What problem does it solve?
Secrets-audit helps you detect leaked credentials and then assess why your organization’s secrets-management practices allowed those exposures, so you can both remediate and prevent recurrence.
Core Features & Use Cases
- Leaked secret discovery across code and history: Scans source files, Git history, and build-related locations for common provider key patterns and other high-confidence secret indicators.
- Verification and triage workflow: Prioritizes findings by checking whether credentials are live, understanding exposure window and blast radius, and recommending safe rotation steps.
- Secrets-management posture audit: Reviews where secrets live (source, env, artifacts, managers), IAM scoping, rotation cadence, logging/auditability, and cross-environment isolation.
Quick Start
Run the secrets-audit to scan a repository for leaked API keys and generate a secrets-exposure report with verification, posture findings, and prioritized recommendations.