Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Scan & Detect Exposed Secrets in Code

Code Leak Detector

v2.0.5

Desktop application that scans your entire codebase for accidentally exposed secrets — API keys, tokens, passwords, and other sensitive data. 200+ detection patterns with 100% offline processing.

WINDOWS 10/11200+ PATTERNSREAL-TIME WATCHZERO TELEMETRY
ONE-TIME LICENCE
— ONE-TIME PURCHASE

One-time purchase. No subscriptions, no recurring fees, no account required. Copies obtained during the free period continue to work indefinitely.

At a glance

  • Versionv2.0.5
  • PlatformWindows 10 / 11 · x64
  • Rules200+ offline patterns
  • Licence$29 one-time
  • Recurring feesNone
  • Telemetry0 bytes

Copies obtained during the free period keep working. No account, no activation ping, no subscription.

Key features

Find secrets before they leave your disk

200+ detection patterns covering all major platforms

AWS access keys, GitHub tokens, Slack webhooks, Stripe secret keys, Google API credentials, private RSA/EC keys, JWT secrets, database connection strings, npm tokens, PyPI credentials and hundreds more — all matched locally against an offline rule pack.

100% offline — no data leaves your machine

Every scan runs entirely on your hardware. Source code, detected secrets, scan reports and rule packs never touch the network. There is no cloud analysis tier, no "send for deeper inspection" option, no telemetry pipeline. Verify with any network monitor.

Real-time file watching with instant alerts

Point the watcher at a working directory and receive instant notifications the moment a new secret is written to disk. Catch the leak at the keystroke — before it is staged, committed, or pushed to any remote.

Entropy-based secret detection for custom patterns

Beyond pattern matching, the entropy analyser flags high-randomness strings that look like secrets even when they do not match a known pattern. Catch obfuscated keys, rotated tokens and novel credential formats that rule-based scanners miss.

Advanced capabilities

Beyond pattern matching — enterprise-grade secret scanning

Third-party scanner integrations (Gitleaks, TruffleHog)

Run Gitleaks and TruffleHog rule sets alongside the native engine from a single interface. Combine detection strategies without leaving the application or managing separate toolchains. Results are merged, deduplicated and presented in a unified report.

Deep scan mode for binaries and archives

Secrets hide in compiled binaries, compressed archives and embedded resources. Deep scan mode unpacks ZIP, 7Z, TAR, GZ and JAR files in memory, inspects binary strings and extracts credentials that surface-level scanners never reach.

Learning mode to manage false positives

Mark a finding as a false positive and the learning engine suppresses identical patterns in future scans — per project, per file, or globally. The allowlist is stored locally and never shared. Tune the scanner to your codebase without losing coverage.

Secure memory handling for sensitive data

Detected secrets are held in protected memory regions and masked in every output — the UI, the report, the clipboard. Full values are never written to log files, temporary directories or swap. When the scan ends, the memory is zeroed.

Specifications

Technical details

Code Leak Detector specifications
ProductCode Leak Detector
Versionv2.0.5
PlatformWindows 10, Windows 11
Detection patterns200+ (offline rule pack)
Detection methodsPattern matching + entropy analysis
IntegrationsGitleaks, TruffleHog rule sets
Deep scanBinaries, ZIP, 7Z, TAR, GZ, JAR
Real-time watchFile system watcher with instant alerts
Learning modePer-project, per-file, global allowlists
ReportsJSON, SARIF, CSV — CI-compatible
Pre-commitSupported via CLI hook
Memory safetyProtected regions, zeroed on exit
Processing100% local — no cloud relay
Telemetry0 bytes — verified continuously
Account requiredNone — ever
Price$29 one-time
Developerx2y Devs Tools Ltd, Nairobi, Kenya

Quick start

From install to first scan in four steps

  1. 01

    Install

    Download from itch.io. Run the installer — no administrator privileges required for standard installs. No account creation or subscription. Purchase once for $29.

  2. 02

    Point it at a repository

    Select a working tree, a specific path, or an entire drive. Choose standard or deep scan mode. Enable Gitleaks or TruffleHog rule sets if desired. The rule pack loads from disk — no network fetch.

  3. 03

    Review findings

    Findings appear in the dashboard with masked values, severity tags, file paths and line numbers. Use intelligent filtering to triage by risk level. Mark false positives to train the learning engine.

  4. 04

    Export and remediate

    Export the report as JSON, SARIF or CSV for your CI pipeline. Rotate exposed credentials immediately. Use the pre-commit hook to prevent future leaks from reaching version history.

CLIcld scan ./repo --rules strict --format sarifindexing 1,204 files ......... donematching 200+ patterns ....... offline pack 2026-06findings ..................... 2 (masked) src/deploy.ts:88 api_key ****…xyz123 [high] .env.bak token ****…9f41aa [med]✓ report saved locally · cld-report.sarif · 0 B sent

Downloads

Get Code Leak Detector v2.0.5

One-time $29 licence. Code Leak Detector is a paid product. One-time purchase, no subscriptions, no recurring fees, no account required. Copies obtained during the free period continue to work indefinitely.

