Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive.
API keys and tokens,
from discovery to sharing.
NHI security for the credentials your teams and workloads use. Find exposed keys, check supported types and assign a response owner. Plan storage and sharing around the way your team works.
Start for free2 GB of free scanning each month · No credit card required
Teams using Cremit
Is the key still active? Who will respond?
Review where a key was found, check supported credentials and assign a response owner. Follow one key from discovery through revocation and a follow-up check in the actual interface.
Follow one key through the response- 01
Return to the source
Review the detected location and its evidence before deciding how to respond.
- 02
Check the verification result
Supported types can be checked for validity. A missing result stays unverified.
- 03
Confirm who will respond
Distinguish author candidates from assigned owners, then track the response.
1,000+
Credential detection rules
A match still needs review; it does not prove the key works.
10
Supported scan source types
Coverage depends on the sources you connect.
~6h
Recheck interval for active keys
Applies to supported keys last confirmed active.
In customers’ words
Customers describe their work with Cremit. Read their stories for the details.
Plans and pricing
Start with 2 GB a month. No card required.
See findings from your own environment on the free plan. Compare monthly pricing and included scan volume before you commit.
Before you connect
- Required permissions
Choose a source and review its access scope and setup instructions.
Integration guides- Stored data
Cremit does not retain entire scanned source files. Detected credentials are stored encrypted using AWS KMS.
How data is handled- Disconnection and deletion
Disconnecting a source and deleting existing records are separate steps. Review retention and deletion by data type.
Retention and deletion
Before you connect a source
Check what a finding proves, what Cremit stores, and who takes action.
Are all findings automatically verified?
No. Cremit checks validity with the issuing service for supported credential types. Other findings need manual review. A successful check says the key authenticated at that time; it does not prove someone misused it.
Where does Cremit look?
It scans sources you connect, including GitHub, GitLab, Bitbucket, GHCR images, AWS S3, Google Drive, Jira, Confluence, Notion and Slack. External scanning can check bounded public content when enabled for your organization. It cannot inspect a local file or an unconnected service.
Can I see what a live key can access?
Cremit can show access context for supported AWS access keys and GCP API keys. That context depends on the available analysis; a validity result alone does not show every permission or prove the key was used. Check issuer records and activity logs before judging impact.
Who rotates or revokes a leaked key?
The service owner does that at the issuer. Cremit records where a key was found, its available verification result and the response status. An assigned owner, a suggested candidate and a source-file author are different signals; the team confirms who should act. Cremit does not rotate or revoke keys automatically.
Does Cremit store my source code?
Cremit reads source content during a scan but does not retain whole source files. It stores finding metadata and the credential value encrypted with AWS KMS for supported re-verification. A customer-managed KMS key can be configured.
Can I start without a sales call?
Yes. The free plan at argus.cremit.io does not require a credit card. Connect a supported source and review its findings before choosing a paid plan.
Discovery, storage and sharing. One management approach.
From a key found in code to a credential used by your team. Cremit’s platform design connects the credential lifecycle. Talk to us about the right setup for your team.
Discuss your team’s setup01 / Discover
Discover and respond
Find exposed credentials across connected code, cloud storage and collaboration tools. Check validity for supported types and track owner response.
Credential inventory · Exposure detection · Validity checks · Response tracking
See the response flow02 / Store
Cremit Vault
A path from discovered credentials to managed credentials. The storage layer is designed around native Vault storage and existing vault integrations.
Native storage · Existing vault integrations · Credential migration
Review Vault storage03 / Share
Team credential hub
API keys and tokens for the people who need them, within the right scope. A shared workspace designed to connect team sharing, access permissions and usage history.
Team sharing · Access permissions · Usage history
Explore team sharing04 / Use
Developer and agent workflows
An access model that extends to developer tools and AI agents. The platform direction brings common credential controls to CLI, desktop and agent workflows.
CLI · Desktop · Agent access
Discuss your developer tools
Check for keys exposed outside your tools
Register a domain or GitHub organization. Cremit finds related public assets with evidence and can monitor supported discoveries unless you exclude them.
Content secret checks are separately enabled and bounded. Review what was actually scanned for each target.
Explore external scanningFind candidates
Review evidence for related domains, websites, IPs, apps and GitHub organizations.
Review the scope
Supported discovered assets can enter monitoring automatically. Exclude an asset that is outside your scope.
Review exposures
Review findings from monitored public assets alongside findings from connected sources.
Latest from our research

MCP Servers Are Taking API Keys Through the Chat Window
We sent one initialize request to every remote MCP server in the official registry. 71.3% of 22,027 responding servers opened a session with no header authentication, and 3,705 credential fields sit in tool arguments. Three of them are marked secret.

Unlisted, Not Private
A September 2026 sweep of 33 public surfaces confirmed 23,912 active credentials. Privilege context was established for 7,468; 1,277 had permission to issue another key. Actual re-issuance was not tested.

How to count live credentials without confusing matches and keys
Count observed locations, distinct credential records and verification states separately. Define scope and check time before reporting exposure.
Blast Radius: a field playbook for leaked API keys
Record where the key was exposed and preserve available logs without delaying containment. The six-phase AWS, GCP and Azure guide also compares versions of AWS's compromised-key quarantine policy.
What is non-human identity (NHI) security?
A non-human identity is a service account, workload principal or other software actor authenticated with a key, token, certificate or delegated grant. Securing it means knowing who controls it, what it can access and how to retire that access. A credential found outside its approved store is one signal to investigate.
Non-human identity: examples and security practicesWhat is Cremit?
Cremit Platform scans connected repositories, cloud storage and collaboration tools for exposed credentials. It checks current validity for supported types and adds available access context for supported AWS access keys and GCP API keys. A finding keeps its source location and ownership signals so a person can confirm who should respond at the issuer.
How many of your leaked keys still work?
Connect a scan source on the free plan and review exposed credentials. Supported types are checked against the issuing service, and results that need manual review are shown separately. No sales call needed.
Monthly NHI research brief
Security engineers and CISOs read our monthly brief on Non-Human Identity attacks, controls, and field research.

