ENVSHIELD
Before you paste a config file, log, or .env into a bug report, a gist, or a chat, run it through ENVSHIELD. It finds the API keys, tokens, passwords, connection strings and private keys and masks them, while leaving the readable settings (ports, hostnames, flags) alone. The scan is free; unlock full redaction and download with a Sovereign pass.
ENVSHIELD runs entirely in your browser and never uploads or transmits your file. It masks values by known secret shapes (AWS, GitHub, Stripe, Slack, Google, JWTs, PEM private keys, basic-auth URLs), by secret-looking key names (password, token, secret, api_key…), and by high entropy. It is a safety net, not a guarantee, always review the output before sharing, and rotate any secret that has already been exposed.