Developer

Log Sanitizer Tool

A log sanitizer strips the identifiers that leak when you paste a log into a ticket, a chat or a public issue: emails, IPv4 and IPv6 addresses, API keys, bearer tokens, JWTs, Luhn-valid card numbers, MACs, phone numbers and SSNs. It runs locally and can keep placeholders consistent so the log still makes sense.

Last reviewed by the Radiatus Cloud team

Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

What gets redacted

The tool applies a fixed set of patterns: emails, JWTs (the eyJ prefix), common API-key shapes (sk-, AKIA, ghp_, xox, AIza and long hex strings), bearer and inline password assignments, card numbers that pass the Luhn check, IPv4 and IPv6, MAC addresses, phone numbers, US SSNs and UUIDs. Card numbers that fail Luhn are left alone, so an order ID that happens to be sixteen digits is not mistaken for a PAN.

Consistent placeholders

With consistent mode on, the same email becomes [EMAIL_1] everywhere and a different email becomes [EMAIL_2]. This preserves the structure of the log, so you can still see that one user hit an error five times, without revealing who they are. Turn it off and every match becomes a bare [EMAIL], which is safer against correlation but harder to read.

Optional passes

  • Home directories and usernames in paths, turning /home/jsmith into /home/[USER_1].
  • Internal hostnames ending in .local, .internal, .corp, .lan or .intranet.

The limit that matters

This is pattern matching. It does not detect names, order numbers, free-text addresses or a customer complaint quoted in a log line. Read the output once before you share it. Everything runs in the browser, so the original log is never uploaded, which is the point: a tool that sanitizes logs by sending them to a server has defeated itself.

Related tools

  • Log Redaction Preview — Paste logs to see what sensitive data (PII, Credits) gets masked.
  • PII Text Redaction Tool — Redact common PII from text (emails, phone numbers, IPs, credit cards, PAN, Aadhaar) using local pattern matching.
  • AI Prompt Sanitizer — Scan and sanitize prompts for injection attacks before sending to LLMs. Detect hidden instructions and unsafe patterns.
  • Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.

Frequently Asked Questions

Are the logs uploaded anywhere?

No. Redaction runs entirely in your browser with JavaScript regular expressions. That is deliberate: sending a log somewhere to have its secrets removed would expose the very secrets you are removing.

What is consistent placeholder mode?

It maps each distinct value to a numbered token, so the same IP is always [IP_3]. That keeps the log analysable, letting you follow one actor across lines, while still hiding the real value.

Why are some 16-digit numbers left unredacted?

Card numbers are only redacted if they pass the Luhn checksum that real card numbers use. This avoids masking order IDs, timestamps and other long digit strings that are not payment data.

Does it catch names and addresses?

No. Those have no fixed format, so pattern matching cannot find them reliably. The tool handles structured identifiers; a human still needs to read the result for free-text personal data.

Can I use it on a config file or stack trace?

Yes. It works on any text. Stack traces often contain home-directory paths and tokens in query strings, both of which the optional passes and key patterns catch.

Privacy & Security

Sanitization done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.