# Support Bundle Redaction

Support bundles should help diagnose The Gateway behavior without exposing secrets, private topology, customer identity, or full traffic content.

## Remove Before Sharing

- Private keys, tokens, passwords, session cookies, API keys, and recovery codes.
- Customer names, account identifiers, email addresses, and billing identifiers.
- Private hostnames, private IP maps, internal domain names, and exact topology unless explicitly approved.
- Full packet captures and raw traffic payloads.
- Unredacted DNS query logs.
- Public IP addresses when they identify a sensitive site or person.

## Usually Safe To Share When Redacted

- The Gateway version or commit.
- Deployment mode.
- Operating system.
- Hardware class.
- Route policy summary.
- DNS policy summary.
- Fallback state.
- Error messages with secrets removed.
- Screenshots with identifiers blurred.
- Reproduction steps.

## Bundle Summary Format

- Goal:
- Deployment mode:
- Route ownership expectation:
- DNS ownership expectation:
- Fallback expectation:
- Observed behavior:
- Expected behavior:
- Evidence attached:
- Redactions performed:
- Remaining risk:

