Access
Install
Showcase


Try itExperimental
See what an agent can do with TruffleHog before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$trufflehog --versionrecorded session — replayed, not liveVerified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommitevidence →
Stories about ci precommit in this arena
Container scanning — stories about container scanning in this arenaContainer scanningevidence →
Stories about container scanning in this arena
n/a
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracyevidence →
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency scaevidence →
Stories about dependency sca in this arena
n/a
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rulesevidence →
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detectionevidence →
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbomevidence →
Stories about supply chain sbom in this arena
n/a
Triage noise — stories about triage noise in this arenaTriage noiseevidence →
Stories about triage noise in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 8 free · 0 paid · 0 enterprise · 18 not stated in evidence
Follow the green: where the map greys out is where TruffleHog stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
—0/10
Subscribe to events via webhooks
~4/10
Build against official SDKs
—0/10
Issue scoped/least-privilege API credentials for an agent
n/an/a
Connect an agent via an official MCP server
n/an/a
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
—0/10
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
~4/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
n/an/a
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—–
Set up automations that run autonomously in the background
~5/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommit
Stories about ci precommit in this arena
Container scanning — stories about container scanning in this arenaContainer scanning
Stories about container scanning in this arena
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency sca
Stories about dependency sca in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rules
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detection
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom
Stories about supply chain sbom in this arena
Triage noise — stories about triage noise in this arenaTriage noise
Stories about triage noise in this arena
Sorted by importance (agentic first) (high → low) · 55/55 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | fullfree | 8/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | fullfree | 7/10 | Cclaimed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | 0/10 | ||
Run the scanner as a pre-commit hook so secrets and issues never enter my git history C Pre commit | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | full | 9/10 | Cclaimed | |
Scan a repository and its full git history for hardcoded secrets and credentials C Secret scanning | developer | Secret detection — stories about secret detection in this arenaSecret detection | 3 | full | 9/10 | Cclaimed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | fullfree | 8/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 6/10 | Cclaimed | |
Run scans in CI on every pull request and fail the build on new findings via exit codes C Ci gates | devops-lead | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | partial | 6/10 | Cclaimed | |
Baseline or ignore existing and false-positive findings so only new issues alert C Fp management | security-engineer | Triage noise — stories about triage noise in this arenaTriage noise | 3 | partial | 5/10 | Cclaimed | |
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings G Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | partialfree | 5/10 | Cclaimed | |
Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives C Ai triage | ai-native user | Triage noise — stories about triage noise in this arenaTriage noise | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Run static analysis that finds vulnerability classes like injection and XSS in my source code C Code analysis | developer | Sast rules — stories about sast rules in this arenaSast rules | 3 | n/a | untested | none yet | |
Scan container images for OS-package and application-layer vulnerabilities before deploying them C Containers | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 3 | n/a | untested | none yet | |
Scan my dependency manifests and lockfiles for packages with known vulnerabilities C Sca scanning | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 3 | n/a | untested | none yet | |
Define custom detection rules for my organization's internal token and secret formats C Custom detection | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | full | 9/10 | Cclaimed | |
Have detected secrets verified against the issuing service so I know which ones are live C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | full | 9/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | fullfree | 7/10 | Tprobed | |
Filter and gate on findings by severity or confidence so low-value noise does not block builds C Fp management | developer | Triage noise — stories about triage noise in this arenaTriage noise | 2 | partial | 6/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partialfree | 5/10 | Cclaimed | |
Scan projects across all the major languages and package ecosystems my organization uses C Coverage | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | partial | 5/10 | Cclaimed | |
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands C Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | partialfree | 5/10 | Cclaimed | |
Write custom static-analysis rules in a simple syntax and share them across repositories C Custom rules | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | partial | 5/10 | Cclaimed | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 4/10 | Cclaimed | |
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secrets C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | disputed | 4/10 | Dcontradicted | |
Apply suggested or automatic code fixes for findings instead of only reading reports C Fix suggestions | developer | Sast rules — stories about sast rules in this arenaSast rules | 2 | none | 0/10 | ||
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | 0/10 | ||
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Detect taint-style vulnerabilities that flow across files and function boundaries C Code analysis | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | n/a | untested | none yet | |
Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling C Output formats | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | nonefree | untested | none yet | |
Generate a software bill of materials (SPDX or CycloneDX) for my project or image C Sbom | security-engineer | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 2 | n/a | untested | none yet | |
Get concrete upgrade paths or automated fix pull requests that remediate vulnerable dependencies C Dependency fixes | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | n/a | untested | none yet | |
Have AI draft remediation pull requests for security findings that I review and merge C Ai remediation | ai-native user | Sast rules — stories about sast rules in this arenaSast rules | 2 | n/a | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Prioritize dependency alerts by whether the vulnerable code is actually reachable from my code C Sca scanning | security-engineer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | n/a | untested | none yet | |
Scan Terraform, Kubernetes, and other IaC files for security misconfigurations C Iac misconfig | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 2 | n/a | untested | none yet | |
See scan findings surfaced as pull-request comments or checks in GitHub or GitLab C Ci gates | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | none | untested | none yet | |
Detect the licenses of my dependencies and enforce a license policy in scans C Licenses | devops-lead | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 1 | n/a | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 29 stories with headroom
What would move TruffleHog’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDrive the product through a documented public API
nonemoves agent-readyimpact 45
No evidence of a documented public API (REST/GraphQL/SDK) for programmatically driving TruffleHog; probes for llms.txt and openapi/swagger specs both 404, and only CLI flags/config and a webhook for custom-detector verification are documented, not a driving API.
