Free tools

Credential exposure checkers

Pick what you want to check. Your first scan is free and takes about a minute. Compliance mapping to SOC 2, HIPAA, NYDFS, and CMMC comes with the full report.

Are your AWS keys exposed?

Check a repo or .env for exposed AWS access keys (AKIA…), secret keys, and over-permissive IAM in ~60 seconds. First scan is free.

Did you leak a Stripe secret key?

Find leaked Stripe secret keys (sk_live…) and webhook secrets in your code or config. Instant scan. Compliance mapping is in the full report.

Scan for exposed GitHub tokens

Scan for exposed GitHub personal access tokens (ghp_…) and OAuth tokens that hand attackers your repos. Free, ~60s.

Is your OpenAI API key exposed?

Check for exposed OpenAI, Anthropic, and other LLM API keys (sk-…) being drained in your repos. Free instant scan.

Scan your .env file for secrets

Drop in a .env file and instantly see every exposed secret (API keys, passwords, tokens) with a risk score. First scan is free.

Find exposed database credentials

Find exposed database connection strings and passwords (Postgres, MySQL, Mongo, Redis) in your code. Free instant scan.

Scan Dockerfiles for hardcoded secrets

Scan Dockerfiles and docker-compose for hardcoded secrets, baked-in keys, and credentials in build args. Free, ~60s.

Detect exposed private keys

Detect exposed private keys (.pem, .key), SSH keys, and certificates committed to your repos. Free instant scan.

SOC 2 secret scanning, the practical version

What auditors expect for secret management under SOC 2, plus a scan that finds your exposed secrets. Control mapping is included in the full report.

HIPAA credential exposure check

Check whether exposed credentials put PHI at risk under HIPAA. Your first scan is free; safeguard mapping is included in the full report.

Is your JWT signing secret exposed?

Find exposed JWT signing secrets that let attackers forge tokens and impersonate any user. Free instant scan.

Find secrets leaked in CI/CD configs

Scan CI/CD configs (GitHub Actions, GitLab CI, CircleCI) for hardcoded secrets and exposed deploy credentials. Free.

Or scan your whole repo, first one free