---
url: https://scruple.dev/rules/observability/no-sensitive-logs.md
description: Disallow sensitive values emitted without redaction.
---

# observability/no-sensitive-logs

Disallow sensitive values emitted without redaction.

## What it checks

Detected log and telemetry calls must mask, allowlist, hash for disclosure control, or redact visibly sensitive emitted values.

## Rule metadata

* Package: `@scruple/observability`
* Category: Data protection
* Tags: logging, privacy, redaction
* Default threshold: `0.9`
* Minimum confidence: `0.7`

## Examples

### Reported

```ts
logger.info({ email, password }, "Login attempt");
```

### Accepted

```ts
logger.info({ emailHash: hash(email) }, "Login attempt");
```