Triage noise — stories about triage noise in this arenaUse AI to triage findings — explaining them, deduplicating, and flagging likely false positives
nonemoves PA Scoreimpact 30
TruffleHog's evidence shows credential verification, classification, and permission analysis (analyzer) to reduce false positives, but none of this involves AI/LLM-based explanation, deduplication, or triage of findings — it's rule-based verification, not AI reasoning.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
The evidence covers scanning, detection, verification, and hosted/self-hosted deployment options, but there is no documentation of any data export feature, open export format, or migration/exit path for users of the hosted platform or CLI findings store.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
TruffleHog is a secrets-scanning/detection tool; the evidence pack describes verification, classification, and analyzer features but no AI-generated insights, summaries, or suggestions surfaced to users—no LLM-based feature is mentioned anywhere.
Agenticness — how well agents can access and operate the productBuild against official SDKs
nonemoves agent-readyimpact 30
The evidence pack documents TruffleHog's CLI, Docker image, detectors, and API-like analyzer features, but contains no mention of an official SDK (Python, JS, Go client library, etc.) for developers to build against; probes for OpenAPI specs also returned 404s, indicating no such offering.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
TruffleHog is a CLI/scanning tool with docs and CLI examples, but there is no evidence of an interactive API reference (e.g., Swagger/OpenAPI explorer) with runnable examples; the openapi probe explicitly returned 404s for all candidate API spec paths and no interactive docs are mentioned.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
A direct probe for OpenAPI/swagger endpoints returned 404 for all candidate paths, and no evidence anywhere in the pack points to a downloadable machine-readable API spec.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
No evidence of versioned APIs or a documented deprecation policy; probe results show no OpenAPI spec found (404s across all candidate paths), and no docs mention API versioning or deprecation practices.
Showing the top 8 of 29 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map7 surfaces · 22 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs21 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Use an official CLI
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands
- Run scans in CI on every pull request and fail the build on new findings via exit codes
- Run the scanner as a pre-commit hook so secrets and issues never enter my git history
- Scan projects across all the major languages and package ecosystems my organization uses
- Self-host the core product
- Choose where my data is stored (region/residency)
- Write custom static-analysis rules in a simple syntax and share them across repositories
- Define custom detection rules for my organization's internal token and secret formats
- Scan a repository and its full git history for hardcoded secrets and credentials
- Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secrets
- Have detected secrets verified against the issuing service so I know which ones are live
- Baseline or ignore existing and false-positive findings so only new issues alert
- Filter and gate on findings by severity or confidence so low-value noise does not block builds
GitHub README11 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Set up automations that run autonomously in the background
- Perform bulk operations across many items at once
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Run scans in CI on every pull request and fail the build on new findings via exit codes
- Scan projects across all the major languages and package ecosystems my organization uses
- Read the product's source under an open license
- Self-host the core product
- Scan a repository and its full git history for hardcoded secrets and credentials
- Have detected secrets verified against the issuing service so I know which ones are live
Trufflehog docs9 stories
- Run the product headlessly / in CI for automation
- Perform bulk operations across many items at once
- Run the scanner as a pre-commit hook so secrets and issues never enter my git history
- Scan projects across all the major languages and package ecosystems my organization uses
- Scan a repository and its full git history for hardcoded secrets and credentials
- Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secrets
- Have detected secrets verified against the issuing service so I know which ones are live
- Baseline or ignore existing and false-positive findings so only new issues alert
- Filter and gate on findings by severity or confidence so low-value noise does not block builds
trufflesecurity.com3 stories
Hacker News2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$trufflehog --versionreproduced$ trufflehog --version trufflehog 3.97.4
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
2 of 12 testable claims verified · 2 contradicted → integrity 0/100
28 distinct capability claims found in TruffleHog’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
2
Verified
8
Unverified
2
Contradicted
11
Undersold
Verified (3)
“Official CLI can scan a GitHub repo and only report verified secrets”
“Installable via Homebrew (brew install trufflehog)”
