TruffleHog™ uncovers exposed non-human identities (NHIs) and their secrets, making it easier for security teams to prioritize risk and remediate faster.
Millions of leaked secrets
Millions NHIs and its secrets, including API keys, passwords, and tokens, are frequently leaking from sources like source code, chat systems, support tickets, and more, underscoring the need for robust secret leak detection.
TruffleHog digs deep
TruffleHog scans for sensitive credentials beyond the source code to include hidden content, deleted code, and version history from GitHub, Google Cloud, Slack, and more commonly used tools across your company.
Over 250K daily runs by developers and security teams
With over 250,000 daily runs and 23,000 GitHub stars, TruffleHog is relied on by thousands of developers and security teams every day.
TruffleHog Enterprise extends that same trusted engine with enterprise-grade visibility, verification, and collaboration tools to help teams manage NHI and their secrets.
250K+
Daily runs
23K+
GitHub stars

Optro expands secrets detection across code, collaboration tools, and application logs
“If we’re going to help our customers with compliance, we’ve got to be compliant ourselves. We’ve got to set the example.”
Steven Seguinot Alvarez, Security Engineer, Optro
See how Optro detects exposed credentials across source code, Jira, Slack, and S3 application logs — and routes findings into its SecOps workflows.
Read the case study

TextNow catches exposed credentials before landing in production
“That’s one thing I don’t have to worry about right now.”
Andrew Cotton, Head of Security, Compliance, and IT, TextNow
See how TextNow finds exposed credentials across source code, Jira, and Confluence — and confirms they’re rotated before closing the incident.
Read the case study
Klaviyo cuts through the noise with TruffleHog Enterprise
“TruffleHog doesn’t just tell us there’s a secret; it identifies what it is and where it came from. That makes the data actionable and builds genuine trust with our developers.”
Dominic Bunch, Security Engineering Manager
See how Klaviyo eliminated false alerts and used actionable context to remediate 200+ high-impact secrets.
Read the case study
←
→


