{
  "id": 11720414,
  "title": "How We Built an On-Device PII Firewall in a 3.4KB Telemetry SDK",
  "url": "https://urgent.news/2026/10/03/how-we-built-an-on-device-pii-firewall-in-a-3-4kb-telemetry-sdk",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T16:12:09.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/snaptrace009/how-we-built-an-on-device-pii-firewall-in-a-34kb-telemetry-sdk-2in4"
  },
  "original_language": "en",
  "account": "SnapTrace, the client telemetry SDK developed by the company, aimed to keep its footprint strictly under 5KB to avoid negatively impacting Next.js Core Web Vitals (INP score). A significant engineering challenge was ensuring privacy and data sanitization by stripping sensitive user data such as passwords, JWT bearer tokens, and credit cards without relying on large third-party packages that would bloat the client bundle. The team implemented an in-browser regex scrubber for this purpose, ensuring raw customer secrets never reached the network or their ingestion servers.\n\nThe architecture of the zero-dependency client approach involves several key steps. First, an in-memory client-side regex scrubber is used to detect and redact unauthorized bearer & auth tokens, JWT patterns, credit card numbers, passwords, and keys before they are dispatched over the network. This process ensures that sensitive information is masked, with unauthorized data being replaced with placeholders like [REDACTED] and [REDACTED_CARD]. This in-memory scrubbing occurs entirely on the user's browser, preventing any raw sensitive information from being transmitted or stored on the company's servers.\n\nSecondly, SnapTrace utilizes the browser's native asynchronous transport mechanism, navigator.sendBeacon, which dispatches events in the background without interfering with the main thread or causing delays in the application's UI. This approach allows the SDK to operate efficiently, maintaining smooth application performance while ensuring that sensitive user data is properly protected and not exposed during network transmission.",
  "summary": "When building SnapTrace , our primary constraint was keeping the client telemetry footprint strictly under 5KB so it doesn't penalize Next.js Core Web Vitals (INP score). One of the most critical engineering hurdles was privacy and data sanitization : How do you strip sensitive user data (passwords, JWT bearer tokens, credit cards) without importing heavy 20KB–30KB third-party sanitization…",
  "key_points": [
    "SnapTrace SDK keeps footprint under 5KB to avoid impacting Core Web Vitals",
    "In-memory regex scrubber redacts sensitive data like tokens, JWTs, credit cards",
    "navigator.sendBeacon transmits data in background without UI delays"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}