“Findings can be routed to Slack, Jira, email, or webhooks”
Unverified (20)
“Official CLI can scan a GitHub repo and only report verified secrets”
Scan a repository and its full git history for hardcoded secrets and credentialsfullproof ↗
“Official CLI can scan a GitHub repo and only report verified secrets”
Have detected secrets verified against the issuing service so I know which ones are livefullproof ↗
“Classifies over 800 secret types and maps them to the identity they belong to”
Scan a repository and its full git history for hardcoded secrets and credentialsfullproof ↗
“For every classifiable secret, can attempt a live login to confirm it's actually valid”
Have detected secrets verified against the issuing service so I know which ones are livefullproof ↗
“Provides pre-commit hook integration to stop secrets before they're pushed”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“Supports custom regex-based secret detectors with optional webhook verification”
Define custom detection rules for my organization's internal token and secret formatsfullproof ↗
“CLI flag lets you manually choose which detectors run via --include-detectors”
Define custom detection rules for my organization's internal token and secret formatsfullproof ↗
“Can force verification for specific secret types (e.g. AWS, Buildkite) regardless of source verify settings”
Have detected secrets verified against the issuing service so I know which ones are livefullproof ↗
“Git scan supports filtering results (verified/unknown) and failing the run via --fail for CI gating”
Run scans in CI on every pull request and fail the build on new findings via exit codespartialproof ↗
“Can run headlessly via Docker container to scan an entire GitHub org”
Run the product headlessly / in CI for automationfullproof ↗
“Global git hook setup via core.hooksPath applies hooks to all repos without per-repo config”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“Documents integration with Husky for managing JS/Node git hooks”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“--verify-detectors and --no-verify-detectors flags let you override verification per detector”
Have detected secrets verified against the issuing service so I know which ones are livefullproof ↗
“Continuously tracks status of exposed keys to detect whether remediation has occurred, with configurable alerts”
Define rules that trigger actions automatically on eventspartialproof ↗
“Offers hosted or self-hosted deployment options for the scanner”
“Supports pre-receive git server hooks to block commits containing secrets before they're accepted”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“Pre-commit hooks can be bypassed in rare cases with git commit --no-verify”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“Custom regex detector verification is performed via a webhook POST request to a provided endpoint”
Define custom detection rules for my organization's internal token and secret formatsfullproof ↗
“Config file plus --include-detectors flag lets scans target specific detector types like AWS and GitHub”
Define custom detection rules for my organization's internal token and secret formatsfullproof ↗
“Core tool is a secrets scanner that digs into code repositories to find passwords and sensitive keys”
Scan a repository and its full git history for hardcoded secrets and credentialsfullproof ↗
Contradicted (4)
“Scans beyond git repos, including comments, Docker images, and other locations”
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secretsdisputedproof ↗
“Git scan supports filtering results (verified/unknown) and failing the run via --fail for CI gating”
Emit scan results in machine-readable formats like JSON or SARIF for downstream toolingnone
“Scans many non-git sources: chats, wikis, logs, API testing platforms, object stores, filesystems, and more”
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secretsdisputedproof ↗
“Can continuously monitor Git, Jira, Slack, Confluence, Microsoft Teams, and Sharepoint for credentials”
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secretsdisputedproof ↗
Undersold (11)
Point an agent at llms.txt or agent-oriented docspartialproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findingspartialproof ↗
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it landspartialproof ↗
Scan projects across all the major languages and package ecosystems my organization usespartialproof ↗
Choose where my data is stored (region/residency)partialproof ↗
Write custom static-analysis rules in a simple syntax and share them across repositoriespartialproof ↗
Baseline or ignore existing and false-positive findings so only new issues alertpartialproof ↗
Filter and gate on findings by severity or confidence so low-value noise does not block buildspartialproof ↗
Claims outside our story set (4)
Real capability claims found in TruffleHog’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Analyze command investigates a secret's creator, accessible resources, and permissions”
source ↗“Onboarding flow connects a source and streams findings into a web UI”
source ↗“Checksums for release artifacts are signed with cosign for supply-chain integrity”
source ↗“Product page describes offering SSO (SAML2.0/OAuth2.0) and role-based access control”
source ↗
Business model
TruffleHog OSS (AGPL-3.0) is free; Truffle Security sells TruffleHog Enterprise with managed or self-hosted scanners, secret analysis, and remediation workflows.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
