Infisical is the open-source platform for secrets, certificates, and privileged access management.
-
Updated
Sep 10, 2026 - TypeScript
Infisical is the open-source platform for secrets, certificates, and privileged access management.
AI gets the context. Not your private data. Local-first privacy proxy for browser chat, AI APIs, and coding agents.
Protect your secrets using Gitleaks-Action
Scan for secrets in dangling commits on GitHub using GH Archive data.
Scan for secrets, endpoints, and other sensitive data after decompiling and deobfuscating Android files. (.apk, .xapk, .dex, .jar, .class, .smali, .zip, .aar, .arsc, .aab, .jadx.kts).
Audit AI chat exports locally before sharing or migration. Find possible secrets, personal-data patterns, broken JSON/JSONL, SQLite issues, and scan gaps—without uploading the archive.
Examples of Custom Secret Scanning Patterns for use with GitHub Secret Protection/Advanced Security
GPU-accelerated secret scanner for code, Git history, containers, cloud, browser assets, and CI. 923 detectors, live verification, CUDA, Metal, WGPU.
Official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc) using TruffleHog.
The antivirus for OpenClaw — approve dangerous actions, scan skills, block secret leaks, and keep humans in control, for safety.
Find and redact secrets in AI coding agent histories (Claude Code, and more).
Local privacy preflight for files, folders, and archives—catch secrets, PII, metadata, and hidden document content before sharing.
Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery
GitHub Secret Scanning Auto Remediator (GSSAR)
Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.
Zero-dependency TypeScript secret and PII redaction for any SDK, logs, HTTP, LLM prompts, and scoped MCP tool boundaries.
Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied automatically.
A comprehensive CLI tool for managing .env files — validation, secret scanning, and format conversion.
collectvars collects JavaScript variables, highlights risky ones, and helps you understand code structure, while you casually browse.
High-precision secret scanner for code, tickets, logs, and web app with ml validation
To associate your repository with the secret-scanning topic, visit your repo's landing page and select "manage topics."