Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
All Customers/enterprise
Spoonlabs

Six platforms, one verified picture

A live audio and short-form video company connected code, cloud and collaboration tools together, then verified which of what it found still worked.

enterprise
8 days
From nothing connected to verified
6
Platforms connected at once
Full history
Scanned
Read the Story
The Challenge

Spoonlabs runs live audio and short-form video platforms with an engineering estate that grew the way successful products do: quickly, across more than one code host, more than one cloud, and a set of collaboration tools that everyone writes into.

That shape is what makes machine-identity risk hard. A credential pasted into a ticket, committed to a repository years ago, or left in a storage bucket is not visible from any single tool. The question was never whether something had been left behind. It was where, and which of it still worked.

The Solution

The proof of concept connected six platforms at once rather than starting with code alone: object storage, two code hosts, an issue tracker, a wiki, and the messaging workspace. Credentials cross those boundaries in practice, so looking at one of them answers the wrong question.

Scanning went through commit history rather than current files, because a secret removed in a later commit is still in the history and usually still valid. Documents, tickets and messages were read the same way.

Then every finding was checked against the service that issued it. That step is what turns a detection list into a work list: it separates the credentials that still authenticate from the ones that were revoked or rotated long ago, and only the first group is worth anyone's time.

The Results

Eight days took the engagement from nothing connected to a verified picture: what exists, where it lives, which of it still works, and what to close first.

The order mattered more than the count. Credentials with direct financial or infrastructure reach were separated from the larger group of messaging and collaboration tokens, so the work started where the damage would be worst rather than where the volume was highest.

The detection curve had not flattened when the window closed, which is the honest finding: coverage was still expanding into history that had not been reached. That is the argument for continuous scanning over an audit. An audit ends, and the estate does not.

Ready to achieve similar results?

Join Spoonlabs and other leading companies securing their infrastructure with Cremit

Trusted by industry leaders

Next SecuritiesRapportlabs8PercentENlightenSBSiOrdercheck