Skip to content

How TruffleHog’s scores are calculated

The full audit trail, recomputed from the verdict data at build time through the same code that produced the leaderboard: verdict × quality × story weight per cell, cells sum to dimension scores, dimensions blend into the PA Score. Every number on the product page is reproducible from this page alone; for why the formula looks like this, see the methodology.

verdict factors: full ×1.0 · partial ×0.6 · disputed ×0.3 · none ×0.0 · n/a excluded from both sides · cell points = weight × quality × factor · cell max = weight × 10

PA Score23/100

Agent-ready 30.5 × 0.30 = 9.15

API quality 0.0 × 0.20 = 0.00

Openness 38.0 × 0.20 = 7.60

Built-in AI 15.0 × 0.15 = 2.25

Automation 24.0 × 0.15 = 3.60

(9.15 + 0.00 + 7.60 + 2.25 + 3.60) ÷ (0.30 + 0.20 + 0.20 + 0.15 + 0.15) = 22.60 ÷ 1.00 = 22.6

Scores are stored to 1 decimal; the product page’s pills round to whole numbers for display. Each dimension below shows the stories, verdicts, and cited evidence behind its number.

Agent-ready30.5/100×0.30 of the PA blend

Outside-in: can YOUR agent reach and drive this product — API, MCP, CLI, headless runs, agent docs.

Point an agent at llms.txt or agent-oriented docsweight 2

2 (weight) × 4 (quality) × 0.6 (partial) = 4.8 of 20 max

  • [probe] https://trufflesecurity.com/llms.txtPROBE llms.txt: HTTP 404 at https://trufflesecurity.com/llms.txt
  • [probe] https://trufflesecurity.com/docs.mdPROBE docs-md: HTTP 200 at https://trufflesecurity.com/docs.md --- title: Choose your adventure slug: docs description: Compare TruffleHog Open Source and TruffleHog Enterprise. Both
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdPre-commit hooks are a useful way to prevent secrets in code from being pushed from a git repository.
  • [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.mdThe custom regex detector allows you to define your own detector using regular expressions with optional verification using a webhook.

Run the product headlessly / in CI for automationweight 2

2 (weight) × 7 (quality) × 1.0 (full) = 14.0 of 20 max

  • [claimed-docs] https://trufflesecurity.com/trufflehogtrufflehog github --only-verified --repo https://github.com/trufflesecurity/test_keys
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdtrufflehog git file://. --since-commit HEAD --results=verified,unknown --fail
  • [github] https://github.com/trufflesecurity/trufflehogdocker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity
  • [github] https://github.com/trufflesecurity/trufflehogdocker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdPre-commit hooks are a useful way to prevent secrets in code from being pushed from a git repository.
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdThis approach uses Git's `core.hooksPath` to apply hooks to all repositories without requiring any per-repository setup
  • [github] https://github.com/trufflesecurity/trufflehogbrew install trufflehog

Plug MCP servers into this product so it can use their toolsweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Connect an agent via an official MCP serverweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Use an official CLIweight 2

2 (weight) × 8 (quality) × 1.0 (full) = 16.0 of 20 max

  • [github] https://github.com/trufflesecurity/trufflehogbrew install trufflehog
  • [github] https://github.com/trufflesecurity/trufflehogdocker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity
  • [github] https://github.com/trufflesecurity/trufflehogdocker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdtrufflehog git file://. --since-commit HEAD --results=verified,unknown --fail
  • [claimed-docs] https://trufflesecurity.com/docs/customizing-detection.md./trufflehog scan --config=config.yaml --include-detectors=AWS,GitHub
  • [claimed-docs] https://trufflesecurity.com/docs/customizing-detection.mdYou can manually specify which detectors to use with the `--include-detectors` flag.
  • [claimed-docs] https://trufflesecurity.com/docs/customizing-detection.mdthe `--verify-detectors` and `--no-verify-detectors` CLI flags can be used to configure detector-specific verification override settings
  • [probe] https://github.com/trufflesecurity/trufflehogofficial CLI documented at https://github.com/trufflesecurity/trufflehog

Drive the product through a documented public APIweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

  • [probe] https://trufflesecurity.com/llms.txtPROBE llms.txt: HTTP 404 at https://trufflesecurity.com/llms.txt
  • [probe] https://trufflesecurity.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)
  • [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.mdVerification is done via a webhook POST request to the provided `endpoint`.

