docs/documentation/platform/secret-scanning/overview.mdx
Infisical Secret Scanning helps teams detect leaked credentials — such as API keys, database passwords, and tokens — across source code and developer systems. It allows organizations to proactively catch exposed secrets before they can be exploited, and respond quickly when incidents occur.
Secret Scanning works across both cloud-connected repositories and local developer environments. It integrates with data sources like GitHub, GitLab, and Bitbucket to monitor repositories for exposed secrets in real time, and provides a CLI (infisical scan) for scanning local directories, Git history, or CI pipelines before changes are pushed.
Core capabilities include: