Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure

An exposed key.
Still active?

Find exposed keys, verify supported keys, review AWS or GCP access, and track owner action.

See the product tour, no sales call
One key. Four checks.Example

AWS access key

AKIA••••••••4F8K

Found in

GitHub

  1. 01
    DiscoveryExposed on GitHub

    Found in a repository config file

  2. 02
    VerificationStill active

    Check the current status of a supported key type

  3. 03
    Access contextAWS permissions

    Review the IAM user and attached policies

  4. 04
    ResponseConfirm owner

    Track key rotation and remediation

Illustrative example: find an exposed key, verify a supported type, review AWS access context, and track owner action.

Teams using Cremit

Next Securities
Rapportlabs
8Percent
ENlighten
SBSi
Ordercheck
Spoonlabs
TVING
Next Securities
Rapportlabs
8Percent
ENlighten
SBSi
Ordercheck
Spoonlabs
TVING
Next Securities
Rapportlabs
8Percent
ENlighten
SBSi
Ordercheck
Spoonlabs
TVING
Next Securities
Rapportlabs
8Percent
ENlighten
SBSi
Ordercheck
Spoonlabs
TVING
1,000+

Credential types detected and verified

10

Sources scanned, connected in minutes

6h

Approximate re-verification cycle for live secrets

In plain terms

What is non-human identity (NHI) security?

Non-human identities (NHIs) are credentials software uses to access other services, including API keys, service accounts and tokens. NHI security means knowing where those credentials are, who owns them and whether exposed keys still work, then getting them rotated or revoked.

What is Cremit?

Cremit Platform finds exposed credentials in connected sources including GitHub, GitLab, AWS S3, Google Drive, Slack, Jira, Confluence and Notion. It checks verifiable keys with their issuing services and shows the location and owner of live findings. Cremit was founded in Seoul in 2023.

How Cremit works

  1. 01

    Connect a source.

    Link GitHub, GitLab, AWS S3, Google Drive, Slack, Jira, Confluence or Notion with OAuth or a token. No agents to install.

  2. 02

    Scan and verify.

    Scan files, commit history, documents and messages for credential patterns. Check verifiable keys with the issuing service to see if they still work.

  3. 03

    Fix live keys first.

    Live findings are ranked and sent to Slack, a webhook, Telegram or email with location and owner context. You rotate or revoke; Cremit Platform re-verifies until the key no longer works.

From discovery to incident response

Find keys in connected sources, check whether they work, review AWS and GCP access, and route findings to the people who can act.

Free plan to start, no credit card. Enterprise pricing on request.

Connect the tools you already use

Connect GitHub, GitLab, Bitbucket, AWS S3, Google Drive, Slack, Jira, Confluence and Notion. Review credentials found across these sources in one inventory.

IntegrationsAll Systems Operational
GitHub
Connected
124 Repos
AWS S3
Connected
52 Buckets
Slack
Connected
14 Workspaces
Notion
Connected
890 Pages
Confluence
Connected
Syncing...
Indexing assets...
Illustrative

Screenshots show illustrative data, not customer metrics.

Check for keys exposed outside your tools

Register a domain or GitHub organization. Cremit suggests related external assets with evidence, and scans public pages only after your team approves the targets.

The scan reads a bounded set of public HTML, JavaScript and JSON on approved assets. Cremit enables external scanning for each organization.

Explore external scanning

Find candidates

Review evidence for related domains, websites, IPs, apps and GitHub organizations.

Approve the scope

Your team chooses which candidates belong in scope. Unapproved assets are not scanned.

Review exposures

See credentials found on approved public assets alongside your existing findings and incidents.

What customers say

See what customers say about finding and verifying leaked credentials with Cremit.

SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
Rapportlabs

"As a solo security lead at a growing commerce company, I couldn't keep up with credential management across all our platforms. Cremit gave me the visibility and automation I needed to do my job effectively — without asking for more headcount."

