all answers

Tessary

Tessary secret leak

secret_leak is one of Tessary's built-in classifiers, a deterministic credential detector. It reads everything an agent emits, including inner calls whose output reaches logs and downstream prompts, and flags credentials appearing where they shouldn't: provider API keys, private-key blocks, session tokens, and password-like assignments. Ordinary prose about passwords doesn't trigger it.

Detections carry redacted evidence: the pattern name and a short snippet, never the secret itself. Checking every trace costs effectively nothing, and detections go to triage, where the ones ruled real issues become cases.

6 questions

Answered, plainly.

Send us the traces you already emit.