TruffleHog

A tool that finds and helps remediate exposed secrets and credentials across your entire infrastructure and development pipeline.

Vendor
Truffle Security Co.
Also known as
trufflehog

Available worldwide · Popular in: US

What is TruffleHog?

TruffleHog detects leaked secrets—such as API keys, passwords, and tokens—across version control systems, cloud platforms, chat applications, and other tools in your SDLC. It verifies whether exposed credentials are live and at risk, then helps teams automate remediation.

Independently observed

TruffleHog pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
HybridFree tier

Free tier available; enterprise tiers available via contact

Free

Free
Free

Open-source tier with scanning across GitHub, S3, directories, GCS, and Docker

  • GitHub, S3, directory, GCS, and Docker scanning
  • 800+ secret detectors
  • GitHub actions, pre-commit, and pre-receive hooks
  • Custom regex and secrets verification
  • Automatic updates

TruffleHog Analyze for SaaS

Contact sales
Contact sales

TruffleHog Analyze for Cloud

Contact sales
Contact sales

What TruffleHog does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
DAST (dynamic analysis)
-
SCA / dependency scanning
Secret scanning
Container / image scanning
IaC misconfiguration scanning
-
Governance
OSS licence compliance
-
SBOM generation (SPDX/CycloneDX)
-
Remediation
Automated fix / upgrade PRs
-
Prioritisation
Reachability / exploitability prioritisation
Deployment
Hosting
Cloud + self-hosted
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
-
Licensing
OSS engine available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
  • Linux
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (30)

Independently observed
chat
  • Microsoft Teams
  • Discord
logging
  • Elasticsearch
cloud_storage
  • AWS S3
  • Google Cloud Storage
secrets_management
  • AWS Secrets Manager
authentication
  • GitHub App
  • GitHub
  • GitLab
  • Bitbucket
  • Gerrit
  • Git
  • Docker
  • Artifactory
  • Jenkins
  • Buildkite
  • Azure Repos
  • Travis CI
  • Circle CI
  • Slack
  • Teams
  • Jira
  • Vector
  • Confluence
  • Google Drive
  • S3
  • SharePoint
  • Splunk
  • Webhook
  • Email

TruffleHog FAQ

Common questions about TruffleHog, answered from independent, dated evidence.

What is TruffleHog?

A security tool that scans code repositories, chat systems, artifact storage, and other SDLC platforms for leaked credentials. It verifies which secrets remain active and provides continuous monitoring and remediation guidance. It is indexed under DevSecOps Tools.

Source: https://trufflesecurity.com/pricing

Is TruffleHog free to use?

TruffleHog is open source, so it can be self-hosted and used at no licence cost. It is released under the AGPL-3.0 licence. Pricing changes often, so verify at source before relying on it.

Source: https://trufflesecurity.com/pricing

What platforms does TruffleHog support?

TruffleHog supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://trufflesecurity.com/pricing

Can TruffleHog be self-hosted?

Yes. TruffleHog can be deployed cloud / SaaS, on-premise and self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://trufflesecurity.com/pricing

What does TruffleHog integrate with?

We have confirmed 22 integrations for TruffleHog, including GitHub, GitLab, Bitbucket, Gerrit, Docker, Artifactory, Jenkins and Buildkite, plus 14 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://trufflesecurity.com/pricing

What security certifications does TruffleHog have?

We have independently confirmed GDPR for TruffleHog. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as TruffleHog not holding them. Always confirm compliance directly before you rely on it.

Source: https://trufflesecurity.com/security

Is TruffleHog open source?

Yes. TruffleHog is published under the AGPL-3.0 licence, a copyleft licence, so check its terms before embedding it in a closed-source product. Licence terms can change between releases, so verify against the repository for the version you intend to use.

Source: https://github.com/trufflesecurity/trufflehog

Where is TruffleHog available?

TruffleHog is available worldwide. Its primary market is the United States.

Source: https://trufflesecurity.com/pricing

TruffleHog alternatives

Other devsecops tools we track, ranked by the same independent score.

All TruffleHog alternatives, ranked →

Compare TruffleHog

Side by side against other devsecops tools, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for TruffleHog, not the verdict.

Balanced composite 59 / 100
low · 41%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Capabilities810.065.1
Release cadence960.055.0
Development activity520.094.9
Security score740.043.1
Dependent projects450.062.9
Integrations380.062.4
Stars840.032.2
Security posture50.210.0-
Package downloads00.140.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d43mediumsource · 2026-09-11 · 65%

Adoption

AttributeValueEvidence
Github stars27,789highsource · 2026-09-11 · 90%
Dependent repos519highsource · 2026-08-26 · 85%

Content

AttributeValueEvidence
Faq8 itemsmediumsource · 2026-09-10 · 64%

Features

AttributeValueEvidence
CapabilitiesSca: No · Sast: Yes · Hosting: both · Ci native: Yes · Open source: Yes · Reachability: Yesmediumsource · 2026-09-14 · 60%

Integrations

AttributeValueEvidence
Count20mediumsource · 2026-09-14 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-09-11 · 90%

License

AttributeValueEvidence
SpdxAGPL-3.0highsource · 2026-09-11 · 95%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …mediumsource · 2026-09-14 · 50%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-09-14 · 60%
Modelfreemiummediumsource · 2026-09-14 · 60%
Price levellowmediumsource · 2026-09-14 · 60%
TransparentNomediumsource · 2026-09-14 · 60%

Release

AttributeValueEvidence
Cadence days7mediumsource · 2026-09-11 · 70%
History20 itemsmediumsource · 2026-09-11 · 70%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-01 · 60%
Sla pct99mediumsource · 2026-08-14 · 60%

Security

AttributeValueEvidence
GdprYeshighsource · 2026-09-14 · 75%
Scorecard7.4highsource · 2026-09-11 · 90%
Trust centerhttps://trufflesecurity.com/securitymediumsource · 2026-09-14 · 60%
Still deciding?

Is TruffleHog the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank TruffleHog against the rest of the devsecops tools we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of TruffleHog

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves TruffleHog up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows TruffleHog's independent score and links back to this profile.

TruffleHog, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/trufflehog" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/trufflehog.svg" alt="TruffleHog, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![TruffleHog, verified on vioscaleAI](https://www.vioscale.ai/badge/software/trufflehog.svg)](https://www.vioscale.ai/software/trufflehog)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing TruffleHog. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim TruffleHog

Not the owner? How vendor profiles work