Redaktyn — Block Secret Leaks
Overview
Other tools guess what a secret looks like. Redaktyn blocks the exact strings you registered — matched on your device.
URL: https://redaktyn.com Other tools guess. Redaktyn knows. Every DLP scanner on the market plays a guessing game — regex for "looks like an API key," entropy scores for "looks random enough," heuristics for "looks like a password." Guess wrong and you either miss the real leak or drown your team in false-positive warnings until they disable you. Redaktyn doesn't guess. You register the exact secrets fingerprints that matter — a production API key, a database password, a signing token or any literals — once, from any browser on your team. From that moment, no browser anywhere in your org can paste that exact string again. Not into ChatGPT. Not into a Jira ticket. Not into a public GitHub Gist. Anywhere. Exactly how the crypto works — read this before you trust us with your keys: Your secrets and your org passphrase never leave your device, in any form, ever. Here's the actual mechanism, not a marketing simplification of it: Passphrase → org key. Your admin sets one org passphrase, once, on a dedicated browser-extension page — never on our website, never in a form our servers can see. That passphrase is run through PBKDF2-SHA256 with 600,000 rounds, salted with your org ID, to derive a 32-byte org key. At 600,000 rounds, brute-forcing a guessed passphrase costs an attacker 600,000 hashes per attempt — the key itself never leaves your browser's memory. Secret → fingerprint, not a copy. Each secret you register is turned into an HMAC-SHA256 fingerprint (a 64-character hex digest) using the org key, entirely client-side. This is one-way math: given the fingerprint, there is no computation that recovers the secret. We store the fingerprint. We could not reconstruct your key from it if a court ordered us to. Matching happens locally, before the paste lands. When you paste anywhere on the web, the extension slides a window across the pasted text and checks it against your cached fingerprints — in-browser, in under a millisecond, with zero network round-trip. A match blocks the paste before it ever reaches the page's input field. This also means it works with your Wi-Fi off, on a plane, fingerprints already cached. Multi-device without re-typing the passphrase. Your session key is protected on disk with a split-key scheme: half lives in extension storage, half is issued by our server per device — neither half alone can reconstruct the org key, so a database breach on our end doesn't hand out your key. Recovery without us ever holding your passphrase. If an admin forgets the passphrase, recovery codes (generated in advance, shown once) decrypt a locally-encrypted copy of it — the decryption happens in your browser, not on our server. We only ever stored a ciphertext we cannot open. What we can prove we never have, because there's no column in our database to hold it: ✗ Your actual secret values ✗ Your org passphrase, in any form ✗ Anything you paste, or a hash of what you paste (only the label of a matched secret is logged, never the pasted text) What we do store — and this is the honest limit of the model: the one-way fingerprints themselves, and event metadata (label, destination domain, timestamp). Someone who steals our database and correctly guesses your org passphrase could theoretically confirm a secret offline — that 600,000-round PBKDF2 wall is the only thing standing between a breach and that outcome. We're telling you this because a vendor who only tells you the reassuring half of their threat model hasn't earned your trust. Why teams switch: ✓ Zero false positives. A paste either contains a secret you registered, or it doesn't. ✓ Zero-knowledge, provably. Standard, published primitives (PBKDF2-SHA256, HMAC-SHA256, AES-GCM) — nothing homegrown, nothing to take on faith. ✓ Works offline. Cached fingerprints mean the block still fires with no network at all. ✓ Team-wide in minutes. Register once, protected everywhere. ✓ Built for the AI era. The fastest-growing leak vector today is pasting a prod key into an AI chat window — Redaktyn catches that too.
0 out of 5No ratings
Details
- Version1.3.1
- UpdatedSeptember 16, 2026
- FeaturesOffers in-app purchases
- Offered byredaktyn.com
- Size239KiB
- LanguagesEnglish (United States)
- Developer
Email
support@redaktyn.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
Redaktyn — Block Secret Leaks has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
Redaktyn — Block Secret Leaks handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site