continuous monitoring active · full git history incl. force-pushed commits

Find exposed secrets
before attackers do

Vigil watches GitHub for leaked API keys, tokens and credentials tied to your company and your employees — verifies them live against the provider, attributes every leak to its owner, and alerts you in minutes. Not thousands of false positives: only what actually works.

no credit card required · cancel anytime · self-host option available
27+
credential types
100%
verified-only mode
<5 min
leak-to-alert time
0
noise tolerance
why vigil

Built different from day one

Most scanners hand you a flat list of regex matches. Vigil answers the three questions that matter: does it work, whose is it, and what should you do now.

🎯

Verified, not guessed

Every candidate is probed read-only against its provider (AWS STS, Stripe balance, Slack auth…). If it doesn't authenticate, you never see it.

🧹

Zero-false-positive pipeline

Documented dummy keys, sample files, test fixtures, vendored code and expired JWTs are eliminated before they ever reach your queue.

👤

Employee & org attribution

Leaks are mapped to your organization and employee accounts via commit emails, repo ownership and content signals — so you know who to call.

Real-time watch

Continuous polling of your tracked orgs, employees and domains. New pushes are scanned within minutes, not on weekly cron jobs.

🔔

Instant alerting

Slack-style webhooks, Discord and Telegram delivery the moment a verified secret appears — with repo, file, line and commit links.

🔒

Safe by design

Verification is strictly read-only. We never send messages, spend credits or mutate anything. Secrets are masked at rest in every view by default.

live feed · anonymized previews

Secrets caught in the wild

A live look at verified leaks Vigil surfaced — masked before display, always.

KEYS VERIFIED LIVE -----...--- (27 chars)… detected
KEYS VERIFIED LIVE -----...--- (31 chars)… detected
KEYS VERIFIED LIVE -----...--- (27 chars)… detected
REDIS VERIFIED LIVE redis...baz (47 chars)… detected
TELEGRAM VERIFIED LIVE 76206...ZrI (46 chars)… detected
POSTGRES VERIFIED LIVE postg...345 (44 chars)… detected
how it works

Up and running in minutes

1

Connect your scope

Add the GitHub organizations, users and domains you want protected. Employee discovery maps personal accounts to your company automatically.

2

Vigil scans everything

Every repo, every branch, full history including force-pushed commits, gists included — with our zero-FP filter chain applied to each candidate.

3

You get verified alerts

Only credentials that authenticate at the provider reach you, attributed to an owner, ranked by impact, with one-click rotation guidance.

Stop hoping nothing leaks.
Know within minutes when it does.

Trusted positioning for security teams: continuous, verified, attributed.

Start free trial →