Penv Cloud
Start free
Docs
Conceptsince cloud@2026-09-25

Secret scanning

We scan your connected GitHub repositories daily for committed credentials. We store where each one sits and a keyed hash, never the credential.

Secret Scanning is an Enterprise add-on, granted by agreement. Once a day we read the default branch of every repository your GitHub installation covers and list each credential-shaped string under Integrations > Secret Scanning, with a link to the file and line on GitHub.

We read through the Penv Cloud GitHub App (install it from Machine Identities > Connect a Platform) with a token limited to contents: read and metadata: read.

We skip a suspended installation. The page names it, even beside a live one, and its open findings stay listed until you unsuspend it and the next scan runs.

What we detect

RuleMatches
AWS access keyAKIA… or ASIA… key ids
GitHub tokenghp_, gho_, ghu_, ghs_, ghr_ and github_pat_ tokens
Stripe live keysk_live_ and rk_live_ keys
Slack tokenxox… tokens
Google API keyAIza… keys
Private keyPEM BEGIN … PRIVATE KEY headers
Penv Cloud credentialpck_, pcu_ and pce_ credentials

What we store

FieldStored
Repository, path, lineyes
Ruleyes
The matched stringno: we keep an HMAC of it, so the same credential in the same file is one finding

A finding closes on the first complete scan that no longer sees it. To close one, rotate the credential, then remove it from the branch: deleting it from the branch alone leaves it in git history.

Limits

LimitValue
Files read per repository per scan300
Largest file read200 KB
Skippedimages, fonts, archives, PDFs, .lock files, node_modules, vendor, dist, build

A repository with more files than the limit is scanned in part, and its open findings stay open until a complete scan. Each scan lands a scanning.repository_scanned entry in the audit log.