Building an Agentic System in .NET, Part 6: Redaction, Audit and the Safety Layer A developer has published the sixth and final part of a .NET agentic-systems series, detailing a safety layer that redacts secrets before they reach storage rather than at presentation time. The design routes every ConversationTurn through a RedactionPipeline that runs deterministic regex detectors first, Shannon-entropy heuristics second, and a contextual model third, replacing sensitive spans with reversible tokens kept in a separate masked-value vault and flagging low-confidence matches to a human review queue. The author argues prompt injection (OWASP LLM01:2025) is the top LLM vulnerability and that most agentic .NET projects reviewed lack any redaction pipeline. Prompt injection is OWASP's LLM01:2025, the top vulnerability in LLM based systems, and yet most agentic .NET projects I review have no redaction pipeline at all. They have a SessionStore , they have JsonSerializer , and they have a lot of optimism. This article closes the series by building the safety layer that the first five parts deliberately deferred: redaction before storage, tamper-evident audit, per-workspace ownership, and the threat model of a tool that can write. The 70% failure rate of visual-blackout redaction exists because teams treat redaction as a presentation concern. It is not. It is a data concern. Once a token, API key, or connection string reaches your database, you need a migration, a key rotation, and a breach notification conversation. The only safe moment is the pipeline stage before the INSERT. The pattern: every agent turn produces a ConversationTurn object. Before that object is handed to the store, it passes through a RedactionPipeline that runs detectors in order, deterministic regex first, entropy heuristics second, contextual model third, and replaces sensitive spans with reversible tokens stored separately in a masked-value vault. // RedactionPipeline.cs public sealed class RedactionPipeline { private readonly IEnumerable