Fuzit

Security model

Security model documentation.

Security is part of the acquisition pipeline.

The intended sequence is:

text
path policy
   ↓
safe traversal
   ↓
file classification
   ↓
safe content acquisition
   ↓
credential detection
   ↓
redaction
   ↓
context generation

Sensitive paths

The hard-sensitive-path policy includes classes such as:

Environment files

text
.env
.env.*

Credentials

text
.netrc
credentials
id_rsa
id_dsa
id_ecdsa
id_ed25519

Key/certificate files

text
.key
.pem
.p12
.pfx
.crt
.cer

Cloud credentials

text
.aws/credentials
.config/gcloud/**
.azure/**

Configured additional patterns are also supported.

Important security property

Known high-risk paths can be excluded **before content acquisition**.

This is stronger than reading the file and attempting to redact it later.

------------------------------------------------------------------------