Catch leaked secrets before attackers do

Keyhound scans your repos for exposed API keys, tokens, and credentials โ€” in your code and your entire git history โ€” then tells you exactly how to fix it.

Install the GitHub App See pricing

Why Keyhound

๐Ÿ•ณ๏ธ

History-deep scanning

A deleted secret still lives in old commits. We scan every blob in your git history โ€” not just the latest diff โ€” so nothing slips through.

๐ŸŽฏ

Low false positives

Regex + Shannon entropy filtering means we flag real secrets, not your variable names. Less noise, more signal.

โšก

One-click remediation

Every alert links straight to the provider's key-rotation page, plus step-by-step fixes and an optional auto-PR.

๐Ÿ›ก๏ธ

Block leaks at commit

Install our pre-commit hook and secrets never even reach GitHub. Stop the leak at the source.

๐Ÿ”’

Private & opt-in

We only scan repos you install us on. Your secrets are masked in every alert and never logged in full.

๐Ÿค

Built on GitHub's model

Same approach as the GitHub Secret Scanning partner ecosystem โ€” legitimate, compliant, and audit-friendly.

# guardian scan ./my-repo
๐Ÿ” Keyhound โ€” 1 secret detected in `my-repo`
| critical | openai_api_key | config.py@a1b2c3d | sk-9****62bb | [Revoke & rotate] |
โ†’ key removed from HEAD but found in commit a1b2c3d (history)
โœ“ Revoke link: https://platform.openai.com/api-keys

Pricing

Free
$0
  • 1 private repo
  • Public repos
  • History scan
  • Email alerts
Pro
$19/mo
  • 10 repos
  • Auto-PR remediation
  • Slack alerts
  • Pre-commit hook
Business
$299/mo
  • Everything in Team
  • SAML SSO
  • Compliance reports
  • SLA

Get started in 2 minutes

1. Install the App

Add Keyhound to your account and pick the repos to protect. Opt-in only.

2. We scan instantly

Working tree + full history. You get a report with every finding, masked and ranked by severity.

3. Fix in one click

Follow the rotation links, accept the auto-PR, and add the pre-commit hook to stay clean.