Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure

API keys and tokens,
from discovery to sharing.

NHI security for the credentials your teams and workloads use. Find exposed keys, check supported types and assign a response owner. Plan storage and sharing around the way your team works.

Start for free

2 GB of free scanning each month · No credit card required

Teams using Cremit

  • Next Securities
  • Rapportlabs
  • 8Percent
  • ENlighten
  • SBSi
  • Ordercheck
  • Spoonlabs
  • TVING

Is the key still active? Who will respond?

Review where a key was found, check supported credentials and assign a response owner. Follow one key from discovery through revocation and a follow-up check in the actual interface.

Follow one key through the response
AWS Access Key
AWSValidNot in a connected vault
aws_access_key_id: EXAMPLE••••••••••••
aws_secret_access_key: ••••••••••••••••
Owner
Example owner
security@example.com
Assigned
Actual product UI with fictional records. Verification results and owner assignments are illustrative values. View full example
  1. 01

    Return to the source

    Review the detected location and its evidence before deciding how to respond.

  2. 02

    Check the verification result

    Supported types can be checked for validity. A missing result stays unverified.

  3. 03

    Confirm who will respond

    Distinguish author candidates from assigned owners, then track the response.

  • 1,000+

    Credential detection rules

    A match still needs review; it does not prove the key works.

  • 10

    Supported scan source types

    Coverage depends on the sources you connect.

  • ~6h

    Recheck interval for active keys

    Applies to supported keys last confirmed active.

In customers’ words

Customers describe their work with Cremit. Read their stories for the details.

See all customer stories
  • Next Securities
    Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive.

    Jeongcheol Kang

    Security Engineer · Next Securities

    Read the customer story
  • Rapportlabs
    As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount.

    Jihoon Gong

    Compliance Security Engineer · Rapportlabs

    Read the customer story
  • 8Percent
    Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive.

    Daeyoung Jeong

    Security Team Leader · 8Percent

    Read the customer story
  • ENlighten
    As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit.

    Jinseok Yeo

    Security Engineer · ENlighten

    Read the customer story
  • SBSi
    As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day.

    Name withheld

    Security Manager · SBSi

    Read the customer story
  • Ordercheck
    As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.

    Woongab Jeong

    CEO, Founder · Ordercheck

    Read the customer story

Plans and pricing

Start with 2 GB a month. No card required.

See findings from your own environment on the free plan. Compare monthly pricing and included scan volume before you commit.

Before you connect

Required permissions

Choose a source and review its access scope and setup instructions.

Integration guides
Stored data

Cremit does not retain entire scanned source files. Detected credentials are stored encrypted using AWS KMS.

How data is handled
Disconnection and deletion

Disconnecting a source and deleting existing records are separate steps. Review retention and deletion by data type.

Retention and deletion

Before you connect a source

Check what a finding proves, what Cremit stores, and who takes action.

Are all findings automatically verified?

No. Cremit checks validity with the issuing service for supported credential types. Other findings need manual review. A successful check says the key authenticated at that time; it does not prove someone misused it.

Where does Cremit look?

It scans sources you connect, including GitHub, GitLab, Bitbucket, GHCR images, AWS S3, Google Drive, Jira, Confluence, Notion and Slack. External scanning can check bounded public content when enabled for your organization. It cannot inspect a local file or an unconnected service.

Can I see what a live key can access?

Cremit can show access context for supported AWS access keys and GCP API keys. That context depends on the available analysis; a validity result alone does not show every permission or prove the key was used. Check issuer records and activity logs before judging impact.

Who rotates or revokes a leaked key?

The service owner does that at the issuer. Cremit records where a key was found, its available verification result and the response status. An assigned owner, a suggested candidate and a source-file author are different signals; the team confirms who should act. Cremit does not rotate or revoke keys automatically.

Does Cremit store my source code?

Cremit reads source content during a scan but does not retain whole source files. It stores finding metadata and the credential value encrypted with AWS KMS for supported re-verification. A customer-managed KMS key can be configured.

Can I start without a sales call?

Yes. The free plan at argus.cremit.io does not require a credit card. Connect a supported source and review its findings before choosing a paid plan.

See all questions

Discovery, storage and sharing. One management approach.

From a key found in code to a credential used by your team. Cremit’s platform design connects the credential lifecycle. Talk to us about the right setup for your team.

Discuss your team’s setup
  1. 01 / Discover

    Discover and respond

    Find exposed credentials across connected code, cloud storage and collaboration tools. Check validity for supported types and track owner response.

    Credential inventory · Exposure detection · Validity checks · Response tracking

    See the response flow
  2. 02 / Store

    Cremit Vault

    A path from discovered credentials to managed credentials. The storage layer is designed around native Vault storage and existing vault integrations.

    Native storage · Existing vault integrations · Credential migration

    Review Vault storage
  3. 03 / Share

    Team credential hub

    API keys and tokens for the people who need them, within the right scope. A shared workspace designed to connect team sharing, access permissions and usage history.

    Team sharing · Access permissions · Usage history

    Explore team sharing
  4. 04 / Use

    Developer and agent workflows

    An access model that extends to developer tools and AI agents. The platform direction brings common credential controls to CLI, desktop and agent workflows.

    CLI · Desktop · Agent access

    Discuss your developer tools

Check for keys exposed outside your tools

Register a domain or GitHub organization. Cremit finds related public assets with evidence and can monitor supported discoveries unless you exclude them.

Content secret checks are separately enabled and bounded. Review what was actually scanned for each target.

Explore external scanning

Find candidates

Review evidence for related domains, websites, IPs, apps and GitHub organizations.

Review the scope

Supported discovered assets can enter monitoring automatically. Exclude an asset that is outside your scope.

Review exposures

Review findings from monitored public assets alongside findings from connected sources.

New research · September 2026

Blast Radius: a field playbook for leaked API keys

Record where the key was exposed and preserve available logs without delaying containment. The six-phase AWS, GCP and Azure guide also compares versions of AWS's compromised-key quarantine policy.

Read the playbook NHI Kill Chain series
Free PDF · English & Korean · No form

What is non-human identity (NHI) security?

A non-human identity is a service account, workload principal or other software actor authenticated with a key, token, certificate or delegated grant. Securing it means knowing who controls it, what it can access and how to retire that access. A credential found outside its approved store is one signal to investigate.

Non-human identity: examples and security practices

What is Cremit?

Cremit Platform scans connected repositories, cloud storage and collaboration tools for exposed credentials. It checks current validity for supported types and adds available access context for supported AWS access keys and GCP API keys. A finding keeps its source location and ownership signals so a person can confirm who should respond at the issuer.

How many of your leaked keys still work?

Connect a scan source on the free plan and review exposed credentials. Supported types are checked against the issuing service, and results that need manual review are shown separately. No sales call needed.

Newsletter

Monthly NHI research brief

Security engineers and CISOs read our monthly brief on Non-Human Identity attacks, controls, and field research.

We never sell your email. Unsubscribe anytime.