FAQ

Everything before you scan or subscribe

How the scan works, what happens to your data, what every plan costs, and how the MSP white-label tier works. Still stuck? Ask us directly.

How it works

What does GhostCred actually scan for?+
In code and config files: exposed API keys, hardcoded passwords, OAuth tokens, private keys, database connection strings, and JWT secrets. If you connect an AWS, Azure, or GCP environment instead, it checks for IAM users without MFA, access keys older than 90 days, overprivileged roles, public storage buckets, open security groups, and orphaned service-account credentials — cloud scanning is a first-class input, not an add-on.
What can I submit for scanning?+
Three input types: a public GitHub repository URL, an uploaded config file, or a connected AWS, Azure, or GCP account. Add a GitHub access token on Pro or MSP plans to reach private repos too.
Do I need to create an account to run a free scan?+
No. The free teaser scan runs with just a repo URL, a config file, or a cloud connection — no signup, no email required. An email only matters if you want the findings sent to your inbox, and it's required at checkout if you buy the full report.
How accurate are the findings — is this AI-guessed or verified?+
Findings come from an AI model (Claude) analyzing whatever you submit, using a forced structured-output prompt built to catch real credential patterns and to resist prompt-injection tricks planted in malicious repo content. It's an automated scan, not a human-reviewed pentest: per our Terms, results are provided as-is and findings are advisory — a clean report doesn't guarantee nothing is exposed, and you're responsible for verifying and remediating what it flags.
How fast do I get my report?+
The free teaser (finding count + risk score) appears in under a minute. The paid PDF report is generated and emailed automatically, typically within a few minutes of payment.
What's the difference between the free scan and the $49 report?+
The free scan gives you a watermarked summary — finding count and an overall risk score, no PDF. The $49 report unlocks the full PDF: every finding with severity and remediation guidance, plus the compliance impact matrix, emailed to you.

Data & security

Is my code or data stored?+
Files you upload are processed to produce your report and aren't retained as raw content afterward. We store the resulting findings (redacted — see next question) and, if you provided one, your email and the repo URL or filename you submitted.
Do you store my actual secret values?+
No. Any secret value GhostCred detects is redacted to its first four characters before anything is written to the database or shown in a report. The full value is never stored or displayed.
Which compliance frameworks does GhostCred map findings to?+
Every finding is mapped to SOC 2, HIPAA, NYDFS Part 500, and CMMC, so you can see which control an exposure puts at risk — the format MSPs use at client reviews and engineering teams use for their own audits.
Can I scan a private repository?+
Yes. Add a GitHub access token on Pro or MSP plans to scan private repos, or upload a config file directly on any plan without connecting GitHub at all.
What if I find a security vulnerability in GhostCred itself?+
We want to hear about it. Report it through the contact form (it's tagged as a security disclosure) and we respond promptly. All traffic is encrypted in transit, reports live in a private storage bucket served only via short-lived signed links, and privileged database operations run server-side only.

Pricing & plans

What are the pricing tiers?+
Free (1 scan, summary teaser, no PDF); Single Report at $49 one-time; Pro at $299/mo or $2,990/yr (unlimited scans, full PDF reports, API access, scan history dashboard); and MSP Pro at $799/mo or $7,990/yr (everything in Pro plus white-label branded reports). Continuous Monitoring ($19/mo), Team seats ($49/seat/mo), a Trust Badge ($29/mo), and a pay-as-you-go metered API ($0.50/scan, no subscription) are also available separately.
Can I cancel anytime?+
Single reports are a one-time charge — nothing to cancel. Pro, MSP, Monitoring, Team, and Trust Badge are monthly (or annual) subscriptions billed via Stripe until you cancel; manage or cancel from the billing portal in your dashboard.
Do you offer continuous monitoring, or is this a one-time scan?+
Both. A single scan is a snapshot. Continuous Monitoring ($19/mo) re-scans your repo every day and emails you the instant a new or worse credential exposure appears, with a full report on each scan.
Is there an API for programmatic scanning?+
Yes. POST to /api/v1/scan with a bearer token to scan a repo and get the full risk report back — no paywall, since you're already authenticated. It's included with Pro and MSP plans, or available pay-as-you-go at $0.50/scan with a metered key and no subscription.

For MSPs

How does the MSP white-label tier work?+
Set your logo, name, and accent color once in your dashboard; every report you generate after that inherits your branding automatically — "Prepared for [Client]" on the cover, your name on it, not GhostCred's. You scan a client's repo or config the same way as on any plan, and a branded PDF mapped to SOC 2, HIPAA, NYDFS, and CMMC lands in your inbox to hand over at the review. You never hold the client's raw secret values either — they're redacted before storage, same as every other plan.
Is there a per-client pricing option, or only flat-rate?+
Both. A per-client reseller rate ($39/client/mo) where you set your own retail price and keep the margin — best for a handful of clients — or a flat $799/mo ($7,990/yr annual) for unlimited clients once you're past roughly 20 of them.
Can I see a sample branded report before I buy?+
Yes — there's a live sample MSP-branded report you can view with no signup, plus the option to book a 15-minute demo where we brand a sample for your own shop.

Ready to see what's exposed?