THE PIPELINE

A signal you can inspect.

One local scanning engine, with a clear path from input to a redacted finding.

  1. 01

    Read locally

    The CLI reads UTF-8 files or bounded Git history. The browser demo sends text directly to the API on your machine.

  2. 02

    Find candidates

    Patterns recognize 15 services, JWTs, and private-key headers. Entropy checks flag random-looking literals assigned to secret-like names.

  3. 03

    Explain the signal

    Every candidate gets a location, rule, severity, and explanation. Matching a shape cannot establish whether a credential is active.

  4. 04

    Redact and respond

    Reports mask values and attach service-specific remediation. Review locally, rotate exposed credentials, and inspect their use.

Where does machine learning fit?

The optional CLI forest converts candidate text and context into 13 numeric features, then adds an experimental score. Scores are uncalibrated. All findings remain visible, including those below the artifact’s threshold. The browser demo uses rules plus entropy only.

See why filtering is disabled →

Know the boundaries.

Ignored files, binary input, symlinks, and oversized files can hide secrets. Explicitly scan ignored files when needed. Resource limits can make scans incomplete; the CLI returns exit code 2 for errors or incomplete work. A clean scan is not a security guarantee.

Detection coverage and limits