import type { NexusResponse } from '../types/response.js'; import type { SecurityConfig, SecurityResult } from '../types/security.js'; /** * Removes common credentials and personal data from diagnostic text. * * This helper intentionally does not report what matched, which makes it safe * for audit/error paths where echoing the original match would recreate the * leak that the output guard detected. */ export declare function redactSensitiveText(value: string): string; /** Checks responses for leaked secrets, PII, and other unsafe output. */ export declare class OutputGuard { /** Checks a response, blocking, flagging, or redacting as configured. */ protect(response: NexusResponse, config?: SecurityConfig): SecurityResult; private calculateOverlap; }