.1:5177. Do not copy these tests to a public system without explicit written authorization.

01

Inspect the redaction preview

Before saving an auth response, preview it. Cookies, Authorization values, and token-shaped values should be masked while response hashes remain available.

02

Choose an evidence mode

Use hash-only when content is not needed to prove behavior. Use encrypted full evidence only when the sanitized body is necessary for owner-data or partial-leakage proof.

03

Set retention

Set a project retention limit appropriate for this disposable lab. Verify stale raw evidence can expire without deleting the finding metadata and hashes.

04

Test explicit reveal and copy

Reveal protected evidence only inside the project, copy the sanitized form, then hide it again. Never paste the lab tokens into reports as if they were real secrets.

MASTERY CHECKPOINT

Prove it before moving on.

The exported finding contains masked credentials, preserved hashes, and only the minimum body fields needed for proof.