[ MSP.DD ] For investors and founders · Updated
Why check a target's code for leaked secrets?
Short answer
Because leaked keys stay valid for years. GitGuardian counted 23.8 million new secrets pushed to public GitHub in 2024, and 35% of the private repositories it scanned contained plaintext secrets. A key in the git history is exposed even if it was deleted from the latest version.
Why it matters
A leaked cloud, database or payment key can mean data exposure, fraud and regulatory fines after the deal closes, and the buyer owns the problem.
How to check
- 01Scan the full git history, not just the current files.
- 02Check whether any keys found are still active, and have them rotated before closing.
- 03Check how secrets are managed: a secrets manager, or environment files in the repository?
- 04Check CI logs and infrastructure configuration as well as application code.
Red flags
- Live keys anywhere in the history.
- Committed .env files.
- One set of credentials shared by the whole team.
Good signs
- A secrets manager in use.
- Automated secret scanning on every push.
The numbers
- GitGuardian counted 23.8 million new hardcoded secrets added to public GitHub repositories in 2024, a 25% rise on the year before. [1]
- 35% of the private repositories in GitGuardian's customer research contained plaintext secrets. [1]
- 70% of the secrets GitGuardian found leaked in 2022 were still active. [1]