Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive.
Find credential exposures.
Connect detection to response.
Find exposed credentials across connected code, cloud storage and collaboration tools. Check validity for supported types, review AWS IAM policies or GCP API-key restrictions, and track owner response.
See how the product works
Teams using Cremit
The finding is where your investigation starts.
Review the credential, its validity and owner information together in the inventory. Open the source location to check how it was exposed.
Explore the product

- 01
Return to the source
Review the detected location and its evidence before deciding how to respond.
- 02
Check the verification result
Supported types can be checked for validity. A missing result stays unverified.
- 03
Confirm who will respond
Distinguish author candidates from assigned owners, then track the response.
1,000+
Credential detection rules
A match still needs review; it does not prove the key works.
10
Supported scan source types
Coverage depends on the sources you connect.
~6h
Recheck interval for active keys
Applies to supported keys last confirmed active.
In customers’ words
Customers describe their work with Cremit. Read their stories for the details.
Check for keys exposed outside your tools
Register a domain or GitHub organization. Cremit finds related public assets with evidence and can monitor supported discoveries unless you exclude them.
Content secret checks are separately enabled and bounded. Review what was actually scanned for each target.
Explore external scanningFind candidates
Review evidence for related domains, websites, IPs, apps and GitHub organizations.
Review the scope
Supported discovered assets can enter monitoring automatically. Exclude an asset that is outside your scope.
Review exposures
Review findings from monitored public assets alongside findings from connected sources.
Latest from our research

Unlisted, Not Private
A September 2026 sweep of 33 public surfaces confirmed 23,912 active credentials. Privilege context was established for 7,468; 1,277 had permission to issue another key. Actual re-issuance was not tested.

How to count live credentials without confusing matches and keys
Count observed locations, distinct credential records and verification states separately. Define scope and check time before reporting exposure.

From exposed credentials to Cremit Platform: the workflow we support
How Cremit Platform finds exposed credentials, verifies supported types, and routes findings to an owner, with clear limits.
Blast Radius: a field playbook for leaked API keys
Record where the key was exposed and preserve available logs without delaying containment. The six-phase AWS, GCP and Azure guide also compares versions of AWS's compromised-key quarantine policy.
What is non-human identity (NHI) security?
A non-human identity is a service account, workload principal or other software actor authenticated with a key, token, certificate or delegated grant. Securing it means knowing who controls it, what it can access and how to retire that access. A credential found outside its approved store is one signal to investigate.
What is Cremit?
Cremit Platform scans connected repositories, cloud storage and collaboration tools for exposed credentials. It checks current validity for supported types and adds available access context for supported AWS access keys and GCP API keys. A finding keeps its source location and ownership signals so a person can confirm who should respond at the issuer.
Before you connect a source
Check what a finding proves, what Cremit stores, and who takes action.
Are all findings automatically verified?
No. Cremit checks validity with the issuing service for supported credential types. Other findings need manual review. A successful check says the key authenticated at that time; it does not prove someone misused it.
Where does Cremit look?
It scans sources you connect, including GitHub, GitLab, Bitbucket, GHCR images, AWS S3, Google Drive, Jira, Confluence, Notion and Slack. External scanning can check bounded public content when enabled for your organization. It cannot inspect a local file or an unconnected service.
Can I see what a live key can access?
Cremit can show access context for supported AWS access keys and GCP API keys. That context depends on the available analysis; a validity result alone does not show every permission or prove the key was used. Check issuer records and activity logs before judging impact.
Who rotates or revokes a leaked key?
The service owner does that at the issuer. Cremit records where a key was found, its available verification result and the response status. An assigned owner, a suggested candidate and a source-file author are different signals; the team confirms who should act. Cremit does not rotate or revoke keys automatically.
Does Cremit store my source code?
Cremit reads source content during a scan but does not retain whole source files. It stores finding metadata and the credential value encrypted with AWS KMS for supported re-verification. A customer-managed KMS key can be configured.
Can I start without a sales call?
Yes. The free plan at argus.cremit.io does not require a credit card. Connect a supported source and review its findings before choosing a paid plan.
How many of your leaked keys still work?
Connect a scan source on the free plan and review exposed credentials. Supported types are checked against the issuing service, and results that need manual review are shown separately. No sales call needed.
Monthly NHI research brief
Security engineers and CISOs read our monthly brief on Non-Human Identity attacks, controls, and field research.