Changelog

Release history

JUN 2026v2.0.5

Expanded rule pack to 200+ detection patterns. Entropy-based secret detection for custom and obfuscated patterns. Gitleaks and TruffleHog rule set integration. Deep scan mode for binaries and compressed archives (ZIP, 7Z, TAR, GZ, JAR). Learning mode with per-project, per-file and global allowlists. Real-time file watcher with instant alerts. Secure memory handling with zeroed buffers on exit. SARIF and JSON report export for CI pipelines. Pre-commit hook support.

2026v2.0.0

Report engine rewrite. Intelligent filtering by severity, file type and pattern category. Scan history with trend analysis across multiple runs. Masked value display in all outputs. CSV export added alongside JSON.

2025v1.x

Initial release. Core pattern-matching engine with 80+ rules. Basic scan and report workflow. Manual scan only — no file watcher.

Security model

Your source code and its secrets never leave your machine

Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Source access: only directories you explicitly select. Detected secrets: masked in all outputs, held in protected memory, zeroed on exit. Rule packs: bundled locally, never fetched. Cloud analysis: none — every scan runs on your hardware. Licence: $29 one-time, with no subscription or recurring fee.

Code Leak Detector reads the files you tell it to scan — that is its function. It does not transmit source code, detected secrets, scan reports, file paths, or any other data anywhere. The rule pack is embedded in the installer and exists entirely on your filesystem. Detected secrets are masked in every output surface — the dashboard, the report, the clipboard — and held in protected memory regions that are zeroed when the scan completes. There is no cloud analysis tier, no "send for deeper inspection" option, no analytics SDK, no crash reporter. Verify with Wireshark, Fiddler, GlassWire or your firewall logs — you will observe zero outbound connections.

Security manifest
Telemetry0 bytes collected
AccountNone required — ever
Source accessOnly directories you explicitly select
Detected secretsMasked in all outputs, zeroed on exit
Rule packsBundled locally, never fetched
Cloud analysisNone — all scans local
NetworkZero outbound connections
VerificationAny network monitor

Detection model

How a local scanner finds secrets without reading your code anywhere else

Patterns are the fast path

Most real leaks are boring: a provider key in the shape the provider documents. The offline rule pack ships 200+ patterns covering access tokens, refresh tokens, API keys, private key blocks, database URLs and service-account files, matched against file contents as the scan walks your tree.

Because the rules are local and versioned, a finding is reproducible. The same repository, the same rule pack and the same exclusions produce the same report — which is exactly what you need if a scan is part of a release checklist or an audit.

Entropy catches the rest

Custom headers, in-house token formats and obfuscated constants do not match a known shape. For those, the scanner scores character entropy and structure — long, high-entropy strings assigned to variables named like credentials — and reports them separately as candidates rather than confirmations.

That split matters operationally. Confirmed pattern hits should be treated as leaked. Entropy candidates are a review queue, and the tool is honest enough to label them that way.

Gitleaks and TruffleHog rules, on your terms

The scanner ingests Gitleaks and TruffleHog rule sets, so an organisation that standardised on either can align findings without changing tools. Nothing is delegated to those projects: matching runs in-process against the bundled packs.

False positives are managed, not ignored

Learning mode lets you suppress a finding per file, per project or globally, with the reason recorded. That is the difference between a scanner a team keeps using and one they disable after a week of test fixtures tripping on every commit.

Secure memory handling closes the other half of the loop: matched values are masked in the interface and reports, protected regions are zeroed on exit, and candidate secrets are never written to a plaintext temporary file on the way to a report.

How it works

Scan a repository, review findings, wire it into the workflow

01

Point it at a tree

Choose a working directory, a folder of exports or a release artefact. The indexer enumerates files, skipping binary blobs unless deep scan is enabled.

02

Match and score

The 200+ pattern pack runs first, then entropy scoring over the remaining candidates. Deep scan opens binaries, JARs and compressed archives for the same treatment.

03

Review masked findings

Each hit shows the file, the line, the rule that fired, a severity and a masked value. Nothing sensitive needs to be on screen to decide whether it is real.

04

Export and remediate

Write JSON, SARIF or CSV. Pre-commit hooks and CI steps consume the same exit codes, so a new tracked secret can fail the commit rather than the release.

Technical summary
Scan modesOn-demand, scheduled watching, deep scan
Watch modeFile-system watcher with instant alerts on new exposures
Report formatsJSON · SARIF · CSV
Hook supportPre-commit, CI pipeline steps
SuppressionPer-file, per-project and global allowlists
Memory safetyMasked display, buffers zeroed on exit
Finding a secret is the beginning, not the end. Rotating the credential is mandatory, because anything committed to a public repository should be treated as already collected. Then decide whether history needs rewriting — git rm --cached removes a file from tracking, not from previous commits.

