[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-secret-scanning::en":3,"gloss-cluster-secret-scanning::en":23,"gloss-next-secret-scanning::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"secret-scanning","security","Secret Scanning","Secret scanning is automated detection of credentials — API keys, database passwords, private keys, OAuth tokens — that have been accidentally committed to source code, config files, or logs. Leaked secrets are one of the most common and costly breach vectors: a key pushed to a public repo can be found and abused by bots within minutes, and rotating it afterward is far more painful than never leaking it. Scanners work by matching known key patterns and entropy heuristics, and the best ones run as a pre-commit hook or CI gate so a secret is caught before it ever lands in history. For builders shipping fast, this is cheap insurance. Practical note: enable your Git host's built-in scanning and push protection, add a pre-commit scanner locally, store real secrets in a manager or vault rather than .env files that drift into commits, and if something does leak, revoke and rotate first — deleting the commit does not un-leak it.","Secret scanning automatically finds credentials committed into code, config, or logs — a key pushed to a public repo is found by bots within minutes.",null,[11,14,17,20],{"slug":12,"name":13},"api-key","API Key",{"slug":15,"name":16},"audit-log","Audit Log (Audit Trail)",{"slug":18,"name":19},"byok","Bring Your Own Key (BYOK)",{"slug":21,"name":22},"secrets-management","Secrets Management",[24,26,30,34,37,40,41,44,47,50,53,56],{"slug":15,"category":5,"name":16,"updated_at":25},"2026-08-24T02:46:37+00:00",{"slug":27,"category":5,"name":28,"updated_at":29},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":31,"category":5,"name":32,"updated_at":33},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":35,"category":5,"name":36,"updated_at":33},"bridge-letter","Bridge Letter",{"slug":38,"category":5,"name":39,"updated_at":33},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":18,"category":5,"name":19,"updated_at":25},{"slug":42,"category":5,"name":43,"updated_at":33},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":45,"category":5,"name":46,"updated_at":29},"data-classification","Data Classification",{"slug":48,"category":5,"name":49,"updated_at":33},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":51,"category":5,"name":52,"updated_at":33},"data-minimization","Data Minimization",{"slug":54,"category":5,"name":55,"updated_at":33},"data-poisoning","Data Poisoning",{"slug":57,"category":5,"name":58,"updated_at":33},"data-processing-agreement","Data Processing Agreement (DPA)"]