Why this matters
Prevents sensitive data exposure in logs for SOC 2.
Implement a tracing layer that scans fields and redacts patterns (JWT, API keys, emails) before output.
Prevents sensitive data exposure in logs for SOC 2.
Side-by-side examples engineers can pattern-match during review.
info!("token={}", token);info!(token="REDACTED", trace_id=%tid);info!("action"="auth.login", user_id=%uid)println!("email={} ", email)From the same buckets as this rule.
Public services must require TLSv1.2 or higher and set HSTS (max-age ≥ 15552000, includeSubDomains). Reject plaintext HTTP and weak ciphers; cookies must be Secure and HttpOnly with SameSite set.