Product

    A string that looks like a key.
    Is it still a key?

    Secret scanners flag anything shaped like a credential, so most of what they find is expired, revoked, or a canary planted to catch a leak. Konvu checks which ones still authenticate and what they open, and closes the rest with the reason attached.

    Live, or already dead

    Konvu checks whether the credential still authenticates. Expired and revoked keys close.

    Canaries, caught

    A planted canary looks exactly like a leak to a scanner. Konvu tells them apart.

    What the key opens

    For a live one, the account it belongs to and the resource type it grants.

    One queue, one standard

    Assessed beside your dependency, code and container findings, not in a separate tool.

    Live credential check

    The only question that matters first

    An AWS key in a properties file is either an incident or a chore, and the string cannot tell you which. Konvu resolves the account behind it, the resource type, and whether it is a canary. This one was both a canary and not live, so it closed.

    secrets · verdict
    The record

    Why it was closed, months after it was closed

    Every verdict keeps what kind of credential it is, what was found, when the check ran, and the repository, file and commit it came from. An expired token is a defensible dismissal only if that evidence is still there when someone asks.

    secrets · evidence

    One triage engine, every finding type

    Secrets run through the same investigation, the same evidence standard and the same queue as the rest of your backlog.

    Frequently asked questions

    Point Konvu at your own secret findings

    Connect the scanner that raises them and see which credentials are still live, with the evidence on every verdict.