AWS key pairs (verified via STS GetCallerIdentity with SigV4), Azure storage keys and SAS tokens, Google service-account JSON keys and billable-API detection for client keys.
Stripe live secret keys (balance check), PayPal-class payment tokens, Shopify admin tokens. Live keys here mean direct financial exposure.
OpenAI, Anthropic, DeepSeek-class keys, Slack workspace tokens, Telegram bot tokens, Twilio accounts, SendGrid senders, Mailgun domains.
npm publish tokens, PyPI upload tokens, Docker Hub PATs — the exact classes behind $14k–$31k bounty payouts and real package-takeover incidents.
MongoDB Atlas URIs, PostgreSQL/MySQL/Redis connection strings, Kubernetes service account tokens, private key blocks, Grafana service accounts.
Ownership attribution, duplicate collapsing across history, severity scoring with plain-English reasons, per-finding report drafts your team can act on immediately.
Client-side identifiers that ship inside every mobile/web app (Firebase API keys),
Microsoft's documented emulator constants, tutorial tokens, .env.example files,
docstring examples, vendored dependencies, expired JWTs, planted credential-corpus repos.
This is where other tools generate 90% of their noise — and it's filtered before you ever see it.