Secrets detection
Scanning of code, repositories and collaboration tools for exposed credentials, keys and tokens.
5 vendors · alphabetical, never ranked
- GitGuardianGitGuardian sells a platform that detects secrets exposed in code repositories, CI/CD pipelines, container registries, and collaboration tools, and extends that detection to govern non-human identities such as service accounts, API keys, and AI agents.Privately held · primary category
- Legit SecurityLegit Security sells an application security posture management platform that discovers AppSec issues across code, secrets, and cloud, coordinates and de-duplicates findings from other scanning tools, and automates remediation and policy enforcement across the software development lifecycle.Ownership not established
- SemgrepSemgrep sells static analysis software that scans source code for security issues, along with tools for open-source dependency and secrets scanning and an AI-assisted layer for detection and remediation.Privately held
- SnykSnyk sells a platform for application security that combines static code analysis, open-source dependency scanning, container and infrastructure-as-code checks, and secrets detection engines, alongside newer tools aimed at code generated by AI assistants and autonomous coding agents.Ownership not established
- Truffle SecurityTruffle Security sells TruffleHog, a tool that scans code repositories and other developer and collaboration tools for exposed non-human identities and their secrets, such as API keys, passwords, and tokens, with an enterprise edition adding verification and collaboration features.Privately held · primary category
No vendor pays to be listed or to change what we write. Descriptions are ours, drawn from each company's own site and filings. Corrections: /corrections.