SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
Secrets · Code & secrets
Catch the key before the merge.
Keys and tokens before they leave the building.
WatchedRepositories and historyWatchedPull requestsWatchedCI logsWhat it closes.
0 of 4 closed
01Open
Push checks
Every push and pull request is scanned for 310 kinds of key before it lands.
02Open
History sweep
The full history of every repository, wiki and ticket, not only today's diff.
03Open
One-click revoke
The key is revoked at the provider and the owner gets a new one, in the same thread.
04Open
Beyond code
Keys pasted into chat, tickets and docs are found the same way.
Every push to GitHub and GitLab is scanned for API keys, tokens and private certificates. When one turns up in a public repository, Palisade tells the owner, checks whether the key is still live and can revoke it for you.
What it closes
- Live keys in public and private repositories
- Tokens pasted into tickets and chat
- Certificates about to expire
What you get in week one
- Live keys in your repository history
- Keys pasted into chat and tickets
- A check on every new pull request
How it connects
A GitHub or GitLab app with read access to code and write access to checks only. Found keys are stored as fingerprints, never in full.
Secrets · Code & secrets
Catch the key before the merge.
Keys and tokens before they leave the building.

What it closes.
0 of 4 closed
01Open
Push checks
Every push and pull request is scanned for 310 kinds of key before it lands.
02Open
History sweep
The full history of every repository, wiki and ticket, not only today's diff.
03Open
One-click revoke
The key is revoked at the provider and the owner gets a new one, in the same thread.
04Open
Beyond code
Keys pasted into chat, tickets and docs are found the same way.
Every push to GitHub and GitLab is scanned for API keys, tokens and private certificates. When one turns up in a public repository, Palisade tells the owner, checks whether the key is still live and can revoke it for you.
What it closes
- Live keys in public and private repositories
- Tokens pasted into tickets and chat
- Certificates about to expire
What you get in week one
- Live keys in your repository history
- Keys pasted into chat and tickets
- A check on every new pull request
How it connects
A GitHub or GitLab app with read access to code and write access to checks only. Found keys are stored as fingerprints, never in full.
Secrets · Code & secrets
Catch the key before the merge.
Keys and tokens before they leave the building.
WatchedRepositories and historyWatchedPull requestsWatchedCI logsWhat it closes.
0 of 4 closed
01Open
Push checks
Every push and pull request is scanned for 310 kinds of key before it lands.
02Open
History sweep
The full history of every repository, wiki and ticket, not only today's diff.
03Open
One-click revoke
The key is revoked at the provider and the owner gets a new one, in the same thread.
04Open
Beyond code
Keys pasted into chat, tickets and docs are found the same way.
Every push to GitHub and GitLab is scanned for API keys, tokens and private certificates. When one turns up in a public repository, Palisade tells the owner, checks whether the key is still live and can revoke it for you.
What it closes
- Live keys in public and private repositories
- Tokens pasted into tickets and chat
- Certificates about to expire
What you get in week one
- Live keys in your repository history
- Keys pasted into chat and tickets
- A check on every new pull request
How it connects
A GitHub or GitLab app with read access to code and write access to checks only. Found keys are stored as fingerprints, never in full.
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected