Repository secret scanner
LiveFind the leaked secret.
Scan a repository or package for live tokens, cloud keys, private keys, and database URIs, surfaced from source with line-level evidence, so you can rotate before it is abused.
✓Tokens, keys, URIs✓Line-level evidence✓Free to start
Product preview
Repository security
See Dralvia in action.
Review source packages for SBOM, secret, dependency, and provenance risks in one workflow.
- Submit a supported repository package
- Track the review
- Export evidence into existing AppSec workflows
This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

What it does
Catch credentials before attackers do.
Broad secret coverage
Cloud keys, API tokens, private keys, webhook URLs, and database connection strings.
Line-level evidence
Exactly where each secret appears, so you can rotate and remove it.
Yours or a dependency's
Use it for "did we commit this?" and "is this package leaking?"
FAQ
Honest answers.
No, analysis is static, safe to run in CI.
Run a free check now.
No account needed for your first scan. See the verdict and the evidence behind it.
Read the research