Included in all plans

Secrets Detection with TruffleHog

Find exposed API keys, passwords, and credentials in every PR. 700+ detector types with near-zero false positives.

700+
Secret types
<1%
False positive rate
100%
Git history

How TruffleHog Protects Your Code

700+ Secret Types

Detect AWS keys, GitHub tokens, Stripe keys, database credentials, private keys, and hundreds more.

Git History Scanning

Find secrets that were committed and later removed. Catches credentials that might still be valid.

Near-Zero False Positives

Purpose-built detectors with entropy analysis and pattern matching for high accuracy.

AI Validation

diffray AI layer verifies findings, checks if secrets are actually used, filters test data.

Pre-Commit Prevention

Block secrets before they're committed. Integrate with CI/CD pipelines.

Instant Alerts

Get notified immediately when secrets are detected. Inline PR comments with remediation steps.

What We Detect

Cloud Providers

  • AWS Access Keys
  • GCP Service Accounts
  • Azure Credentials

Version Control

  • GitHub Tokens
  • GitLab PATs
  • Bitbucket Keys

Payment

  • Stripe API Keys
  • PayPal Credentials
  • Square Tokens

Databases

  • MongoDB URIs
  • PostgreSQL Passwords
  • Redis Auth

Communication

  • Slack Tokens
  • Discord Webhooks
  • Twilio Auth

Certificates

  • Private Keys
  • SSL Certificates
  • SSH Keys

And 650+ more secret types...

Frequently Asked Questions

Complete Security Coverage

TruffleHog is part of diffray's security toolkit. Combine it with Semgrep for comprehensive protection.

Stop Leaking Secrets

TruffleHog is included in all diffray plans. Start scanning your PRs for free.