
TRUFFLEHOG ANALYZE
SaaS
SaaS
Understand the impact of leaked SaaS secrets
Understand the impact of your secrets
TruffleHog Analyze for SaaS maps leaked SaaS credentials to their owners, permissions, and access, giving security teams one investigation workflow across supported SaaS providers.
Every provider exposes identity and access differently
Every provider exposes identity and access differently
A Slack token doesn't look like a GitHub PAT. A SharePoint credential doesn't behave like an OpenAI API key. Every provider exposes different identity, permission, and access information, forcing teams to switch between provider consoles just to understand the impact of a leaked credential.
A Slack token doesn't look like a GitHub PAT. A SharePoint credential doesn't behave like an OpenAI API key. Every provider exposes different identity, permission, and access information, forcing teams to switch between provider consoles just to understand the impact of a leaked credential.

Investigate SaaS credentials from one view
Investigate every SaaS credential the same way

Analyze for SaaS normalizes provider-specific identity and access information into a consistent investigation workflow, so teams can quickly understand ownership, permissions, impact, and the next remediation step regardless of provider.
Move from investigation to remediation
Move from investigation to remediation
Understanding the impact of a leaked credential is only half the investigation. Analyze for SaaS provides provider-specific remediation guidance for supported credential types, including direct links to HowToRotate.com, so teams know exactly how to rotate exposed credentials and take the right next step.
Understanding the impact of a leaked credential is only half the investigation. Analyze for SaaS provides provider-specific remediation guidance for supported credential types, including direct links to HowToRotate.com, so teams know exactly how to rotate exposed credentials and take the right next step.
Learn more about TruffleHog Analyze
Learn more about TruffleHog Analyze
Every surface presents different investigation challenges. TruffleHog Analyze includes specialized analyzers for AWS, Google Cloud, and supported SaaS credential types, each designed to surface the identity and access context unique to that environment while maintaining a consistent investigation workflow.
Every surface presents different investigation challenges. TruffleHog Analyze includes specialized analyzers for AWS, Google Cloud, and supported SaaS credential types, each designed to surface the identity and access context unique to that environment while maintaining a consistent investigation workflow.
Analyze for AWS
Map AWS identities, effective permissions, assumable roles, and credential access to understand real blast radius.
Map AWS identities, effective permissions, assumable roles, and credential access to understand real blast radius.
Learn more →



Analyze for GCP
Visualize service account permissions, IAM inheritance, and accessible resources across your Google Cloud hierarchy.
Visualize service account permissions, IAM inheritance, and accessible resources across your Google Cloud hierarchy.
Learn more →



The Dig
Thoughts, research findings, reports, and more from Truffle Security Co.
The Dig
Thoughts, research findings, reports, and more from Truffle Security Co.
STAY STRONG
DIG DEEP
TRUFFLEHOG
DOING IT THE RIGHT WAY
© 2026 Truffle Security Co.
STAY STRONG
DIG DEEP
© 2026 Truffle Security Co.


