TRUFFLEHOG

COMPANY

RESOURCES

CUSTOMER STORY · TRUFFLEHOG ENTERPRISE

Optro expands secrets detection across code, collaboration tools, and application logs

Optro needed a consistent way to detect exposed credentials beyond source code, including collaboration systems and application logs. TruffleHog Enterprise expanded that coverage across the environment and connected findings to the security operations workflows the team already uses to investigate and respond.

“A lot of the time all it takes is a public repo with credentials being leaked to take down an entire organization and take down your millions of dollars that you put into your security stack just because of one commit.”

Steven Seguinot Alvarez, Security Engineer, Optro

CUSTOMER SNAPSHOT

INDUSTRY

Compliance SaaS

DEVELOPERS

~400

TEAM

Security engineering

CUSTOMER SINCE

2 years

HOW OPTRO USES TRUFFLEHOG ENTERPRISE

Scans beyond repositories

Covers source code, Jira, Slack, and S3 application logs.

Feeds existing SecOps workflows

Findings move into Tines for investigation and response.

Keeps risk visible to leadership

Credential exposures and remediation activity are reviewed in a weekly event review.

01 · THE CHALLENGE

Expanding credential visibility across the environment

Optro needed a dedicated way to detect exposed credentials across more of its environment. Source code was only part of the risk surface. Credentials could also appear in collaboration systems and application logs, where they were harder to identify consistently.

Because Optro handles sensitive customer information, the security team wanted to surface those exposures quickly and reduce the chance that a leaked credential could create a larger incident.

02 · WHAT CHANGED

Detection reached the places credentials can actually surface

Optro chose TruffleHog Enterprise for the breadth of its detectors and integrations. The team scans source code, Jira, Slack, and S3, with a self-hosted scanner covering the bucket where application logs are stored.

That coverage matters because an application misconfiguration can write a credential into a log even when the source itself is clean. Findings also feed a weekly event review shared with executive leadership, keeping both exposures and remediation work visible.

“Compared to before where we had no detection capabilities, to now being able to scan Jira, Slack, source code, and S3 where we have our application logs, it’s been a huge difference.”

Steven Seguinot Alvarez, Security Engineer, Optro

03 · IN PRACTICE

Customer credentials landed in a public repository

TruffleHog Enterprise alerted Optro to a file in a public-facing repository containing several credentials associated with a customer instance. The security team identified the application owner, began remediation, and revoked and rotated the affected credentials.

The incident demonstrated the role dedicated secrets detection can play alongside Optro’s existing controls: surfacing an exposure quickly and giving the team a clear finding to investigate and remediate.

04 · OUTCOME

Security controls that match the product promise

Because Optro helps customers manage compliance and risk, the company places particular importance on maintaining strong controls in its own environment. TruffleHog Enterprise gives the team consistent credential detection across multiple systems and a direct path from finding to response.

“If we’re going to help our customers with compliance, we’ve got to be compliant ourselves. We’ve got to set the example.”

Steven Seguinot Alvarez, Security Engineer, Optro

KEY TAKEAWAYS

What TruffleHog Enterprise gave Optro

Hundreds of exposed credentials surfaced

Over two years, the team estimates TruffleHog Enterprise has identified hundreds of credentials that required review or remediation.

Coverage reaches application logs

A self-hosted scanner checks the S3 bucket where logs land, extending detection beyond what developers commit.

Findings flow into SecOps

TruffleHog Enterprise alerts feed into Tines and the team’s broader response automation instead of becoming another standalone queue.

Find exposed credentials before they become a bigger problem.

See how TruffleHog Enterprise helps security teams turn exposed credentials into actionable security signals.

infra