Patterns are the fast path
Most real leaks are boring: a provider key in the shape the provider documents. The offline rule pack ships 200+ patterns covering access tokens, refresh tokens, API keys, private key blocks, database URLs and service-account files, matched against file contents as the scan walks your tree.
Because the rules are local and versioned, a finding is reproducible. The same repository, the same rule pack and the same exclusions produce the same report — which is exactly what you need if a scan is part of a release checklist or an audit.
Entropy catches the rest
Custom headers, in-house token formats and obfuscated constants do not match a known shape. For those, the scanner scores character entropy and structure — long, high-entropy strings assigned to variables named like credentials — and reports them separately as candidates rather than confirmations.
That split matters operationally. Confirmed pattern hits should be treated as leaked. Entropy candidates are a review queue, and the tool is honest enough to label them that way.
Gitleaks and TruffleHog rules, on your terms
The scanner ingests Gitleaks and TruffleHog rule sets, so an organisation that standardised on either can align findings without changing tools. Nothing is delegated to those projects: matching runs in-process against the bundled packs.
False positives are managed, not ignored
Learning mode lets you suppress a finding per file, per project or globally, with the reason recorded. That is the difference between a scanner a team keeps using and one they disable after a week of test fixtures tripping on every commit.
Secure memory handling closes the other half of the loop: matched values are masked in the interface and reports, protected regions are zeroed on exit, and candidate secrets are never written to a plaintext temporary file on the way to a report.