Why this matters
Logs often leave systems; SOC 2 requires confidentiality of sensitive data.
Before emitting logs, detect and redact PII and secret patterns (emails, tokens, keys). Replace values with consistent hashes or tokens; never log full credentials.
Logs often leave systems; SOC 2 requires confidentiality of sensitive data.
Side-by-side examples engineers can pattern-match during review.
{ "email":"alice@example.com","token":"Bearer eyJ..." }{ "email_hash":"sha256:ab12..","token":"REDACTED" }log.info({ email_hash: hash(email) })log.info({ email })From the same buckets as this rule.
Public services must require TLSv1.2 or higher and set HSTS (max-age ≥ 15552000, includeSubDomains). Reject plaintext HTTP and weak ciphers; cookies must be Secure and HttpOnly with SameSite set.