Seed values and search every sink
Use one unique fake card value, token, customer name, and account ID. Run a successful payment, failed payment, provider timeout, and crash. Search device logs, remote crash reports, analytics events, and support bundles. Keep a trace ID and safe error code as proof that support can still find the fault. Error handlers often record more than normal paths, so inspect them separately. Do not keep full request or response objects just to make debugging easy.
Test cases and proof
| Case | Expected result | Proof to keep |
|---|---|---|
| Payment request fails | Log safe error code and trace ID | Log entry |
| Authorization header sent | Never log token | Log search |
| Crash during card entry | No sensitive field dump | Crash report |
Check every copy of an error
A failure may reach a device log, an app analytics SDK, a crash service, and a support ticket. Use a unique fake token in one staging request and search all four places. Record when each copy appeared and who can read it. If the provider adapter logs the request before the app logger redacts it, fixing only the app logger will leave the leak. Add a log schema that names safe fields, then make adapters emit that shape. Test a new, unexpected provider error because developers often print full objects when the error type is unknown.
Force one error through every logger
Trigger a fake failed transfer with reference TEST-123, a fake bearer token, and fake account number. Check device logs, crash reports, analytics, network tracing, and server error logs. The reference and error class can remain for support; the token and full account number must not. Repeat in release build because debug and release logging paths differ. Keep redacted samples and pipeline settings. A logger that strips secrets in the app can still leak them when an HTTP client dumps headers or a crash tool records request bodies. (OWASP mobile storage control).
Check the support bundle as a separate export
Send synthetic marker TOKEN-LEAK-01 in a failed staging request, and make the provider return malformed JSON. Inspect the HTTP client exception before the app error handler receives it; the exception can contain headers or body data. Export the support bundle after the failure and search both plain files and compressed contents. Then attempt the export as another test account. A redacted log is still private if it names customer activity. Save the bundle schema, export permission result, and safe trace ID. Finally, find the failed operation using only that trace ID to prove that redaction preserves diagnosis.
Test nested fields and encoding
Create a staging error object with the fake token in three places: an Authorization header, a nested request.credentials.token field, and an exception message. Send it through the adapter and crash reporter. Redaction that removes only top-level token keys must fail this fixture. Search the exact marker and its URL-encoded form in the exported report. If a report is inaccessible to the tester, record that sink as unchecked rather than clean. Add one safe diagnostic with a provider reference and approved error class, then confirm support can search it. Keep the allowlist version beside the app build so a new SDK field cannot silently widen the log schema.