Tokens 363/500 of daily quota Demo Analyst Administrator
Interactive demo — synthetic data, read-only. Nothing here is a real person or organisation. Request access →

Secrets & keys

API keys, cloud secrets and connection strings our scanner pulled from the downloaded files — categorized and risk-rated. AD/LDAP & database connections are flagged critical. Every source links to its file and machine.

18 secrets 6 critical 6 high 15 corporate 0 personal 9 confirmed live 14 machines
RiskCategorySecretHost / userOwnershipSourceStatus
medium ☁️ Cloud & SaaS keys
google
AI******** api.northwind-logistics.ex...
svc-deploy
🖥️ machine · 📄 config.env ✓ live
medium ☁️ Cloud & SaaS keys
google
AI******** owa.globex-financial.examp...
svc-deploy
🖥️ machine · 📄 config.env invalid
medium ☁️ Cloud & SaaS keys
google
AI******** vpn.acme-corp.example
svc-deploy
🖥️ machine · 📄 config.env ✓ live

⚖️ Validation runs client-side, never from this server. Click validate ⚡: for provider API keys (Google/AWS/Stripe/SendGrid/Slack/GitHub) the check runs in your browser where CORS allows; for raw-socket services (AD/LDAP, DB, FTP, SMTP, MQTT) and remote-access "connect" files (RDP/VNC/SSH/AnyDesk/TeamViewer) — which a browser can't open — you get the exact command to run from an authorized position on the client network, then record the outcome. Only validate targets you are authorized to test. Results (live / rejected / unreachable) are saved with a timestamp and the method used.