A site put together quickly with vibe coding went out with credentials sitting in the source. That moved credential detection from a someday item to a now item.
Security tooling here has to run without a dedicated operator, so it had to be quick to deploy and quiet to run.
Deployed as SaaS, with no one assigned to run it.
GitHub, Slack, Confluence and Jira connected to Cremit, so leaks are watched in the places the work actually happens.
Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive.
An AKIA key (AWS Access Key) left by an outsourced developer was found and removed.
Alerts arrive in Slack, so responding is a matter of tagging the person who owns the credential in the thread.
Support runs over Slack Connect instead of email and phone. One request was live 15 minutes after it was made.
