Find exposed secrets in your repositories with Sliyce Leak Scanner
Sliyce scans GitHub repositories, commit history, and dependency manifests to surface accidental leaks, API keys, tokens, and vulnerable packages. Clear findings, actionable remediation, and CI-ready protection.
Continuous codebase security checks
Ensure credentials and API tokens are never exposed in your public or private repositories. Sliyce acts as a dynamic monitor guarding your Git branches.
Scanned repos
100+
Avg scan time
14s
Detected leaks
env, key, token
CI ready
merge guard
Latest repository scan
Updated 5 minutes ago
๐ .env committed in history โ 1 occurrence โ ๏ธ vulnerable dependency found: example@1.2.3 ๐งน orphaned secret in config file
Repo type
Node / JS
Policy status
Blocked
Features
Everything you need to surface leaks and secure code.
Secret & leak detection
Detect accidentally committed env files, API keys, tokens, and private data.
Dependency scanning
Flag known vulnerable packages and risky dependency chains.
Guided remediation
Receive actionable fixes to rotate keys, remove leaks, and harden repos.
CI integration
Block risky merges and keep exposed secrets out of production.
How it works
Scan, detect, and fix leaks in minutes.
Connect your GitHub repo
Read-only connection and no credentials stored.
Scan commits, history, and manifests
Sliyce checks for secrets, config leaks, and vulnerable packages.
Receive a secure findings report
Actionable remediation steps and CI rules to fix leaks fast.
Our Token System
Future-proofing repo security with zero-trust credentials.
Sliyce is developing a decentralized, cryptographically attested token architecture to completely eliminate the need for storing long-lived GitHub access tokens or static API keys.
1. Scan Request
Your CI/CD pipeline or developer terminal requests a repository scan. Instead of sending a static secret key, a temporary transaction handshake is initiated.
FAQ
Common questions about Sliyce
Why choose Sliyce over the competition?+
Traditional scanners rely strictly on narrow signature databases or exact pattern matching, missing complex leaks. Sliyce goes beyond basics by scanning repository commit history, dependency manifests, and configurations to locate accidental leaks that standard tools miss entirely.
Are we the only dedicated option specifically for GitHub?+
Yes, Sliyce is built from the ground up exclusively for GitHub. Rather than offering a generic, multi-provider platform, we focus entirely on native integration with the GitHub ecosystem, including OAuth setups, repository webhooks, pull request branch protections, and CI/CD pipelines.
Do I need technical knowledge to read the security analysis?+
Not at all. We provide an extremely simple security analysis that anyone can read and understand, even without technical knowledge. We strip away complex security jargon and show exactly what is exposed (e.g., API keys or config files) and outline simple, step-by-step instructions to remediate it.
Is Sliyce free to use?+
Yes, standard repository scanning and core leak detection are completely free. Later, we plan to implement paid tokens to unlock advanced security options, automated workflows, and enterprise-scale features.
How long does a scan take?+
Sliyce is built for performance. The average scanning duration for standard repositories is under 15 seconds, ensuring you receive near-instant results for your commits and dependencies.
Are the results accurate?+
We target broad scanning coverage to find every potential leak. While no scanner can be 100% perfect, Sliyce minimizes false alerts and walks you through verifying and resolving every security issue flagged.
Ready to secure your repo?
Start a free scan and stop leaked secrets before they spread.