Skip to main content

Channels Overview

A channel represents an outbound boundary through which sensitive data can leave your application. envtrap monitors five distinct runtime channels.

The 5 Monitored Channels

Network (network)

Intercepts outbound HTTP/HTTPS traffic through an in-memory loopback MITM proxy.

DNS Resolution (dns)

Intercepts core node:dns lookup and resolution APIs to block secret queries and tunneling.

Subprocess Spawning (child_process)

Wraps spawn, exec, and fork to prevent passing credentials via options.env.

Terminal Output (stdout & stderr)

Scans and redacts credentials from stdout and stderr console streams in real time.

Enforcement Modes

Each channel can be independently configured in envtrap.json with one of three modes:

Default Policies

envtrap ships with zero-configuration defaults designed to stop remote exfiltration while maintaining developer visibility:
envtrap.json