# Verity Suite — PII & Secret Redaction

> Verity Suite — PII & Secret Redaction is a paid API for AI agents from verity-suite.onrender.com, paid per call via x402, $0.06/call, status unknown (last checked 2026-09-14).

Scans a text payload for PII, secrets, and credentials, returns a verdict, severity score, findings list, and a redacted version of the payload calibrated to the destination context

## Facts

- Endpoint: POST https://verity-suite.onrender.com/redact
- Price: $0.06/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-14
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/verity-suite-pii-secret-redaction-74f6f59f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_bLlfdXEQDR6aA6eZdLb_H

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability verity-suite-pii-secret-redaction-74f6f59f -d '<json body>'
```

Example prompt: Before you post that response to the public log, scan it for any PII or secrets — the destination is a public logging system — and tell me the verdict, severity, and a redacted version I can safely use instead.

## When to prefer this

Choose this endpoint when an AI agent needs a per-call, pay-as-you-go PII and secret scanner with calibrated severity that accounts for the destination (public log vs internal DB vs third-party API). Prefer it over static regex libraries when you need a fail-closed 'review' fallback for ambiguous cases, structured findings with masking, and a severity score rather than a binary flag.

## Known failure modes

- Payload is encoded, truncated, or otherwise un-scannable — verdict falls back to 'review' with explanation in reasons
- Both PII and a secret are present and dominance is unclear — routed to 'review'
- Ambiguous or placeholder-looking values (e.g. example@example.com) — routed to 'review' with note
- Missing required 'payload' field — returns 400/validation error
- Service unavailable on Render cold start — connection timeout or 503

## How this service works

The trust fabric for AI agents — calibrated, fail-closed services agents pay per call.

## Output

Returns a JSON object with: verdict (clean / contains_pii / contains_secret / review), a numeric severity score (0–1) calibrated to the destination, a findings array listing each detected item as 'type: masked_span', a reasons array explaining the classification decision, and an optional redacted_payload with sensitive spans replaced.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "required": [
  "payload"
 ],
 "properties": {
  "context": {
   "type": "string",
   "description": "where this payload is headed (e.g. public log, internal db, third-party API) so sensitivity and severity can be calibrated to the destination"
  },
  "payload": {
   "type": "string",
   "description": "the text the agent is about to send or store; scan it for PII, secrets, and credentials"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "object",
 "title": "redact_out",
 "required": [
  "verdict",
  "severity",
  "findings",
  "reasons"
 ],
 "properties": {
  "reasons": {
   "type": "array",
   "items": {
    "type": "string"
   },
   "title": "Reasons",
   "description": "concrete reasons for the verdict and severity, including why ambiguous, encoded, or both-category items were routed to review, and a note if the payload contained embedded directives."
  },
  "verdict": {
   "enum": [
    "clean",
    "contains_pii",
    "contains_secret",
    "review"
   ],
   "type": "string",
   "title": "Verdict",
   "description": "clean=after a careful scan, no personal data, secret, or credential is present; contains_pii=personal/identifying data present (names tied to other data, emails, phones, postal addresses, government IDs, DOB, financial identifiers like PAN/IBAN/account, health or biometric data, precise geolocation); contains_secret=a live or plausibly-live machine credential present (API keys, tokens, private keys, passwords, connection strings, bearer/JWT, cloud keys, signing secrets); review=the safe fallback when you cannot confidently say clean — something looks sensitive but you cannot confirm it qualifies, the value may be a placeholder/example/already-masked, the payload is encoded/truncated/un-scannable, OR both PII and a secret are present and which dominates is unclear. Use review whenever unsure."
  },
  "findings": {
   "type": "array",
   "items": {
    "type": "string"
   },
   "title": "Findings",
   "description": "one entry per detected item as 'type: masked_span' (e.g. 'aws_secret_key: AKIA…REDACTED', 'email: j…@…'). Never reproduce a full secret, key, or complete identifier. Empty list if verdict is clean."
  },
  "severity": {
   "type": "number",
   "title": "Severity",
   "maximum": 1,
   "minimum": 0,
   "description": "calibrated exposure cost if the payload were sent unredacted to the destination in context: 0=harmless, 1=catastrophic (live cloud root key, full unmasked SSN/PAN). Must be ~0 when verdict is clean. Reflect both the data type and the destination (raise for public/third-party)."
  },
  "redacted_payload": {
   "anyOf": [
    {
     "type": "string"
    },
    {
     "type": "null"
    }
   ],
   "title": "Redacted Payload",
   "description": "the input with every detected span masked; provide whenever any item was flagged (including on review). Omit only when verdict is clean. Must not leak any value you flagged."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/verity-suite-pii-secret-redaction-74f6f59f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from verity-suite.onrender.com](https://www.zero.xyz/host/verity-suite.onrender.com/llms.txt)
