Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure

Credential management,
from discovery to sharing.

Find scattered API keys and tokens, see which supported keys still work, and assign the response. Give security and engineering one place to follow credentials from discovery to resolution.

Start for free

Teams using Cremit

  • Next Securities
  • Rapportlabs
  • 8Percent
  • ENlighten
  • SBSi
  • Ordercheck
  • Spoonlabs
  • TVING

Discovery, storage and sharing. One management approach.

From a key found in code to a credential used by your team. Cremit’s platform design connects the credential lifecycle. Talk to us about the right setup for your team.

Discuss your team’s setup
  1. 01 / Discover

    Discover and respond

    Find exposed credentials across connected code, cloud storage and collaboration tools. Check validity for supported types and track owner response.

    Credential inventory · Exposure detection · Validity checks · Response tracking

  2. 02 / Store

    Cremit Vault

    A path from discovered credentials to managed credentials. The storage layer is designed around native Vault storage and existing vault integrations.

    Native storage · Existing vault integrations · Credential migration

  3. 03 / Share

    Team credential hub

    API keys and tokens for the people who need them, within the right scope. A shared workspace designed to connect team sharing, access permissions and usage history.

    Team sharing · Access permissions · Usage history

  4. 04 / Use

    Developer and agent workflows

    An access model that extends to developer tools and AI agents. The platform direction brings common credential controls to CLI, desktop and agent workflows.

    CLI · Desktop · Agent access

The finding is where your investigation starts.

Review the credential, its validity and owner information together in the inventory. Open the source location to check how it was exposed.

Explore the product
Example credential inventory detail showing a masked AWS key, verification status, owner candidate and source information.
Actual source table showing the example GitHub repository, detected path, author candidate, last scan and location status.
Excerpts of the actual product interface with example data. View full example
  1. 01

    Return to the source

    Review the detected location and its evidence before deciding how to respond.

  2. 02

    Check the verification result

    Supported types can be checked for validity. A missing result stays unverified.

  3. 03

    Confirm who will respond

    Distinguish author candidates from assigned owners, then track the response.

  • 1,000+

    Credential detection rules

    A match still needs review; it does not prove the key works.

  • 10

    Supported scan source types

    Coverage depends on the sources you connect.

  • ~6h

    Recheck interval for active keys

    Applies to supported keys last confirmed active.

In customers’ words

Customers describe their work with Cremit. Read their stories for the details.

See all customer stories
  • Next Securities
    Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive.

    Jeongcheol Kang

    Security Engineer · Next Securities

    Read the customer story
  • Rapportlabs
    As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount.

    Jihoon Gong

    Compliance Security Engineer · Rapportlabs

    Read the customer story
  • 8Percent
    Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive.

    Daeyoung Jeong

    Security Team Leader · 8Percent

    Read the customer story
  • ENlighten
    As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit.

    Jinseok Yeo

    Security Engineer · ENlighten

    Read the customer story
  • SBSi
    As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day.

    Name withheld

    Security Manager · SBSi

    Read the customer story
  • Ordercheck
    As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.

    Woongab Jeong

    CEO, Founder · Ordercheck

    Read the customer story

Check for keys exposed outside your tools

Register a domain or GitHub organization. Cremit finds related public assets with evidence and can monitor supported discoveries unless you exclude them.

Content secret checks are separately enabled and bounded. Review what was actually scanned for each target.

Explore external scanning

Find candidates

Review evidence for related domains, websites, IPs, apps and GitHub organizations.

Review the scope

Supported discovered assets can enter monitoring automatically. Exclude an asset that is outside your scope.

Review exposures

Review findings from monitored public assets alongside findings from connected sources.

New research · September 2026

Blast Radius: a field playbook for leaked API keys

Record where the key was exposed and preserve available logs without delaying containment. The six-phase AWS, GCP and Azure guide also compares versions of AWS's compromised-key quarantine policy.

Read the playbook NHI Kill Chain series
Free PDF · English & Korean · No form

What is non-human identity (NHI) security?

A non-human identity is a service account, workload principal or other software actor authenticated with a key, token, certificate or delegated grant. Securing it means knowing who controls it, what it can access and how to retire that access. A credential found outside its approved store is one signal to investigate.

What is Cremit?

Cremit Platform scans connected repositories, cloud storage and collaboration tools for exposed credentials. It checks current validity for supported types and adds available access context for supported AWS access keys and GCP API keys. A finding keeps its source location and ownership signals so a person can confirm who should respond at the issuer.

Before you connect a source

Check what a finding proves, what Cremit stores, and who takes action.

Are all findings automatically verified?

No. Cremit checks validity with the issuing service for supported credential types. Other findings need manual review. A successful check says the key authenticated at that time; it does not prove someone misused it.

Where does Cremit look?

It scans sources you connect, including GitHub, GitLab, Bitbucket, GHCR images, AWS S3, Google Drive, Jira, Confluence, Notion and Slack. External scanning can check bounded public content when enabled for your organization. It cannot inspect a local file or an unconnected service.

Can I see what a live key can access?

Cremit can show access context for supported AWS access keys and GCP API keys. That context depends on the available analysis; a validity result alone does not show every permission or prove the key was used. Check issuer records and activity logs before judging impact.

Who rotates or revokes a leaked key?

The service owner does that at the issuer. Cremit records where a key was found, its available verification result and the response status. An assigned owner, a suggested candidate and a source-file author are different signals; the team confirms who should act. Cremit does not rotate or revoke keys automatically.

Does Cremit store my source code?

Cremit reads source content during a scan but does not retain whole source files. It stores finding metadata and the credential value encrypted with AWS KMS for supported re-verification. A customer-managed KMS key can be configured.

Can I start without a sales call?

Yes. The free plan at argus.cremit.io does not require a credit card. Connect a supported source and review its findings before choosing a paid plan.

See all questions

Plans and pricing

Start with 2 GB a month. No card required.

See findings from your own environment on the free plan. Compare monthly pricing and included scan volume before you commit.

How many of your leaked keys still work?

Connect a scan source on the free plan and review exposed credentials. Supported types are checked against the issuing service, and results that need manual review are shown separately. No sales call needed.

Newsletter

Monthly NHI research brief

Security engineers and CISOs read our monthly brief on Non-Human Identity attacks, controls, and field research.

We never sell your email. Unsubscribe anytime.