Live or dead, before you panic
Each credential is checked against its provider with a harmless call, so a revoked key is closed quietly and a live one is escalated immediately.
Scan code, configuration, and the full git history for API keys, tokens, and private keys, check whether each one still works, and hand your team the rotation steps.
sk_live_••••••••4f2asrc/billing/client.ts:9LiveAKIA••••••••7QXMcommit 4f2c1e9 · deploy.shLiveghp_••••••••Zk2pcommit a91d0b3 · .env.exampleRevokedpostgres://app:••••@dbdocker-compose.yml:18RotatedGET /v1/balance → 200Search code, configuration, and git history for credentials.
Check with the provider whether each credential is still valid.
Show where the secret is used and what it can access.
Follow provider-specific steps, then confirm the old value is dead.
Each credential is checked against its provider with a harmless call, so a revoked key is closed quietly and a live one is escalated immediately.
Deleting a key in the latest commit does not remove it from the repository. winfunc scans every commit, so old exposures are found too.
The agents read the code around a match, so test fixtures and documentation placeholders are separated from real credentials.
Secret values are masked in the dashboard, reports, and notifications. Findings show where the secret lives and who can reach it, not the secret itself.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.
