Sensitive data leaks from every surface your teams touch.
Traditional answers each cover a fragment: open-source scanners flag matches but can't tell you which credentials are still live. SaaS platforms manage findings — after you send them your secrets. DLP suites watch email and endpoints but were never built for repositories or AI prompts. The result is alert fatigue in one place and blind spots everywhere else.
Repositories remember everything
Credentials committed to Git remain in history long after the file is deleted — in HEAD, branches, CI/CD workflows, and every past commit.
Regulated data drifts everywhere
Names, card numbers, medical records, and government IDs end up in source code, log fixtures, PDFs, and screenshots.
AI tools sit outside the perimeter
Every day, employees paste code and customer data into AI chat tools that your security stack never sees.
One platform. Three products. Every finding accountable.
Detection is multi-signal — pattern matching, Shannon entropy, and contextual analysis — so confidence scores mean something. Discovered credentials are validated against live provider APIs. Regulated data is classified and mapped to GDPR, HIPAA, PCI DSS, and DPDP the moment it's found. And every finding enters an audited workflow — deduplicated, owner-resolved, risk-scored, escalated, and verified through closure.
Three products. One substrate.
Secret Security
Detect, validate, and drive remediation of exposed credentials across GitHub orgs and repos.
- ·200+ patterns + entropy + context scoring
- ·Live validation: GitHub, AWS, Stripe, Azure
- ·21-state audited workflow
Privacy Security
Detect regulated personal data in repos, documents, and images — classified and compliance-mapped.
- ·PII / PHI / PCI / Financial classification
- ·GDPR · HIPAA · PCI DSS · DPDP mapping
- ·PDF, DOCX & image OCR scanning
AI Guardienne
A browser extension that stops secrets, PII, PCI, and PHI before they reach AI Models (LLMs/Frontier Models).
- ·Entirely on-device — zero network calls
- ·60+ rules with checksum validation
- ·Allow / warn / redact / block per policy
Built for evidence, not noise.
Detect secrets. Then prove which ones are live.
200+ patterns combined with Shannon entropy and context scoring. Findings arrive labeled LIVE_VALID, DEAD_INVALID, or UNVERIFIED — not just “matched a regex.”
HEAD, branches, workflows, and full history.
Shallow scans need no clone; deep scans walk complete commit history. Cross-scan deduplication means a credential seen in ten scans is one finding, not ten.
Regulated data, classified at detection time.
Presidio NLP plus recognizers for Indian identifiers, financial data, and healthcare records — checksum-validated, tagged GDPR / HIPAA / PCI DSS / DPDP.
Scan what your organization actually leaks.
PDFs — native, scanned, or mixed — DOCX including tables, plain-text formats, and screenshots through OCR with per-finding bounding boxes.
From detection to verified closure.
A 21-state workflow: deduplication, ownership resolution, validation, approval gates, remediation, escalation, and verified closure — with append-only timelines.
Decisions you can audit, not guess at.
A rule-based engine routes every validated finding. No LLM sits in the decision path — language models are confined to optional plain-English explanations.
Findings meet your existing workflow.
Slack Block Kit alerts, email, and Jira tickets. A governance worker pushes confirmed findings into SimpleRisk or CISO Assistant — idempotently.
Shift left without the friction.
A pre-commit CLI blocks secrets at commit time. SARIF 2.1.0 uploads straight into GitHub Code Scanning. OpenAPI REST + WebSocket events power any integration.
Built like the security tool it is.
Encryption at rest under your keys with rotation. Reveals require written justification, are rate-limited, and land in an immutable audit log.
What Perryscope finds.
Secrets & credentials
Personal & regulated data
Twenty-one states. Seven phases. Zero guesswork.
Every finding is a stateful work item, moved by a deterministic transition table. Hover a phase to see its constituent states.
Architectural answers, not marketing claims.
vs. open-source scanners
TruffleHog, Gitleaks, and detect-secrets detect and exit. Perryscope validates against live provider APIs, persists findings, deduplicates across scans, and manages them through an audited workflow with escalation and verification.
vs. SaaS secret managers
Comparable management capabilities — validation, workflows, dashboards — but self-hosted, so secrets and personal data never leave your infrastructure, under enterprise licensing that fits your organization.
vs. platform-native scanning
Broader pattern surface, live validation, deep history scans by default — plus privacy/compliance scanning and browser DLP that platform-native tools don't attempt.
vs. traditional DLP suites
Built for the surfaces DLP ignores — Git history, CI/CD workflows, developer commits, and AI chat prompts — with detection tuned for code and structured identifiers.
Built for the people who carry the risk.
Confirmed-live credentials at the top of the queue — not 10,000 regex hits.
Validation outcomes separate active credentials from dead matches, criticality scoring ranks what matters, and deduplication collapses noise before it reaches the queue.
Common questions.
Yes — Docker Compose with an nginx proxy, FastAPI backend, and React dashboard. SQLite works out of the box; PostgreSQL is recommended for production.
See everything. Leak nothing.
Deploy Perryscope in your own infrastructure and run your first organization-wide scan — we'll walk you through it.