8Percent runs P2P lending on a stack most fintech teams would recognize: GitHub for the code, and Slack, Confluence, Jira and Notion for everything said about the code. Credentials travel with the work. A key pasted into a Jira ticket during an incident, or a token written into a runbook, is not visible from any tool except the one it landed in. Answering where the credentials were meant asking five systems separately and trusting the answer was complete. As a regulated lender, the security team wanted that answer measured rather than assumed.
The security team ran the deployment themselves. All five platforms were connected in one day, with no agent to install and nothing to run inside their own infrastructure. Scanning started when the proof of concept started rather than after it, so the first findings arrived while the evaluation was still open.
Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive.
Within 24 hours the first full historical scan finished across all five platforms, and it surfaced credential exposures that had not been caught before. Each finding had already been checked against the service that issued it, so what reached the team was the set that still authenticated, not every string that matched a pattern. By the end of the first day, five tools' worth of credential state fit on one screen.