Find exposed API keys, passwords, and credentials in every PR. 700+ detector types with near-zero false positives.
Detect AWS keys, GitHub tokens, Stripe keys, database credentials, private keys, and hundreds more.
Find secrets that were committed and later removed. Catches credentials that might still be valid.
Purpose-built detectors with entropy analysis and pattern matching for high accuracy.
diffray AI layer verifies findings, checks if secrets are actually used, filters test data.
Block secrets before they're committed. Integrate with CI/CD pipelines.
Get notified immediately when secrets are detected. Inline PR comments with remediation steps.
And 650+ more secret types...
TruffleHog is part of diffray's security toolkit. Combine it with Semgrep for comprehensive protection.
TruffleHog is included in all diffray plans. Start scanning your PRs for free.