Tokens 363/500 of daily quota Demo Analyst Administrator
Interactive demo — synthetic data, read-only. Nothing here is a real person or organisation. Request access →

Secrets & keys

API keys, cloud secrets and connection strings our scanner pulled from the downloaded files — categorized and risk-rated. AD/LDAP & database connections are flagged critical. Every source links to its file and machine.

18 secrets 6 critical 6 high 15 corporate 0 personal 9 confirmed live 14 machines
RiskCategorySecretHost / userOwnershipSourceStatus
medium 🗄️ Database connections my******** git.northwind-logistics.ex...
svc-deploy
🏢 corporate 🖥️ machine · 📄 config.env invalid
medium 🗄️ Database connections my******** admin.globex-financial.exa...
svc-deploy
🏢 corporate 🖥️ machine · 📄 config.env invalid
medium 🗄️ Database connections my******** api.acme-corp.example
svc-deploy
🏢 corporate 🖥️ machine · 📄 config.env invalid

⚖️ Validation runs client-side, never from this server. Click validate ⚡: for provider API keys (Google/AWS/Stripe/SendGrid/Slack/GitHub) the check runs in your browser where CORS allows; for raw-socket services (AD/LDAP, DB, FTP, SMTP, MQTT) and remote-access "connect" files (RDP/VNC/SSH/AnyDesk/TeamViewer) — which a browser can't open — you get the exact command to run from an authorized position on the client network, then record the outcome. Only validate targets you are authorized to test. Results (live / rejected / unreachable) are saved with a timestamp and the method used.