What is TruffleHog?
TruffleHog uncovers exposed non-human identities (NHIs) and their secrets, helping security teams prioritize risk and remediate faster. It scans for sensitive credentials across source code, chat systems, and cloud platforms.
TruffleHog pricing
Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.
Open source (free). Enterprise pricing available upon request.
Open Source
FreeGitHub, S3, directory, GCS, and Docker scanning with 800+ secret detectors
- GitHub, S3, directory, GCS, and Docker scanning
- 800+ secret detectors
- GitHub Actions, pre-commit, and pre-receive hooks
- Custom regex and secrets verification
- Automatic updates
- On-premises and cloud scanning
Enterprise
Contact salesAdvanced features including continuous monitoring, integrations, SSO, and dedicated support
- 19+ integrations (GitHub, Confluence, Jira, Slack, more)
- Continuous monitoring
- Intuitive dashboard
- Alerting
- Monitor vast public datasets
- Single sign-on (SAML 2.0 or OAuth 2.0)
- Role-based access control
- Deployment and onboarding support
- Ongoing priority technical support
- Detailed analytics and reporting
What TruffleHog does
The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- SAST (static analysis)
- ✓
- DAST (dynamic analysis)
- -
- SCA / dependency scanning
- -
- Secret scanning
- ✓
- Container / image scanning
- ✓
- IaC misconfiguration scanning
- -
- OSS licence compliance
- -
- SBOM generation (SPDX/CycloneDX)
- -
- Automated fix / upgrade PRs
- -
- Reachability / exploitability prioritisation
- ✓
- Hosting
- Cloud + self-hosted
- First-class CI / pipeline integration
- ✓
- In-editor / IDE scanning
- -
- OSS engine available
- ✓
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
- Self-hosted
Integrations (7)
Independently observed- GitHub
- GitLab
- Bitbucket
- Gerrit
- Confluence
- Jira
- Slack
TruffleHog alternatives
Other devsecops tools we track, ranked by the same independent score.
- Endor LabsSpeed or security. The best teams code without compromise.low · 36%
- SemgrepAI-assisted SAST, SCA and Secrets Detectionmedium · 51%
- SnykAI Security Fabricmedium · 60%
- OWASP ZAPThe world's most widely used web app scanner. Free and open source.low · 13%
- MendSecure code, AI, and every interaction between themmedium · 53%
- GitGuardianFind every credential. Stop the next breach.medium · 60%
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for TruffleHog, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Capabilities | 81 | 12.00 | 973.8 | ✓ |
| Github Activity | 53 | 18.00 | 957.8 | ✓ |
| Release Cadence | 94 | 10.00 | 938.9 | ✓ |
| Reliability | 50 | 18.00 | 900.0 | ✓ |
| Price Level | 100 | 8.00 | 800.0 | ✓ |
| Integrations | 38 | 12.00 | 456.3 | ✓ |
| Github Stars | 84 | 5.00 | 418.4 | ✓ |
| Pricing Transparency | 25 | 10.00 | 250.0 | ✓ |
| Security Posture | 0 | 40.00 | 0.0 | - |
| Package Downloads | 0 | 26.00 | 0.0 | - |
| Stackoverflow Activity | 0 | 12.00 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 48 | mediumsource · 2026-08-01 · 65% |
Adoption
| Attribute | Value | Evidence |
|---|---|---|
| Github stars | 27,267 | highsource · 2026-08-01 · 90% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | {"sast":true,"hosting":"both","ci_native":true,"open_source":true,"reachability":true,"secret_scanning":true,"container_scanning":true} | mediumsource · 2026-08-01 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 20 | mediumsource · 2026-08-01 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Go | highsource · 2026-08-01 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | AGPL-3.0 | highsource · 2026-08-01 · 95% |
Pricing
Release
| Attribute | Value | Evidence |
|---|---|---|
| Cadence days | 11 | mediumsource · 2026-08-01 · 70% |
Reliability
| Attribute | Value | Evidence |
|---|---|---|
| Status page | Yes | mediumsource · 2026-08-01 · 60% |