8Percent runs P2P lending on a stack most fintech teams would recognize: GitHub for the code, and Slack, Confluence, Jira and Notion for everything said about the code. Credentials travel with the work. A key pasted into a Jira ticket during an incident, or a token written into a runbook, is not visible from any tool except the one it landed in. Answering where the credentials were meant asking five systems separately and trusting the answer was complete. As a regulated lender, the security team wanted that answer measured rather than assumed.
The security team ran the deployment themselves. All five platforms were connected in one day, with no agent to install and nothing to run inside their own infrastructure. Scanning started when the proof of concept started rather than after it, so the first findings arrived while the evaluation was still open.
Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive.
The initial scan brought findings from five connected tools into one view. A source match did not by itself establish whether a credential still worked: issuer-side checks applied to supported credential types, while other findings needed review. Scan time and historical coverage depend on each connector and the amount of data.