Secret scanning for GitHub repos
Paste a repository URL and get every exposed API key, credential, and private key in seconds. No signup. Your code is never stored.
One request in, one report out. Built for solo developers and small teams who don't have time for enterprise security theater.
We pull only the latest snapshot of your repo into an isolated temp directory. Private repos supported on Pro with a scoped token.
AWS, GitHub, Stripe, Slack, OpenAI keys, private keys, database URLs and more — with false-positive filtering so you're not chasing placeholders.
You get findings with file, line, and severity. The clone is deleted immediately. Nothing about your code is retained.
Start free. Upgrade when you need private repos or CI-scale usage. Cancel anytime.
Free
$0
Pro
$9 /month
A security tool has to hold itself to a higher bar. Here is exactly how we handle your data.
No. The repo is shallow-cloned into an isolated temporary directory, scanned, and deleted immediately — even if the scan fails. We store only the findings metadata you see in the report.
On Pro, pass a fine-grained GitHub token with read-only access to the repo. It's used once for the clone and never persisted. We recommend a token scoped to a single repository with a short expiry.
Checkout is handled by Lemon Squeezy. You receive a license key by email instantly — that key is your API key. Use it in the X-API-Key header or paste it here on the site.
Yes. Pro includes API access — call POST /v1/scan from any pipeline and fail the build if criticals are found. Docs are available at api.minimalsecops.com/docs.
Please email security@minimalsecops.com. We read every report and credit responsible disclosure.