How TruffleHog’s scores are calculated
The full audit trail, recomputed from the verdict data at build time through the same code that produced the leaderboard: verdict × quality × story weight per cell, cells sum to dimension scores, dimensions blend into the PA Score. Every number on the product page is reproducible from this page alone; for why the formula looks like this, see the methodology.
verdict factors: full ×1.0 · partial ×0.6 · disputed ×0.3 · none ×0.0 · n/a excluded from both sides · cell points = weight × quality × factor · cell max = weight × 10
PA Score23/100
Agent-ready 30.5 × 0.30 = 9.15
API quality 0.0 × 0.20 = 0.00
Openness 38.0 × 0.20 = 7.60
Built-in AI 15.0 × 0.15 = 2.25
Automation 24.0 × 0.15 = 3.60
(9.15 + 0.00 + 7.60 + 2.25 + 3.60) ÷ (0.30 + 0.20 + 0.20 + 0.15 + 0.15) = 22.60 ÷ 1.00 = 22.6
Scores are stored to 1 decimal; the product page’s pills round to whole numbers for display. Each dimension below shows the stories, verdicts, and cited evidence behind its number.
Agent-ready30.5/100×0.30 of the PA blend
Outside-in: can YOUR agent reach and drive this product — API, MCP, CLI, headless runs, agent docs.
Point an agent at llms.txt or agent-oriented docsweight 2
2 (weight) × 4 (quality) × 0.6 (partial) = 4.8 of 20 max
- [probe] https://trufflesecurity.com/llms.txt“PROBE llms.txt: HTTP 404 at https://trufflesecurity.com/llms.txt”
- [probe] https://trufflesecurity.com/docs.md“PROBE docs-md: HTTP 200 at https://trufflesecurity.com/docs.md --- title: Choose your adventure slug: docs description: Compare TruffleHog Open Source and TruffleHog Enterprise. Both”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“Pre-commit hooks are a useful way to prevent secrets in code from being pushed from a git repository.”
- [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.md“The custom regex detector allows you to define your own detector using regular expressions with optional verification using a webhook.”
Run the product headlessly / in CI for automationweight 2
2 (weight) × 7 (quality) × 1.0 (full) = 14.0 of 20 max
- [claimed-docs] https://trufflesecurity.com/trufflehog“trufflehog github --only-verified --repo https://github.com/trufflesecurity/test_keys”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“trufflehog git file://. --since-commit HEAD --results=verified,unknown --fail”
- [github] https://github.com/trufflesecurity/trufflehog“docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity”
- [github] https://github.com/trufflesecurity/trufflehog“docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“Pre-commit hooks are a useful way to prevent secrets in code from being pushed from a git repository.”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“This approach uses Git's `core.hooksPath` to apply hooks to all repositories without requiring any per-repository setup”
- [github] https://github.com/trufflesecurity/trufflehog“brew install trufflehog”
Plug MCP servers into this product so it can use their toolsweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Connect an agent via an official MCP serverweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Use an official CLIweight 2
2 (weight) × 8 (quality) × 1.0 (full) = 16.0 of 20 max
- [github] https://github.com/trufflesecurity/trufflehog“brew install trufflehog”
- [github] https://github.com/trufflesecurity/trufflehog“docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity”
- [github] https://github.com/trufflesecurity/trufflehog“docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“trufflehog git file://. --since-commit HEAD --results=verified,unknown --fail”
- [claimed-docs] https://trufflesecurity.com/docs/customizing-detection.md“./trufflehog scan --config=config.yaml --include-detectors=AWS,GitHub”
- [claimed-docs] https://trufflesecurity.com/docs/customizing-detection.md“You can manually specify which detectors to use with the `--include-detectors` flag.”
- [claimed-docs] https://trufflesecurity.com/docs/customizing-detection.md“the `--verify-detectors` and `--no-verify-detectors` CLI flags can be used to configure detector-specific verification override settings”
- [probe] https://github.com/trufflesecurity/trufflehog“official CLI documented at https://github.com/trufflesecurity/trufflehog”
Drive the product through a documented public APIweight 3
3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max
- [probe] https://trufflesecurity.com/llms.txt“PROBE llms.txt: HTTP 404 at https://trufflesecurity.com/llms.txt”
- [probe] https://trufflesecurity.com/openapi.json“PROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)”
- [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.md“Verification is done via a webhook POST request to the provided `endpoint`.”
Issue scoped/least-privilege API credentials for an agentweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Build against official SDKsweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://trufflesecurity.com/openapi.json“PROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)”
- [github] https://github.com/trufflesecurity/trufflehog“brew install trufflehog”
- [claimed-docs] https://trufflesecurity.com/trufflehog“trufflehog github --only-verified --repo https://github.com/trufflesecurity/test_keys”
Subscribe to events via webhooksweight 2
2 (weight) × 4 (quality) × 0.6 (partial) = 4.8 of 20 max
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Route findings to Slack, Jira, email, or webhooks so the right people can act on them.”
- [claimed-docs] https://trufflesecurity.com“TruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.”
- [claimed-docs] https://trufflesecurity.com“TruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing”
- [probe] https://trufflesecurity.com/openapi.json“PROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)”
Agent-ready = 39.6 ÷ 130 × 100 = 30.5
API quality0.0/100×0.20 of the PA blend
The programmable surface once an agent is there — machine-readable spec, interactive docs, sandbox, versioning discipline.
