Repository secret scanner
Live

Find the leaked secret.

Scan a repository or package for live tokens, cloud keys, private keys, and database URIs, surfaced from source with line-level evidence, so you can rotate before it is abused.

✓Tokens, keys, URIs✓Line-level evidence✓Free to start
Product preview

Repository security

See Dralvia in action.

Review source packages for SBOM, secret, dependency, and provenance risks in one workflow.

  • Submit a supported repository package
  • Track the review
  • Export evidence into existing AppSec workflows

This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Dralvia Repository Risk Scanner workspace preview
Product preview · Repository Risk Scanner
What it does

Catch credentials before attackers do.

Broad secret coverage

Cloud keys, API tokens, private keys, webhook URLs, and database connection strings.

Line-level evidence

Exactly where each secret appears, so you can rotate and remove it.

Yours or a dependency's

Use it for "did we commit this?" and "is this package leaking?"

FAQ

Honest answers.

No, analysis is static, safe to run in CI.

Run a free check now.

No account needed for your first scan. See the verdict and the evidence behind it.