Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive.
An exposed key.
Still active?
Find exposed keys, verify supported keys, review AWS or GCP access, and track owner action.
See how the product worksAWS access key
AKIA••••••••4F8K
Found in
GitHub
- 01DiscoveryExposed on GitHub
Found in a repository config file
- 02VerificationStill active
Check the current status of a supported key type
- 03Access contextAWS permissions
Review the IAM user and attached policies
- 04ResponseConfirm owner
Track key rotation and remediation
Teams using Cremit
1,000+
Credential detection rules
A match still needs review; it does not prove the key works.
10
Supported scan source types
Coverage depends on the sources you connect.
~6h
Recheck interval for active keys
Applies to supported keys last confirmed active.
What is non-human identity (NHI) security?
A non-human identity is a service account, workload principal or other software actor authenticated with a key, token, certificate or delegated grant. Securing it means knowing who controls it, what it can access and how to retire that access. A credential found outside its approved store is one signal to investigate.
What is Cremit?
Cremit Platform scans connected repositories, cloud storage and collaboration tools for exposed credentials. It checks current validity for supported types and adds available access context for supported AWS access keys and GCP API keys. A finding keeps its source location and ownership signals so a person can confirm who should respond at the issuer.
From discovery to incident response
Find keys in connected sources, check whether they work, review AWS and GCP access, and route findings to the people who can act.
Connect the tools you already use
Connect GitHub, GitLab, Bitbucket, AWS S3, Google Drive, Slack, Jira, Confluence and Notion. Review credentials found across these sources in one inventory.
Evidence flow · diagram
Keep the source with the finding
Connected source
GitHub repository
One example of a supported source
Finding
AWS access key
The credential is displayed in masked form
Location
File and commit details
Link back to the source for investigation
The available location details vary by source.
A conceptual diagram, not a product screenshot or customer data. Available fields depend on the integration and key type.
Check for keys exposed outside your tools
Register a domain or GitHub organization. Cremit finds related public assets with evidence and can monitor supported discoveries unless you exclude them.
Content secret checks are separately enabled and bounded. Review what was actually scanned for each target.
Explore external scanningFind candidates
Review evidence for related domains, websites, IPs, apps and GitHub organizations.
Review the scope
Supported discovered assets can enter monitoring automatically. Exclude an asset that is outside your scope.
Review exposures
Review findings from monitored public assets alongside findings from connected sources.
In customers’ words
Customers describe their work with Cremit. Read their stories for the details.
As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount.
Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive.
As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit.
As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day.
As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.
Latest from our research

When an exposed credential has no clear owner
How to verify, investigate, assign, and replace an exposed credential when the service owner is unclear.

Eight credential exposure patterns and how to respond
A practical summary of eight NHI credential exposure patterns, the evidence to check, and what Cremit Platform can help investigate.

How to find hidden credentials in code and shared tools
A practical workflow for preventing, finding, verifying, and replacing exposed credentials across code and shared tools.
Blast Radius: a field playbook for leaked API keys
Record where the key was exposed and preserve available logs without delaying containment. The six-phase AWS, GCP and Azure guide also compares versions of AWS's compromised-key quarantine policy.
Before you connect a source
Check what a finding proves, what Cremit stores, and who takes action.
Are all findings automatically verified?
No. Cremit checks validity with the issuing service for supported credential types. Other findings need manual review. A successful check says the key authenticated at that time; it does not prove someone misused it.
Where does Cremit look?
It scans sources you connect, including GitHub, GitLab, Bitbucket, GHCR images, AWS S3, Google Drive, Jira, Confluence, Notion and Slack. External scanning can check bounded public content when enabled for your organization. It cannot inspect a local file or an unconnected service.
Can I see what a live key can access?
Cremit can show access context for supported AWS access keys and GCP API keys. That context depends on the available analysis; a validity result alone does not show every permission or prove the key was used. Check issuer records and activity logs before judging impact.
Who rotates or revokes a leaked key?
The service owner does that at the issuer. Cremit records where a key was found, its available verification result and the response status. An assigned owner, a suggested candidate and a source-file author are different signals; the team confirms who should act. Cremit does not rotate or revoke keys automatically.
Does Cremit store my source code?
Cremit reads source content during a scan but does not retain whole source files. It stores finding metadata and the credential value encrypted with AWS KMS for supported re-verification. A customer-managed KMS key can be configured.
Can I start without a sales call?
Yes. The free plan at argus.cremit.io does not require a credit card. Connect a supported source and review its findings before choosing a paid plan.
How many of your leaked keys
still work?
Connect a scan source on the free plan and review exposed credentials. Supported types are checked against the issuing service, and results that need manual review are shown separately. No sales call needed.
Monthly NHI research brief
Security engineers and CISOs read our monthly brief on Non-Human Identity attacks, controls, and field research.
