version: 1.0 description: CASAN H4 output filtering and data leakage prevention policy default_action: allow filters: - id: OUT-SECRET-001 name: Secret material must never leave the harness match: regex: "(API[_-]?KEY|ACCESS[_-]?TOKEN|REFRESH[_-]?TOKEN|PASSWORD|JWT[_-]?SECRET|SECRET)[[:space:]]*[:=][[:space:]]*[^[:space:]]+" action: redact replacement: "[REDACTED_SECRET]" severity: high - id: OUT-PII-EMAIL name: Email masking match: regex: "[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{2,}" action: mask replacement: "***MASKED_EMAIL***" severity: medium - id: OUT-PII-PHONE name: Phone masking match: regex: "(\\+?[0-9][0-9 .-]{8,}[0-9])" action: mask replacement: "***MASKED_PHONE***" severity: medium - id: OUT-HALLUCINATION-RISK name: Uncertainty language marker match: regex: "(maybe|might be incorrect|i am not sure|uncertain)" action: flag severity: low evidence: trace_dir: ".specify/logs/trace" audit_log: ".specify/logs/audit/security.jsonl" level4_gate: required: true fail_on: - unredacted_secret - credit_card_output - blocked_prompt_injection report_in: "docs/output/casan/casan-level4-assessment.md"