Skip to main content

maskflow-evidence

A metadata-only, verifiable record of what MaskFlow masked — never the values themselves. Publishing the schema and shipping the emitters in the open lets any user confirm, by reading the code, exactly what leaves their environment.

Part of MaskFlow. MIT, free forever, no telemetry.

What an event looks like

{"event_id":"…","ts":"2026-09-07T12:00:00Z","session_id":"…","service":"support-bot",
 "environment":"prod","entity_type":"AADHAAR","count":1,"score":0.98,
 "recognizer":"pattern:AADHAAR","action":"masked","provider":"openai","model":"gpt-4o",
 "pack_version":"0.5.0","engine_version":"0.6.0"}

There is no field that can carry free text. Every string is a bounded slug; there is no place for a detected value, a placeholder, or the mapping between them. This is enforced structurally in schema.py and in CI by tests/test_schema_metadata_only.py.

Off by default

Nothing is emitted unless you turn it on. In .maskflowrc:

[evidence]
enabled     = true
sink        = "file"          # stdout | file | syslog | webhook | otlp | hosted
path        = "evidence.log"
service     = "support-bot"
environment = "prod"

The gateway reads MASKFLOW_GATEWAY_EVIDENCE_* environment variables with the same names.

Sinks

sink transport extra
stdout one JSON line per event —
file size-rotated JSON lines —
syslog SysLogHandler —
webhook POST JSON per event maskflow-evidence[webhook]
otlp OpenTelemetry log records maskflow-evidence[otlp]
hosted batched POST to the collector at url, opt-in via api_key maskflow-evidence[hosted]

What is deliberately not collected

Raw values, masked values, the mapping, request/response bodies, prompt text, and any user identifier beyond a caller-supplied opaque session_id. See docs/evidence.md for the full statement.

Metadata

Release files for maskflow-evidence 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for maskflow-evidence 0.2.0
File Size Uploaded
maskflow_evidence-0.2.0.tar.gz 21.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for maskflow-evidence 0.2.0
File Interpreter ABI Platform
maskflow_evidence-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 41.7 kB

Release files / maskflow_evidence-0.2.0.tar.gz

Download URL maskflow_evidence-0.2.0.tar.gz
Size 21.2 kB
Tags Source
SHA-256 checksum
How to use checksums
b62f1e3dfbf472bc1d3c283f4a32b83ad39f4c26d6bc1dab14caa9e535dd773b
BLAKE2b-256 checksum
How to use checksums
09a79b15af7e087392565445dd257abde54b9543924c84ab908c1df9cca08c9a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release files / maskflow_evidence-0.2.0-py3-none-any.whl

Download URL maskflow_evidence-0.2.0-py3-none-any.whl
Size 20.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
84e4b06dac2fb4adb9408232d8ad0ea028de65e18d4cdf973d80cdf7d97041b8
BLAKE2b-256 checksum
How to use checksums
5632834c4200a3cf74e4a0dd8f352ea1542cb79717a4c5df5fc70ba1c4b37bcb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page