Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure

Product data handling

What happens to a credential finding

From a connected source to an owner review, and what an organization deletion request actually removes.

Cremit

This note describes the current application behavior. It does not replace your agreement, privacy notice, or a security assessment for your deployment.

Follow the record

  1. 01

    Connected source

    Cremit scans connected sources and, when enabled, monitored external assets.

  2. 02

    Protected finding

    A detected value is encrypted; a masked version and the finding context are stored for review.

  3. 03

    Scoped review

    Organization permissions govern actions. The public finding API returns a masked value.

  4. 04

    Owner action

    An owner acts at the issuer. An organization deletion request starts a separate seven-day restore window.

What the finding contains

A finding is useful only when its evidence and limits travel together.

01

Location and status

The record connects a detected credential to its observed locations and verification state. A pattern match alone does not prove that a key still works or was misused.

02

Encrypted value, masked display

The detection worker encrypts credential values through KMS and stores a separate masked representation. The public finding API serializes the masked value and excludes the encrypted payload and key identifiers.

03

Supported checks

Issuer-side validity checks apply only to supported credential types. AWS access-key and GCP API-key permission analysis requires the relevant integration; neither result proves that a key was abused.

Organization deletion has two stages

The current product keeps a restoration period. Deletion from the console is not immediate physical erasure.

  1. 01

    Request and restore window

    An authorized owner requests deletion. The organization is marked deleted, active access is removed, and the owner may restore it during the following seven days.

  2. 02

    Scheduled local purge

    After that window, a scheduled process hard-deletes the local organization graph and associated organization-scoped OAuth state. The request itself does not perform that purge.

What this action does not do

  • 01

    Deleting a Cremit organization does not revoke a credential at its issuer or erase copies in connected repositories and services. The owner handles those separately.

  • 02

    Database backups follow a separate retention lifecycle. This page does not promise a fixed backup expiry or row-by-row removal from snapshots; request the current terms for your deployment.

  • 03

    This page does not claim SOC 2 or ISO 27001 certification, a universal recovery target, or a fixed patch or penetration-test schedule. Ask for current evidence when those controls matter to your review.