What is Tessary's secret_leak classifier?

It’s a deterministic check that reads everything an agent emits, including inner calls whose output reaches logs and downstream prompts, and flags credentials sitting where they shouldn’t.

It looks for the shape of a live credential: provider API keys, private-key block headers, session tokens, and password-like assignments such as api_key= or password:. Ordinary prose about passwords doesn’t trigger it, because the check is anchored on what a credential looks like rather than on the word showing up nearby.

A detection carries redacted evidence, the pattern name and a short snippet, never the secret itself. That is also the limit: it tells you a credential was emitted, not what the credential was or who now has it. The detection writes a finding, and triage rules on it.

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y