{"_id":"@dadieng/receipt-sanitizer","name":"@dadieng/receipt-sanitizer","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@dadieng/receipt-sanitizer","version":"0.1.0","private":false,"description":"Privacy-safe threat receipt and encrypted evidence pipeline for Dadieng.","license":"UNLICENSED","repository":{"type":"git","url":"git+https://github.com/XaidenLabs/Dadieng.git","directory":"packages/receipt-sanitizer"},"homepage":"https://dadieng.vercel.app/docs","publishConfig":{"access":"public"},"engines":{"node":">=22"},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"dependencies":{"@dadieng/schemas":"0.1.0"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_nodeVersion":"24.20.0","_id":"@dadieng/receipt-sanitizer@0.1.0","dist":{"integrity":"sha512-pNqhJE5SAbO1mrCLR+9mhVXGHlVtbBOIKNg2H3HRxrSLJNC+EZsJOtiHVcOSADwd2qAuxwLSNScQlBHWJ5himw==","shasum":"faf097f47557ab2bc8f31624d27169e4d0d86896","tarball":"https://registry.npmjs.org/@dadieng/receipt-sanitizer/-/receipt-sanitizer-0.1.0.tgz","fileCount":6,"unpackedSize":24773,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC0H1zwI27ecGNGhs9vgR0uUjXf0UkMJ2bw6hgl7UA5WQIgKdqjm+2N2w61qTEXsVNbSCi/NqTPsv7ozkm6dyQJ4fk="}]},"_npmUser":{"name":"xaidenlabs","email":"xaidentechnologies@gmail.com"},"directories":{},"maintainers":[{"name":"xaidenlabs","email":"xaidentechnologies@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/receipt-sanitizer_0.1.0_1788586934999_0.8940718596783546"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-05T05:42:14.801Z","0.1.0":"2026-09-05T05:42:15.141Z","modified":"2026-09-05T05:42:15.416Z"},"maintainers":[{"name":"xaidenlabs","email":"xaidentechnologies@gmail.com"}],"description":"Privacy-safe threat receipt and encrypted evidence pipeline for Dadieng.","homepage":"https://dadieng.vercel.app/docs","repository":{"type":"git","url":"git+https://github.com/XaidenLabs/Dadieng.git","directory":"packages/receipt-sanitizer"},"license":"UNLICENSED","readme":"# @dadieng/receipt-sanitizer\n\nThe Dadieng Threat Receipt pipeline separates public security intelligence from private incident evidence.\n\nThe pipeline:\n\n1. Classifies the incident using versioned attack and capability taxonomies.\n2. Builds a public receipt from controlled values without copying prompt or tool content.\n3. Encrypts the exact normalized event and decision using AES-256-GCM.\n4. Commits the public receipt to that encrypted envelope with SHA-256.\n5. Produces a stable deduplication key independent of receipt IDs and encryption randomness.\n6. Requires manual review for high and critical public disclosures.\n\n```ts\nimport {\n  createThreatReceiptPipeline,\n  decryptThreatEvidence,\n  verifyEvidenceCommitment,\n} from \"@dadieng/receipt-sanitizer\";\n\nconst incident = createThreatReceiptPipeline(event, decision, {\n  encryption: {\n    key: evidenceKey, // exactly 32 bytes; obtain this from a secret manager\n    keyId: \"tenant-evidence-key-v1\",\n  },\n});\n\nif (!verifyEvidenceCommitment(incident.receipt, incident.encryptedEvidence)) {\n  throw new Error(\"Evidence commitment mismatch\");\n}\n\nconst privateEvidence = decryptThreatEvidence(incident.encryptedEvidence, evidenceKey);\n```\n\nThe encrypted envelope is returned to the caller for local or tenant-private storage. Dadieng does not persist plaintext or encryption keys. Phase 8 will provide the database and object-storage adapters; a later Mera integration can supply recoverable, namespaced key material without changing this receipt contract.\n","readmeFilename":"","_rev":"1-6f8888dc070759d05c2bce5c6cc928e9"}