VentureUnderwriting

Acquisition Due Diligence

Assess a target company's public repositories for leaked credentials before you buy.

GitHub leaks · 1 credit per leak per lookup · no monthly fee

Target reposRisk: med
14 repos2 with leaks

How it works

1

Send the repository

Call the GitHub leaks endpoint with a public repository URL. Encrata clones the code and full git history.

2

We scan for secrets

Every commit is scanned for hardcoded API keys, tokens and private keys, including secrets removed in later commits.

3

Rotate what leaked

Get each finding with its file, line and severity, so you can rotate the exposed credentials fast. One credit per leak found.

One call, structured answer

Acquisition Due Diligence runs on the github leaks lookup at 1 credit per leak per lookup. Same API key, same JSON shape as every other Encrata lookup.

  • Scans the full git history, not just the current HEAD
  • Finds API keys, tokens and private keys with file and line context
  • A clean repository costs nothing, you only pay per leak found
  • Findings export cleanly into your ticketing and remediation flow
Terminal
curl -X POST "https://developer.encrata.com/api/breaches/github" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"repo": "https://github.com/acme/checkout"}'
response.json
{
"repo": "acme/checkout",
"findings": [
{ "rule": "aws-access-key", "severity": "critical", "path": "config/prod.env", "line": 12 }
],
"credits": 1
}

More github leaks use cases

View all
Start with 500 free credits
$curl https://developer.encrata.com/api/lookup -H "Authorization: Bearer YOUR_API_KEY" -d '{"e": "satya@microsoft.com"}'