Docs · Performance

Verified latency benchmarks

Per-request release measurements for typical, clean and secret-dense workloads.

Summary

Measured per request in release with 20,000 samples per scenario:

ScenarioP50P95P99
Typical ~2 KB prompt0.0216 ms0.0301 ms0.0466 ms
Clean 64 KB text0.415 ms0.465 ms0.699 ms
Secret-dense 8 KB content0.875 ms1.148 ms1.499 ms
Secret-dense 64 KB contentmeasured separately7.75 ms10.4 ms

The typical prompt is the dominant workload. Secret-saturated payloads are deliberately adversarial: they trigger many rules and validators per byte.

Methodology

The source is masking_engine/benches/latency_percentiles.rs in the Rust program. Each request is timed with Instant, 2,000 warm-up iterations are discarded, and 20,000 samples are sorted to calculate P50, P95 and P99 using nearest-rank.

cargo bench --bench latency_percentiles -- --nocapture

Results depend on CPU, operating system and binary version. These figures come from a release build run on July 10, 2026.

How to read the numbers

We do not publish “sub-2 ms” as a universal guarantee. On a typical workload, measured overhead is a few hundredths of a millisecond. Clean text up to 64 KB reached 0.465 ms P95. Secret-dense content costs more, so that workload is shown explicitly instead of being hidden behind a headline number.

Verify maskingCLI reference

Your privacy, your choice

We use essential storage to keep the site working and, only with your consent, analytics through PostHog and Google Analytics 4. We do not load advertising providers. Read our Privacy Policy.