Secrets scanning detects credentials that leak into places they should not be: API keys, database passwords, cloud tokens, and certificates committed to repositories, embedded in pipeline definitions, or pasted into configuration. A leaked secret is an incident, not a finding — it must be revoked, not just fixed forward.
How detection works
Scanners combine high-precision patterns for known credential formats (cloud keys have recognizable shapes), entropy analysis for random-looking strings, and validity checking — testing whether a candidate credential actually authenticates — to separate live leaks from noise.
Where to catch secrets
- Pre-commit and PR: the cheapest catch — the secret never lands in history.
- Repository history: secrets committed long ago remain live until rotated.
- Pipeline surfaces: variable groups, service connections, and logs leak too — not just code.
Why the estate view matters
A secrets program that scans some repositories is a false comfort: attackers enumerate everything. Coverage — every repo, every new pipeline, by default — is the property that makes secrets scanning meaningful.