Issue scoped/least-privilege API credentials for an agentweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Build against official SDKsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://trufflesecurity.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)
  • [github] https://github.com/trufflesecurity/trufflehogbrew install trufflehog
  • [claimed-docs] https://trufflesecurity.com/trufflehogtrufflehog github --only-verified --repo https://github.com/trufflesecurity/test_keys

Subscribe to events via webhooksweight 2

2 (weight) × 4 (quality) × 0.6 (partial) = 4.8 of 20 max

  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdRoute findings to Slack, Jira, email, or webhooks so the right people can act on them.
  • [claimed-docs] https://trufflesecurity.comTruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.
  • [claimed-docs] https://trufflesecurity.comTruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing
  • [probe] https://trufflesecurity.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)

Agent-ready = 39.6 ÷ 130 × 100 = 30.5

API quality0.0/100×0.20 of the PA blend

The programmable surface once an agent is there — machine-readable spec, interactive docs, sandbox, versioning discipline.

Explore an interactive API reference with runnable examplesweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://trufflesecurity.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)
  • [probe] https://trufflesecurity.com/llms.txtPROBE llms.txt: HTTP 404 at https://trufflesecurity.com/llms.txt

Download a machine-readable API spec (OpenAPI or equivalent)weight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://trufflesecurity.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)

Test against a sandbox environment without touching production dataweight 1

1 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 10 max

  • [claimed-docs] https://trufflesecurity.com/trufflehogtrufflehog github --only-verified --repo https://github.com/trufflesecurity/test_keys
  • [github] https://github.com/trufflesecurity/trufflehogdocker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys

Rely on versioned APIs with a documented deprecation policyweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://trufflesecurity.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)

API quality = 0.0 ÷ 70 × 100 = 0.0

Openness38.0/100×0.20 of the PA blend

Can you leave, inspect, or self-host — data export, open source, portability.

Do everything through the API that I can do in the UIweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://trufflesecurity.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://trufflesecurity.com/openapi.json, https://trufflesecurity.com/swagger.json, https://trufflesecurity.com/api/openapi.json, https://trufflesecurity.com/.well-known/openapi.json)
  • [claimed-docs] https://trufflesecurity.com/docssingle sign on saml 2 0 or oauth 2 0 ❌ ✅ role based access control ❌ ✅
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdBy the end, you'll have a running scanner, your first source connected, and findings flowing into the web UI.

Export all of my data in open formats and leaveweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Read the product's source under an open licenseweight 2

2 (weight) × 7 (quality) × 1.0 (full) = 14.0 of 20 max

  • [community] https://news.ycombinator.com/item?id=30910893Note that v3 shifts to AGPL, from GPL in prior versions. Doesn't bother me personally, but I know a lot of companies won't touch AGPL'd projects with a bargepole so this probably worth bearing in mind.
  • [github] https://github.com/trufflesecurity/trufflehogbrew install trufflehog
  • [probe] https://github.com/trufflesecurity/trufflehogofficial CLI documented at https://github.com/trufflesecurity/trufflehog

Self-host the core productweight 3

3 (weight) × 8 (quality) × 1.0 (full) = 24.0 of 30 max

  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdDeploy hosted or self-hosted scanners, scan your critical systems for secrets, and notify the right teams to remediate and rotate.
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdChoose hosted (managed by Truffle Security) or self-hosted (running in your environment).
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdBy the end, you'll have a running scanner, your first source connected, and findings flowing into the web UI.
  • [github] https://github.com/trufflesecurity/trufflehogbrew install trufflehog
  • [github] https://github.com/trufflesecurity/trufflehogdocker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity

Openness = 38.0 ÷ 100 × 100 = 38.0

Built-in AI15.0/100×0.15 of the PA blend

Inside-out: how agentic the product itself is for its users — built-in assistants, autonomous features.