Explore an interactive API reference with runnable examplesweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://trufflesecurity.com/openapi.json“PROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)”
- [probe] https://trufflesecurity.com/llms.txt“PROBE llms.txt: HTTP 404 at https://trufflesecurity.com/llms.txt”
Download a machine-readable API spec (OpenAPI or equivalent)weight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://trufflesecurity.com/openapi.json“PROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)”
Test against a sandbox environment without touching production dataweight 1
1 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 10 max
- [claimed-docs] https://trufflesecurity.com/trufflehog“trufflehog github --only-verified --repo https://github.com/trufflesecurity/test_keys”
- [github] https://github.com/trufflesecurity/trufflehog“docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys”
Rely on versioned APIs with a documented deprecation policyweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://trufflesecurity.com/openapi.json“PROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)”
API quality = 0.0 ÷ 70 × 100 = 0.0
Openness38.0/100×0.20 of the PA blend
Can you leave, inspect, or self-host — data export, open source, portability.
Do everything through the API that I can do in the UIweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://trufflesecurity.com/openapi.json“PROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)”
- [claimed-docs] https://trufflesecurity.com/docs“single sign on saml 2 0 or oauth 2 0 ❌ ✅ role based access control ❌ ✅”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“By the end, you'll have a running scanner, your first source connected, and findings flowing into the web UI.”
Export all of my data in open formats and leaveweight 3
3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Read the product's source under an open licenseweight 2
2 (weight) × 7 (quality) × 1.0 (full) = 14.0 of 20 max
- [community] https://news.ycombinator.com/item?id=30910893“Note that v3 shifts to AGPL, from GPL in prior versions. Doesn't bother me personally, but I know a lot of companies won't touch AGPL'd projects with a bargepole so this probably worth bearing in mind.”
- [github] https://github.com/trufflesecurity/trufflehog“brew install trufflehog”
- [probe] https://github.com/trufflesecurity/trufflehog“official CLI documented at https://github.com/trufflesecurity/trufflehog”
Self-host the core productweight 3
3 (weight) × 8 (quality) × 1.0 (full) = 24.0 of 30 max
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Deploy hosted or self-hosted scanners, scan your critical systems for secrets, and notify the right teams to remediate and rotate.”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Choose hosted (managed by Truffle Security) or self-hosted (running in your environment).”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“By the end, you'll have a running scanner, your first source connected, and findings flowing into the web UI.”
- [github] https://github.com/trufflesecurity/trufflehog“brew install trufflehog”
- [github] https://github.com/trufflesecurity/trufflehog“docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity”
Openness = 38.0 ÷ 100 × 100 = 38.0
Built-in AI15.0/100×0.15 of the PA blend
Inside-out: how agentic the product itself is for its users — built-in assistants, autonomous features.
Get AI-generated insights and suggestions from my data inside the productweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Set up automations that run autonomously in the backgroundweight 2
2 (weight) × 5 (quality) × 0.6 (partial) = 6.0 of 20 max
- [github] https://github.com/trufflesecurity/trufflehog“Are you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials?”
- [github] https://github.com/trufflesecurity/trufflehog“continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials”
- [claimed-docs] https://trufflesecurity.com“TruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.”
- [claimed-docs] https://trufflesecurity.com“TruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Deploy hosted or self-hosted scanners, scan your critical systems for secrets, and notify the right teams to remediate and rotate.”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Choose hosted (managed by Truffle Security) or self-hosted (running in your environment).”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Route findings to Slack, Jira, email, or webhooks so the right people can act on them.”
Delegate tasks to a built-in AI assistant inside the productweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Operate the product with natural-language commandsweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Built-in AI = 6.0 ÷ 40 × 100 = 15.0
Automation24.0/100×0.15 of the PA blend
Depth of automation primitives — rules, scheduling, bulk operations, webhooks.
Perform bulk operations across many items at onceweight 2
2 (weight) × 5 (quality) × 0.6 (partial) = 6.0 of 20 max
- [claimed-docs] https://trufflesecurity.com/trufflehog“TruffleHog scans beyond code repositories to identify secrets hidden in comments, Docker images, and more.”
- [claimed-docs] https://trufflesecurity.com/docs“TruffleHog can look for secrets in many places including git, chats, wikis, logs, api testing platforms, object stores, filesystems and more”
- [github] https://github.com/trufflesecurity/trufflehog“Are you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials?”
- [github] https://github.com/trufflesecurity/trufflehog“continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials”
- [claimed-docs] https://trufflesecurity.com/docs“trufflehog classifies over 800 secret types, mapping them back to the specific identity they belong to”
- [claimed-docs] https://trufflesecurity.com/docs“for every secret trufflehog can classify, it can also log in to confirm if that secret is live or not”
Define rules that trigger actions automatically on eventsweight 3
3 (weight) × 6 (quality) × 0.6 (partial) = 10.8 of 30 max
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“Pre-commit hooks are a useful way to prevent secrets in code from being pushed from a git repository.”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“trufflehog git file://. --since-commit HEAD --results=verified,unknown --fail”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“This approach uses Git's `core.hooksPath` to apply hooks to all repositories without requiring any per-repository setup”
- [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.md“If you run your own git server, consider the pre-receive hook option which can block commits with secrets from being accepted.”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Route findings to Slack, Jira, email, or webhooks so the right people can act on them.”
- [claimed-docs] https://trufflesecurity.com“TruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.”
- [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.md“Verification is done via a webhook POST request to the provided `endpoint`.”
- [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.md“The custom regex detector allows you to define your own detector using regular expressions with optional verification using a webhook.”
Schedule recurring jobs or workflowsweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [claimed-docs] https://trufflesecurity.com“TruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.”
- [github] https://github.com/trufflesecurity/trufflehog“Are you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials?”
- [github] https://github.com/trufflesecurity/trufflehog“continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials”
- [claimed-docs] https://trufflesecurity.com/docs/getting-started.md“Deploy hosted or self-hosted scanners, scan your critical systems for secrets, and notify the right teams to remediate and rotate.”
Version, review, and roll back my automationsweight 1
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Automation = 16.8 ÷ 70 × 100 = 24.0