Vigil watches GitHub for leaked API keys, tokens and credentials tied to your company and your employees — verifies them live against the provider, attributes every leak to its owner, and alerts you in minutes. Not thousands of false positives: only what actually works.
Most scanners hand you a flat list of regex matches. Vigil answers the three questions that matter: does it work, whose is it, and what should you do now.
Every candidate is probed read-only against its provider (AWS STS, Stripe balance, Slack auth…). If it doesn't authenticate, you never see it.
Documented dummy keys, sample files, test fixtures, vendored code and expired JWTs are eliminated before they ever reach your queue.
Leaks are mapped to your organization and employee accounts via commit emails, repo ownership and content signals — so you know who to call.
Continuous polling of your tracked orgs, employees and domains. New pushes are scanned within minutes, not on weekly cron jobs.
Slack-style webhooks, Discord and Telegram delivery the moment a verified secret appears — with repo, file, line and commit links.
Verification is strictly read-only. We never send messages, spend credits or mutate anything. Secrets are masked at rest in every view by default.
A live look at verified leaks Vigil surfaced — masked before display, always.
Add the GitHub organizations, users and domains you want protected. Employee discovery maps personal accounts to your company automatically.
Every repo, every branch, full history including force-pushed commits, gists included — with our zero-FP filter chain applied to each candidate.
Only credentials that authenticate at the provider reach you, attributed to an owner, ranked by impact, with one-click rotation guidance.
Trusted positioning for security teams: continuous, verified, attributed.
Start free trial →