Find sensitive data before it finds its way out.

Perryscope detects exposed credentials and regulated personal data across your GitHub organization, documents, images, and the text your teams paste into AI tools — then validates, classifies, and drives every finding through an audited remediation workflow. Self-hosted. Your data never leaves your infrastructure.

Request a demoExplore the architecture →
100% self-hosted encrypted at rest (AES-256-GCM) every reveal audited no LLM in the decision path SARIF 2.1.0 output enterprise ready
The problem

Sensitive data leaks from every surface your teams touch.

Traditional answers each cover a fragment: open-source scanners flag matches but can't tell you which credentials are still live. SaaS platforms manage findings — after you send them your secrets. DLP suites watch email and endpoints but were never built for repositories or AI prompts. The result is alert fatigue in one place and blind spots everywhere else.

Repositories remember everything

Credentials committed to Git remain in history long after the file is deleted — in HEAD, branches, CI/CD workflows, and every past commit.

Regulated data drifts everywhere

Names, card numbers, medical records, and government IDs end up in source code, log fixtures, PDFs, and screenshots.

AI tools sit outside the perimeter

Every day, employees paste code and customer data into AI chat tools that your security stack never sees.

The platform

One platform. Three products. Every finding accountable.

Detection is multi-signal — pattern matching, Shannon entropy, and contextual analysis — so confidence scores mean something. Discovered credentials are validated against live provider APIs. Regulated data is classified and mapped to GDPR, HIPAA, PCI DSS, and DPDP the moment it's found. And every finding enters an audited workflow — deduplicated, owner-resolved, risk-scored, escalated, and verified through closure.

DashboardReact 18 + TSnginxreverse proxyFastAPI platformjobs · auth · cryptoaudit · events · metricsplugin engine managerscan pipelineprivacy pipelineagent workflowDatabaseSQLite / PostgresEscalationSlack · Email · JiraGovernance syncSimpleRisk · CISO AssistantWebSocket eventsAI Guardienneruns in the browseroffline · 0 network callssame detection math as the server
Platform / Shared / Products — the platform layer knows nothing about secrets or privacy; products plug in through registries and engine interfaces.
Products

Three products. One substrate.

Capabilities

Built for evidence, not noise.

Detect secrets. Then prove which ones are live.

200+ patterns combined with Shannon entropy and context scoring. Findings arrive labeled LIVE_VALID, DEAD_INVALID, or UNVERIFIED — not just “matched a regex.”

HEAD, branches, workflows, and full history.

Shallow scans need no clone; deep scans walk complete commit history. Cross-scan deduplication means a credential seen in ten scans is one finding, not ten.

Regulated data, classified at detection time.

Presidio NLP plus recognizers for Indian identifiers, financial data, and healthcare records — checksum-validated, tagged GDPR / HIPAA / PCI DSS / DPDP.

Scan what your organization actually leaks.

PDFs — native, scanned, or mixed — DOCX including tables, plain-text formats, and screenshots through OCR with per-finding bounding boxes.

From detection to verified closure.

A 21-state workflow: deduplication, ownership resolution, validation, approval gates, remediation, escalation, and verified closure — with append-only timelines.

Decisions you can audit, not guess at.

A rule-based engine routes every validated finding. No LLM sits in the decision path — language models are confined to optional plain-English explanations.

Findings meet your existing workflow.

Slack Block Kit alerts, email, and Jira tickets. A governance worker pushes confirmed findings into SimpleRisk or CISO Assistant — idempotently.

Shift left without the friction.

A pre-commit CLI blocks secrets at commit time. SARIF 2.1.0 uploads straight into GitHub Code Scanning. OpenAPI REST + WebSocket events power any integration.

Built like the security tool it is.

Encryption at rest under your keys with rotation. Reveals require written justification, are rate-limited, and land in an immutable audit log.

Detection coverage

What Perryscope finds.

Secrets & credentials

AWS · Azure · GCP keysGitHub PATsSSH keysStripe keysDB connection stringsPEM · OpenSSH · PuTTYJWTs · OAuth · bearer tokensHardcoded passwordsUnknown high-entropy secrets

Personal & regulated data

PII — names · emails · SSNsPHI — MRNs · diagnosesPCI — Luhn-validated cardsIBAN · SWIFT · routingAadhaar · PAN · GSTINUPI · IFSCVoter ID · driving licenseChecksum-validated
Finding lifecycle

Twenty-one states. Seven phases. Zero guesswork.

Every finding is a stateful work item, moved by a deterministic transition table. Hover a phase to see its constituent states.

Detect
Dedup & own
Validate
Decide
Approve
Remediate & escalate
Verify & close
Why Perryscope

Architectural answers, not marketing claims.

vs. open-source scanners

TruffleHog, Gitleaks, and detect-secrets detect and exit. Perryscope validates against live provider APIs, persists findings, deduplicates across scans, and manages them through an audited workflow with escalation and verification.

vs. SaaS secret managers

Comparable management capabilities — validation, workflows, dashboards — but self-hosted, so secrets and personal data never leave your infrastructure, under enterprise licensing that fits your organization.

vs. platform-native scanning

Broader pattern surface, live validation, deep history scans by default — plus privacy/compliance scanning and browser DLP that platform-native tools don't attempt.

vs. traditional DLP suites

Built for the surfaces DLP ignores — Git history, CI/CD workflows, developer commits, and AI chat prompts — with detection tuned for code and structured identifiers.

See the full comparison →
Who it serves

Built for the people who carry the risk.

Confirmed-live credentials at the top of the queue — not 10,000 regex hits.

Validation outcomes separate active credentials from dead matches, criticality scoring ranks what matters, and deduplication collapses noise before it reaches the queue.

What they get
validation outcomescriticality scoringdedupSlack escalation
FAQ

Common questions.

Yes — Docker Compose with an nginx proxy, FastAPI backend, and React dashboard. SQLite works out of the box; PostgreSQL is recommended for production.

Read the full FAQ →

See everything. Leak nothing.

Deploy Perryscope in your own infrastructure and run your first organization-wide scan — we'll walk you through it.

Request a demoRead the documentation