Skip to content
LyraShield AIOpen beta

Protect data and access

Secret Exposure Scanner

This browser-local secret scanner checks up to 20 selected text files for high-confidence credential patterns and shows redacted matches so you can rotate a real exposure.

Local analyzer: Runs entirely in this browser. Files never leave your device.

Run the checkLocal · nothing uploaded

Files over 1 MB and non-text files are skipped. Matches are redacted before display.

What this checks

  • Common OpenAI-compatible, AWS, GitHub, Stripe, Supabase, and Google credential formats
  • Private-key blocks and assigned API keys, tokens, client secrets, or passwords
  • Duplicate matches, with likely secret values redacted before display

What this cannot prove

  • It checks only the text files you select, skips non-text files, and limits each file to 1 MB
  • Pattern matching can miss custom formats and can flag test or example values
  • It does not scan Git history, deployed bundles, logs, cloud stores, or already leaked credentials

Primary references

Use these standards and vendor references when you investigate a result. A link does not imply certification or full coverage of the source.

Need an app-wide assurance record?

LyraShield AI adds authorized target scanning, explicit coverage receipts, evidence states, approval-gated fix proposals, server-owned retests, and immutable reports. This browser tool remains guidance, not a security guarantee.

Get product updates

Frequently asked questions

Does this upload my input?

Files never leave your device.

Does a clear result mean my app is secure?

No. Each result is limited to the checks shown here. Use it as a next-step guide, then test the relevant application path.