GitHub Actions only catch future commits. We find the old ones.

Find secrets you committed years ago before hackers do.

GitHub Actions only scan new code. Every secret you committed in the past is still sitting there — in your history, on every branch, forever.

SecretScan digs through your entire commit history and finds them.

Free — Scan current state of public repos

🔍 Full History Audit — $29 one-time

Every commit. Every branch. Every secret you've ever pushed — going back years. Includes a remediation report: exactly which keys to rotate and how.

Why history scanning matters

The problem with GitHub Actions

TruffleHog, Gitleaks, GitGuardian — they all run on new commits only. Any secret you pushed before setting them up? Still there. Forever. Anyone with a git clone of your repo can run git log -p | grep sk- and find it instantly.

Git history is permanent

Deleting a file doesn't remove it from history. Force-pushing doesn't help if someone already cloned it. The only real fix is to rotate the key — but first you have to know it was exposed.

What the Full History Audit gives you

  • → Every secret committed, ever — across all branches
  • → The exact commit, date, and author
  • → Which keys are still active vs already rotated
  • → Step-by-step remediation for each finding