Get AI-generated insights and suggestions from my data inside the productweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Set up automations that run autonomously in the backgroundweight 2

2 (weight) × 5 (quality) × 0.6 (partial) = 6.0 of 20 max

  • [github] https://github.com/trufflesecurity/trufflehogAre you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials?
  • [github] https://github.com/trufflesecurity/trufflehogcontinuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials
  • [claimed-docs] https://trufflesecurity.comTruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.
  • [claimed-docs] https://trufflesecurity.comTruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdDeploy hosted or self-hosted scanners, scan your critical systems for secrets, and notify the right teams to remediate and rotate.
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdChoose hosted (managed by Truffle Security) or self-hosted (running in your environment).
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdRoute findings to Slack, Jira, email, or webhooks so the right people can act on them.

Delegate tasks to a built-in AI assistant inside the productweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Operate the product with natural-language commandsweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Built-in AI = 6.0 ÷ 40 × 100 = 15.0

Automation24.0/100×0.15 of the PA blend

Depth of automation primitives — rules, scheduling, bulk operations, webhooks.

Perform bulk operations across many items at onceweight 2

2 (weight) × 5 (quality) × 0.6 (partial) = 6.0 of 20 max

  • [claimed-docs] https://trufflesecurity.com/trufflehogTruffleHog scans beyond code repositories to identify secrets hidden in comments, Docker images, and more.
  • [claimed-docs] https://trufflesecurity.com/docsTruffleHog can look for secrets in many places including git, chats, wikis, logs, api testing platforms, object stores, filesystems and more
  • [github] https://github.com/trufflesecurity/trufflehogAre you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials?
  • [github] https://github.com/trufflesecurity/trufflehogcontinuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials
  • [claimed-docs] https://trufflesecurity.com/docstrufflehog classifies over 800 secret types, mapping them back to the specific identity they belong to
  • [claimed-docs] https://trufflesecurity.com/docsfor every secret trufflehog can classify, it can also log in to confirm if that secret is live or not

Define rules that trigger actions automatically on eventsweight 3

3 (weight) × 6 (quality) × 0.6 (partial) = 10.8 of 30 max

  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdPre-commit hooks are a useful way to prevent secrets in code from being pushed from a git repository.
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdtrufflehog git file://. --since-commit HEAD --results=verified,unknown --fail
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdThis approach uses Git's `core.hooksPath` to apply hooks to all repositories without requiring any per-repository setup
  • [claimed-docs] https://trufflesecurity.com/docs/pre-commit-hooks.mdIf you run your own git server, consider the pre-receive hook option which can block commits with secrets from being accepted.
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdRoute findings to Slack, Jira, email, or webhooks so the right people can act on them.
  • [claimed-docs] https://trufflesecurity.comTruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.
  • [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.mdVerification is done via a webhook POST request to the provided `endpoint`.
  • [claimed-docs] https://trufflesecurity.com/docs/custom-detectors.mdThe custom regex detector allows you to define your own detector using regular expressions with optional verification using a webhook.

Schedule recurring jobs or workflowsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [claimed-docs] https://trufflesecurity.comTruffleHog continuously tracks the status of all key types to identify whether remediation has occurred. Set up alerts across the platform of your choosing and include customized messages for developers to rotate and secure keys.
  • [github] https://github.com/trufflesecurity/trufflehogAre you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials?
  • [github] https://github.com/trufflesecurity/trufflehogcontinuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials
  • [claimed-docs] https://trufflesecurity.com/docs/getting-started.mdDeploy hosted or self-hosted scanners, scan your critical systems for secrets, and notify the right teams to remediate and rotate.

Version, review, and roll back my automationsweight 1

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Automation = 16.8 ÷ 70 × 100 = 24.0