PATTERN DETECTION
What PasteGuard can find.
Matches are suggestions. Pattern detection can miss sensitive details or mark ordinary text by mistake.
Supported patterns
- Email: common ASCII local-part and domain forms. Internationalized or unusual formats may need a custom rule.
- Phone candidates: plus-prefixed formatted numbers of 8–15 digits, and common 10-digit forms with spaces, dashes, dots, or area-code parentheses. Bare digit-only phone numbers and many regional forms are not covered.
- Card candidates: 13–19 digits, optionally spaced or hyphenated, passing the Luhn checksum. Repeated-digit placeholders are rejected. Luhn does not establish that a number is a real payment card.
- Tokens: recognizable GitHub ghp/gho/ghu/ghs/ghr and github_pat prefixes, selected sk-/sk-proj-/sk-svcacct- forms, Stripe-style sk/rk live/test forms, AWS AKIA/ASIA access-key ID forms, Google AIza forms, and JWT-shaped three-part strings starting with eyJ.
- Private keys: complete standard PRIVATE KEY, RSA, EC, OPENSSH, DSA, and ENCRYPTED PRIVATE KEY blocks with matching begin/end labels.
- Custom text: literal names, references, or values you enter. Case matching is optional. Longer overlaps take precedence; a custom type wins an equal-length tie.
Review manually
Names, physical addresses, account IDs, arbitrary secrets, nonstandard tokens, health details, and identifying context are not comprehensively detected. Images, files, OCR, page requests, and clipboard history are not inspected. No external AI or named-entity model is used. A masked output may still identify a person or business.
Alias restoration
Tokens have a session namespace, for example [PG_A1B2C3D4_CLIENT_1]. Identical original text of the same type reuses its alias. Different casing or formatting can receive separate aliases to preserve the exact original. Restoration matches exact known aliases once; it does not guess values for missing, translated, or altered aliases. Unrecognized PG-like alias text is reported for manual review.
Safe examples
Demo screenshots and the built-in example use synthetic data. No real customer material or live credentials are included.