Secret detection

Secret detection reviews credentials, tokens, and sensitive configuration patterns in the authorized code and project artifacts you provide to Workbench.

Inputs

Include the approved source, configuration, and relevant project artifacts in the assessment. The feature does not grant permission to test third-party systems, call a provider API, or validate a credential outside the authorized project boundary.

Review workflow

Use the finding inventory to inspect the location and remediation context with the owning team. Rotate, revoke, remove, or otherwise remediate a suspected credential only after the team validates the context.

A match is not automatically a live secret, and this documentation does not expose customer values or present a fabricated provider-validation result.

Evidence and handling

Treat sensitive values as restricted evidence. Keep disclosure to the smallest information necessary for triage and remediation; do not copy suspected credentials into tickets, chat, or public reports.

Availability

Secret detection is included from the Professional package. See Plans for the current package matrix.

Need a workflow that is not documented here? Email contact@eresussec.com.