05
Redaction
When a secret slips in, scrub the bytes. Keep the receipt.
Heddle is content-addressed and immutable on purpose — but a
leaked credential needs to come out. Redaction is the first-class
primitive that reconciles both: an attributed, signed operation
that declares a blob removed, swaps a stub into every
materialized view, and leaves a tombstone any auditor can verify.
Two phases. heddle redact writes the tombstone —
the state still resolves, but readers see the redaction notice
in place of the secret. heddle purge, owner-only,
removes the underlying bytes from local + canonical stores and
appends a non-reversible oplog entry. The tombstone stays. The
audit trail of the removal stays.