A string that looks like a key.
Is it still a key?
Secret scanners flag anything shaped like a credential, so most of what they find is expired, revoked, or a canary planted to catch a leak. Konvu checks which ones still authenticate and what they open, and closes the rest with the reason attached.
Live, or already dead
Konvu checks whether the credential still authenticates. Expired and revoked keys close.
Canaries, caught
A planted canary looks exactly like a leak to a scanner. Konvu tells them apart.
What the key opens
For a live one, the account it belongs to and the resource type it grants.
One queue, one standard
Assessed beside your dependency, code and container findings, not in a separate tool.
The only question that matters first
An AWS key in a properties file is either an incident or a chore, and the string cannot tell you which. Konvu resolves the account behind it, the resource type, and whether it is a canary. This one was both a canary and not live, so it closed.
Why it was closed, months after it was closed
Every verdict keeps what kind of credential it is, what was found, when the check ran, and the repository, file and commit it came from. An expired token is a defensible dismissal only if that evidence is still there when someone asks.
One triage engine, every finding type
Secrets run through the same investigation, the same evidence standard and the same queue as the rest of your backlog.