Skip to content
winfunc
Secrets
Available

Find the credentials that should never have been committed.

Scan code, configuration, and the full git history for API keys, tokens, and private keys, check whether each one still works, and hand your team the rotation steps.

  1. acme
  2. /billing-api
  3. /Secrets
2 live
Found4
Live2
Commits scanned8,412
  • Stripe live keysk_live_••••••••4f2asrc/billing/client.ts:9Live
  • AWS access keyAKIA••••••••7QXMcommit 4f2c1e9 · deploy.shLive
  • GitHub tokenghp_••••••••Zk2pcommit a91d0b3 · .env.exampleRevoked
  • Postgres URLpostgres://app:••••@dbdocker-compose.yml:18Rotated
Stripe live key · validityCritical
Check
GET /v1/balance → 200
First seen
commit 7b21e0a · 214 days ago
Reachable by
Everyone with read access to the repository
Mark as test keyRotation steps
Secrets · code and git historyIllustrative data
What it does

Capabilities.

  • API keys, tokens, passwords, private keys, and connection strings
  • Full git history, not just the current revision
  • Validity checks that confirm whether a credential is still live
  • Provider-aware detection for cloud, payment, source control, and SaaS keys
  • Entropy and context analysis to cut false positives
  • Secret values masked everywhere they are shown
  • Rotation and revocation guidance per provider
  • Pull-request checks that stop new secrets before merge
How it works

From inventory to a verified upgrade.

  1. Step 1

    Scan

    Search code, configuration, and git history for credentials.

  2. Step 2

    Verify

    Check with the provider whether each credential is still valid.

  3. Step 3

    Scope

    Show where the secret is used and what it can access.

  4. Step 4

    Rotate

    Follow provider-specific steps, then confirm the old value is dead.

Why it matters

Built for decisions, not queues.

01

Live or dead, before you panic

Each credential is checked against its provider with a harmless call, so a revoked key is closed quietly and a live one is escalated immediately.

02

History included

Deleting a key in the latest commit does not remove it from the repository. winfunc scans every commit, so old exposures are found too.

03

Context, not regex alone

The agents read the code around a match, so test fixtures and documentation placeholders are separated from real credentials.

04

Handled carefully

Secret values are masked in the dashboard, reports, and notifications. Findings show where the secret lives and who can reach it, not the secret itself.

Continue the evaluation

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified