Protect data and access
Secret Exposure Scanner
This browser-local secret scanner checks up to 20 selected text files for high-confidence credential patterns and shows redacted matches so you can rotate a real exposure.
Local analyzer: Runs entirely in this browser. Files never leave your device.
Files over 1 MB and non-text files are skipped. Matches are redacted before display.
What this checks
- Common OpenAI-compatible, AWS, GitHub, Stripe, Supabase, and Google credential formats
- Private-key blocks and assigned API keys, tokens, client secrets, or passwords
- Duplicate matches, with likely secret values redacted before display
What this cannot prove
- It checks only the text files you select, skips non-text files, and limits each file to 1 MB
- Pattern matching can miss custom formats and can flag test or example values
- It does not scan Git history, deployed bundles, logs, cloud stores, or already leaked credentials
Primary references
Use these standards and vendor references when you investigate a result. A link does not imply certification or full coverage of the source.
Need an app-wide assurance record?
LyraShield AI adds authorized target scanning, explicit coverage receipts, evidence states, approval-gated fix proposals, server-owned retests, and immutable reports. This browser tool remains guidance, not a security guarantee.
Get product updatesFrequently asked questions
Does this upload my input?
Files never leave your device.
Does a clear result mean my app is secure?
No. Each result is limited to the checks shown here. Use it as a next-step guide, then test the relevant application path.