---
title: Choose your adventure
slug: docs
description: Compare TruffleHog Open Source and TruffleHog Enterprise. Both versions offer extensive scanning capabilities and a wide range of secret detectors for various platforms.
icon: {"faIcon":"fa-solid fa-map-location-dot"}
docTags: 
createdAt: 2024-05-15T00:25:13.622Z
---

::::LinkArray{contentSource="CUSTOM"}
:::LinkArrayItem{headerType="IMAGE" headerImage="https://api.archbee.com/api/optimize/S23bFlGfp3a-8_a9YY_cE/e3SRa79avBFd4b7-PJ5gA_screenshot-2024-05-15-at-55230-pm.png"}
[TruffleHog Open Source](https://github.com/trufflesecurity/trufflehog)
:::

:::LinkArrayItem{headerType="IMAGE" headerImage="https://api.archbee.com/api/optimize/S23bFlGfp3a-8_a9YY_cE/XrMFS72YC6SsEVSAxsAJS_screenshot-2026-08-17-at-75317-am.png"}
[TruffleHog Enterprise](docId\:thkH-gLbMuRKDWud7wbmh)
:::
::::

# What is TruffleHog 🐽

TruffleHog is the most powerful secrets **Discovery, Classification, Validation,** and **Analysis** tool. In this context secret refers to a credential a machine uses to authenticate itself to another machine. This includes API keys, database passwords, private encryption keys, and more...

## Discovery 🔍

TruffleHog can look for secrets in many places including Git, chats, wikis, logs, API testing platforms, object stores, filesystems and more

## Classification 📁

TruffleHog classifies over 800 secret types, mapping them back to the specific identity they belong to. Is it an AWS secret? Stripe secret? Cloudflare secret? Postgres password? SSL Private key? Sometimes its hard to tell looking at it, so TruffleHog classifies everything it finds.

## Validation ✅

For every secret TruffleHog can classify, it can also log in to confirm if that secret is live or not. This step is critical to know if there’s an active present danger or not.

## Analysis 🔬

For over 50 of the most commonly leaked out credential types, instead of sending one request to check if the secret can log in, TruffleHog can send many requests to learn everything there is to know about the secret. Who created it? What resources can it access? What permissions does it have on those resources?

## Comparison

|                                                          | **Open-source** | **Enterprise**   |
| -------------------------------------------------------- | --------------- | ---------------- |
| GitHub, S3, directory, GCS, and Docker scanning          | ✅               | ✅                |
| 800+ secret detectors                                    | ✅               | ✅                |
| GitHub actions, pre-commit, and pre-receive hooks        | ✅               | ✅                |
| Custom regex and secrets verification                    | ✅               | ✅                |
| Automatic updates                                        | ✅               | ✅                |
| Choice of on-premises and cloud scanning                 | ❌               | ✅                |
| 19+ Integrations (GitHub, Confluence, JIRA, Slack, More) | ❌               | ✅                |
| Continuous monitoring                                    | ❌               | ✅                |
| Intuitive dashboard                                      | ❌               | ✅                |
| Alerting                                                 | ❌               | ✅                |
| Monitor vast public datasets                             | ❌               | ✅                |
| Single sign-on: SAML 2.0 or OAuth 2.0                    | ❌               | ✅                |
| Role-based access control                                | ❌               | ✅                |
| Deployment and onboarding support                        | ❌               | ✅                |
| On-going priority technical support                      | ❌               | ✅                |
| Detailed analytics and reporting                         | ❌               | ✅                |

**Interested in Enterprise?&#x20;**[Contact us](https://trufflesecurity.com/contact)**&#x20;for a free trial.**

