Skip to main content

maskflow-evidence

A metadata-only, verifiable record of what MaskFlow masked — never the values themselves. Publishing the schema and shipping the emitters in the open lets any user confirm, by reading the code, exactly what leaves their environment.

Part of MaskFlow. MIT, free forever, no telemetry.

What an event looks like

{"event_id":"…","ts":"2026-09-07T12:00:00Z","session_id":"…","service":"support-bot",
 "environment":"prod","entity_type":"AADHAAR","count":1,"score":0.98,
 "recognizer":"pattern:AADHAAR","action":"masked","provider":"openai","model":"gpt-4o",
 "pack_version":"0.5.0","engine_version":"0.6.0"}

There is no field that can carry free text. Every string is a bounded slug; there is no place for a detected value, a placeholder, or the mapping between them. This is enforced structurally in schema.py and in CI by tests/test_schema_metadata_only.py.

Off by default

Nothing is emitted unless you turn it on. In .maskflowrc:

[evidence]
enabled     = true
sink        = "file"          # stdout | file | syslog | webhook | otlp
path        = "evidence.log"
service     = "support-bot"
environment = "prod"

The gateway reads MASKFLOW_GATEWAY_EVIDENCE_* environment variables with the same names.

Sinks

sink transport extra
stdout one JSON line per event —
file size-rotated JSON lines —
syslog SysLogHandler —
webhook POST JSON per event maskflow-evidence[webhook]
otlp OpenTelemetry log records maskflow-evidence[otlp]

What is deliberately not collected

Raw values, masked values, the mapping, request/response bodies, prompt text, and any user identifier beyond a caller-supplied opaque session_id. See docs/evidence.md for the full statement.

Metadata

Release files for maskflow-evidence 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for maskflow-evidence 0.1.0
File Size Uploaded
maskflow_evidence-0.1.0.tar.gz 18.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for maskflow-evidence 0.1.0
File Interpreter ABI Platform
maskflow_evidence-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 37.0 kB

Release files / maskflow_evidence-0.1.0.tar.gz

Download URL maskflow_evidence-0.1.0.tar.gz
Size 18.7 kB
Tags Source
SHA-256 checksum
How to use checksums
33bf8fd412cbc0024a733964ebcf38e00bcf211eab7fe313a876dc6ccf11e95a
BLAKE2b-256 checksum
How to use checksums
8b5ebf3e96fbc5137c15d871df0fcde4be68eb330074785868019a33e17434b3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release files / maskflow_evidence-0.1.0-py3-none-any.whl

Download URL maskflow_evidence-0.1.0-py3-none-any.whl
Size 18.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
44cb27d5e46a390c609178dc88313c880492d346936a9302df673d9cb0ab8908
BLAKE2b-256 checksum
How to use checksums
6eeccc71646b19217737ee49f627559e7b76e38716e30699ffb478e9345ae8df
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.0

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page