Opus 4.8's audit identified a critical privacy vulnerability: redacting rendered HTML isn't sufficient when the generator/source layer still contains domain fragments. If the source is rebuilt, the redacted content regenerates. The fix must happen in the data store — the articles database or batch files — not in the static HTML output. This is a software engineering insight with real privacy implications: redaction must occur at the earliest possible point in the data pipeline.