Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure

An exposed key.
Still active?

Find exposed keys, verify supported keys, review AWS or GCP access, and track owner action.

See how the product works
One key. Four checks.Example

AWS access key

AKIA••••••••4F8K

Found in

GitHub

  1. 01
    DiscoveryExposed on GitHub

    Found in a repository config file

  2. 02
    VerificationStill active

    Check the current status of a supported key type

  3. 03
    Access contextAWS permissions

    Review the IAM user and attached policies

  4. 04
    ResponseConfirm owner

    Track key rotation and remediation

Illustrative example: find an exposed key, verify a supported type, review AWS access context, and track owner action.

Teams using Cremit

Next Securities
Rapportlabs
8Percent
ENlighten
SBSi
Ordercheck
Spoonlabs
TVING
  • 1,000+

    Credential detection rules

    A match still needs review; it does not prove the key works.

  • 10

    Supported scan source types

    Coverage depends on the sources you connect.

  • ~6h

    Recheck interval for active keys

    Applies to supported keys last confirmed active.

What is non-human identity (NHI) security?

A non-human identity is a service account, workload principal or other software actor authenticated with a key, token, certificate or delegated grant. Securing it means knowing who controls it, what it can access and how to retire that access. A credential found outside its approved store is one signal to investigate.

What is Cremit?

Cremit Platform scans connected repositories, cloud storage and collaboration tools for exposed credentials. It checks current validity for supported types and adds available access context for supported AWS access keys and GCP API keys. A finding keeps its source location and ownership signals so a person can confirm who should respond at the issuer.

From discovery to incident response

Find keys in connected sources, check whether they work, review AWS and GCP access, and route findings to the people who can act.

Free plan to start, no credit card. Enterprise pricing on request.

Connect the tools you already use

Connect GitHub, GitLab, Bitbucket, AWS S3, Google Drive, Slack, Jira, Confluence and Notion. Review credentials found across these sources in one inventory.

Evidence flow · diagram

Keep the source with the finding

01 / 05
  1. Connected source

    GitHub repository

    One example of a supported source

  2. Finding

    AWS access key

    The credential is displayed in masked form

  3. Location

    File and commit details

    Link back to the source for investigation

The available location details vary by source.

A conceptual diagram, not a product screenshot or customer data. Available fields depend on the integration and key type.

Check for keys exposed outside your tools

Register a domain or GitHub organization. Cremit finds related public assets with evidence and can monitor supported discoveries unless you exclude them.

Content secret checks are separately enabled and bounded. Review what was actually scanned for each target.

Explore external scanning

Find candidates

Review evidence for related domains, websites, IPs, apps and GitHub organizations.

Review the scope

Supported discovered assets can enter monitoring automatically. Exclude an asset that is outside your scope.

Review exposures

Review findings from monitored public assets alongside findings from connected sources.

In customers’ words

Customers describe their work with Cremit. Read their stories for the details.

See all customer stories
Next Securities
Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive.

Jeongcheol Kang

Security Engineer · Next Securities

Read the customer story
Rapportlabs
As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount.

Jihoon Gong

Compliance Security Engineer · Rapportlabs

Read the customer story
8Percent
Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive.

Daeyoung Jeong

Security Team Leader · 8Percent

Read the customer story
ENlighten
As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit.

Jinseok Yeo

Security Engineer · ENlighten

Read the customer story
SBSi
As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day.

Name withheld

Security Manager · SBSi

Read the customer story
Ordercheck
As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.

Woongab Jeong

CEO, Founder · Ordercheck

Read the customer story
New research · September 2026

Blast Radius: a field playbook for leaked API keys

Record where the key was exposed and preserve available logs without delaying containment. The six-phase AWS, GCP and Azure guide also compares versions of AWS's compromised-key quarantine policy.

Read the playbook NHI Kill Chain series
Free PDF · English & Korean · No form

Before you connect a source

Check what a finding proves, what Cremit stores, and who takes action.

Are all findings automatically verified?

No. Cremit checks validity with the issuing service for supported credential types. Other findings need manual review. A successful check says the key authenticated at that time; it does not prove someone misused it.

Where does Cremit look?

It scans sources you connect, including GitHub, GitLab, Bitbucket, GHCR images, AWS S3, Google Drive, Jira, Confluence, Notion and Slack. External scanning can check bounded public content when enabled for your organization. It cannot inspect a local file or an unconnected service.

Can I see what a live key can access?

Cremit can show access context for supported AWS access keys and GCP API keys. That context depends on the available analysis; a validity result alone does not show every permission or prove the key was used. Check issuer records and activity logs before judging impact.

Who rotates or revokes a leaked key?

The service owner does that at the issuer. Cremit records where a key was found, its available verification result and the response status. An assigned owner, a suggested candidate and a source-file author are different signals; the team confirms who should act. Cremit does not rotate or revoke keys automatically.

Does Cremit store my source code?

Cremit reads source content during a scan but does not retain whole source files. It stores finding metadata and the credential value encrypted with AWS KMS for supported re-verification. A customer-managed KMS key can be configured.

Can I start without a sales call?

Yes. The free plan at argus.cremit.io does not require a credit card. Connect a supported source and review its findings before choosing a paid plan.

See all questions

How many of your leaked keys
still work?

Connect a scan source on the free plan and review exposed credentials. Supported types are checked against the issuing service, and results that need manual review are shown separately. No sales call needed.

Newsletter

Monthly NHI research brief

Security engineers and CISOs read our monthly brief on Non-Human Identity attacks, controls, and field research.

We never sell your email. Unsubscribe anytime.