Who it is for

Teams that cannot afford one careless commit

Six situations where a local scanner earns its licence fee once.

Agencies shipping client code

Prove that a repository handed over clean stayed clean, with a dated SARIF report instead of a promise in an email.

Pre-release and open-sourcing checks

Flipping a private repository to public is the single most common way a project leaks. Scan before the toggle, and again in CI afterwards.

Security and platform teams

A desktop scanner your developers can run themselves beats a queue for the central tooling team, and never sees the source.

Contractors and consultants

One-time licence, no seat subscription. Scan a client repository on the client's machine, offline, in minutes.

Archives, backups and old exports

Deep scan reads inside ZIP, 7Z, TAR, GZ and JAR files, where abandoned credentials hide longest and are least likely to be rotated.

Incident response and forensics

When a repository may already be public, the scanner's job is to enumerate every candidate so your rotation list is complete rather than guessed.

Prerequisites

Environment, integrations and licence terms

Code Leak Detector prerequisites and licence terms
RequirementMinimumRecommended
Operating systemWindows 10 (64-bit)Windows 11 (64-bit)
Target of a scanA local folder or working treeA Git working tree plus its checked-out artefacts, so build outputs get covered too
PrivilegesStandard user accountNo service install needed; run it as the developer who owns the repository
NetworkNone — every byte is processed locallyA connection only to download the installer and the rule-pack update
CI usageReports consumed as artefactsPre-commit hook plus a pipeline gate using the same exit codes
Existing scannersFine to run alongside Gitleaks or TruffleHogImport their rule sets so findings converge instead of competing
Licence$29 one-time per licenceReinstall and move machines freely — there is no activation server to phone
Price changes are documented, not hidden. Code Leak Detector moved to a one-time $29 licence on 1 September 2026 after a free period; it has no subscription and no recurring charge, and every other product in the suite remains free.

Context

Local desktop scanner versus hosted and DIY options

Where each approach genuinely wins.

Comparison of local, hosted and scripted secret scanning
ConcernCode Leak DetectorHosted secret scanningRegex in a build script
Where code goesNowhere — in-process on your machineUploaded or indexed by the providerLocal, but you maintain the rules
Rules maintenanceVersioned offline pack, importable third-party packsProvider-managed and opaqueWhatever your team remembers to update
Archives and binariesDeep scan inside ZIP, 7Z, TAR, GZ, JARUsually source files onlyRarely handled
Finding shapeConfirmed hits plus entropy candidatesProvider severity modelWhatever your regex matches
Blocking a commitPre-commit hook with exit codesPlatform-dependent, needs account/APIPossible, fully yours to break
Cost$29 one-time (the suite's only paid tool)Often per-seat SaaSEngineering hours

Questions

Answers that decide the purchase

No. Detection runs in-process against the bundled rule packs, with no cloud relay and no vendor endpoint to call. The report you export is the only artefact the tool produces, and it goes wherever you put it. That is verifiable: run the scanner under any network monitor and watch it stay silent.
It is a one-time $29 licence with no subscription, no recurring fee and no account required. Copies obtained during the free period continue to work indefinitely. Full terms are in the Terms of Use.
It scans what is on disk — working trees, build output, exports and archives. For history you should combine it with your own repository review: anything already committed is presumed public, so rotation matters more than archaeology.
No, and it does not try to. Push-time scanning on a forge only sees the moment a secret arrives; it does not audit the whole tree, archives or a repository you are about to open source. Treat them as independent layers — a local scan is also the only option for repositories that never touch a hosted forge.
200+ patterns covering all major cloud providers, SaaS platforms, private key blocks, database connection strings and service-account files, plus entropy-based scoring for custom and uncommon formats. Gitleaks and TruffleHog rule sets can be imported if your team already standardised on them.
Learning mode. Suppress a finding per file, per project or globally, with the reason recorded, so legitimate sample keys stop producing noise without hiding a real credential in a different location.
Yes — the same report formats (JSON, SARIF, CSV) and exit codes work as a pipeline gate, and SARIF is consumed natively by the common code-scanning dashboards. Pre-commit hooks cover the local half of that.
Rotate first, then remove, then verify. Revoke and reissue the credential, take it out of the file, and remember that git rm --cached untracks a file without erasing previous commits. If the repository was ever public or shared, assume the secret is known.

Ready to scan

Purchase Code Leak Detector — $29 one-time

No subscriptions. No recurring fees. No account. One payment, permanent licence. Find exposed credentials at the keystroke — entirely on your machine.

Summary
Versionv2.0.5
PlatformWindows 10 / 11
Price$29 one-time
Telemetry0 bytes