Jihoon Gong
Compliance Security Engineer
ENlighten

"As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit."

Jinseok Yeo
Security Engineer
SBSi

"As media infrastructure moves to the cloud, credential management becomes exponentially more complex. Cremit gave us the visibility we needed to secure our GitLab environment and protect the cloud infrastructure that serves millions of viewers every day."

OOO
Security Manager
Next Securities

"Traditional vendors communicate via email or phone, but with Cremit we can quickly reach out through Slack Connect. Having a feature request implemented in just 15 minutes was truly impressive."

Jeongcheol Kang
Security Engineer
8Percent

"Before Cremit, we had no way of knowing where or how many credentials were exposed across our systems. Within a single day of deployment, we gained complete visibility into our entire environment, and every alert was a real threat — not a single false positive."

Daeyoung Jeong
Security Team Leader
Ordercheck

""As a startup CEO wearing multiple hats, I didn't have time to manually check for exposed credentials. Cremit found AWS keys I didn't even know were at risk and let me secure them before anything happened.""

Woongab Jeong
CEO, Founder
New research · September 2026

Blast Radius: a field playbook for leaked API keys

When a key leaks, most teams delete it first. That is the moment the evidence of where it reached disappears. Six phases for AWS, GCP and Azure, with a version-by-version diff of AWS's compromised-key quarantine policy.

Read the playbook NHI Kill Chain series
Free PDF · English & Korean · No form
FAQ

Frequently asked questions

Short answers to what people ask before starting on the free plan. The full list is on the FAQ page.

What is non-human identity (NHI) security?

NHI security is finding, verifying and controlling the credentials machines use to authenticate, such as API keys, service accounts, tokens and SSH keys. Because these identities usually have no owner, expiry or MFA, a leaked one can stay usable for months, so the work is to inventory them, detect exposure, confirm which exposed credentials still work, and rotate or revoke them.

What does Cremit detect?

Cremit detects exposed credentials: cloud access keys for AWS, GCP and Azure, API keys and OAuth tokens for third-party services, database connection strings, SSH private keys and similar secrets, in source code, git history, documents, chat messages, cloud storage, and the public pages of external assets you approve. It does not classify general sensitive data such as PII or business documents.

How does Cremit know whether a leaked key still works?

Findings of supported types are checked against the service that issued the credential; types without an automatic check are marked for manual review. A key that still authenticates is marked live and ranked first; one that has been revoked or has expired is recorded but not raised as an incident. This verification step is what removes most of the noise a pattern-only scanner produces.

Which sources can Cremit scan?

Scan sources are GitHub, GitLab, Bitbucket, GitHub Packages (GHCR images), AWS S3, Google Drive, Jira, Confluence, Notion and Slack (messages and attachments). AWS (via CloudFormation) and GCP (via a service account) are connected for permission analysis. Alerts are delivered to Slack, a webhook, Telegram or email, and the platform supports SAML 2.0 / OIDC SSO, SCIM 2.0 provisioning (e.g. Okta) and Google Workspace directory sync.

Does Cremit store my source code?

No. Files are read during a scan and are not retained. Cremit keeps each finding's location, secret type and verification status, plus the credential value itself encrypted with AWS KMS (optionally your own customer-managed key), because re-verification needs it.

How do I get started, and is there a free plan?

Sign up at argus.cremit.io on the free plan, no credit card, and connect your first source with a GitHub App, OAuth or a CloudFormation template. The first scan starts right away and any credential that is verified live goes to the top of the list. Paid and enterprise plans are available on request.

How many of your leaked keys
still work?

Connect a scan source on the free plan and review exposed credentials. Supported types are checked against the issuing service, and results that need manual review are shown separately. No sales call needed.

Newsletter

Monthly NHI research brief

Security engineers and CISOs read our monthly brief on Non-Human Identity attacks, controls, and field research.

We never sell your email. Unsubscribe anytime.