Leak Check

Check a folder for credential-shaped files before you commit it. The same ruleset the fleet mirror runs fail-closed every night, ported to run here in the browser.

🔒 Nothing is uploaded. Files are read locally and contents are never displayed.

Drop a folder here

or use the buttons below — a whole project directory works best

What it looks for

By filename or path — .env, *htpasswd*, *.pem, *.key, *.p12, *.pfx, *.crt, id_rsa*, id_ed25519*, *_rsa, *_ed25519, *credential*, *secret*, *token*, *oauth*, *client_secret*, *api_key*, *apikey*, *password*, *passwd*, *cookie*, access.log, *.sqlite, *.db, authorized_keys, known_hosts, KEYSDONOTDELETE*.

By folder name — anything inside secrets, .secrets, orders, customers, KEYSDONOTDELETE, or uploads under a private path.

By content (first 8 KB, files under 2 MB) — PEM private-key headers, AWS_SECRET_ACCESS_KEY, and assignments like api_key = … / client_secret: … / password=… where the value runs 16 characters or more.

Deliberately allowed — .env.example, .env.sample, .env.template, and UI routes such as ForgotPassword or reset-password. Placeholder values (changeme, your_…, example, <…>) and bare identifiers on the right-hand side are skipped, since stripe.api_key = stripe_key is code, not a leak. .git directories are ignored.

A hit means shaped like a secret, not proven to be one. It is a stop-and-look list, not a verdict.