Enterprise-grade secret detection for your codebase. Scan for API keys, tokens, credentials, and sensitive data before they reach your repository.
AWS, GitHub, Stripe, OpenAI, Slack, Azure, GCP, and many more. Covers every major cloud provider and service.
Catch high-entropy strings that look like secrets even when they don't match a known pattern. No secret slips through.
Optionally verify if detected secrets are actually active and valid. Reduce false positives, focus on real threats.
GitHub Actions, GitLab CI, pre-commit hooks. Generate configs with a single command. Block merges with leaked secrets.
Console, JSON, SARIF, HTML, CSV. Integrate with GitHub Code Scanning, feed into dashboards, or export for audits.
Track known findings and only alert on new ones. Perfect for large codebases with historical secrets being remediated.
35+ detectors across every category that matters
Open source. MIT licensed. Install in seconds.