# TruffleHog

> Make secrets easier

- **Canonical URI:** https://www.vioscale.ai/software/trufflehog
- **Category:** DevSecOps Tools
- **Homepage:** https://trufflesecurity.com
- **Also known as:** trufflehog
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-01T16:09:48.771Z

## Vioscale score

**61.2 / 100**, confidence 26% (low).

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| price_level | 100 | 8 | 800 | ✓ |
| reliability | 50 | 18 | 900 | ✓ |
| capabilities | 81.2 | 12 | 973.8 | ✓ |
| github_stars | 83.7 | 5 | 418.4 | ✓ |
| integrations | 38 | 12 | 456.3 | ✓ |
| github_activity | 53.2 | 18 | 957.8 | ✓ |
| release_cadence | 93.9 | 10 | 938.9 | ✓ |
| security_posture | 0 | 40 | 0 | - |
| package_downloads | 0 | 26 | 0 | - |
| pricing_transparency | 25 | 10 | 250 | ✓ |
| stackoverflow_activity | 0 | 12 | 0 | - |

## Pricing

_As of 2026-08-01, [verify at source](https://trufflesecurity.com). Independently observed._

Open source · Free tier

> Open source (free). Enterprise pricing available upon request.

| Plan | Price | Free | Commitment |
|---|---|:--:|---|
| Open Source | Free | ✓ | - |
| Enterprise | Contact sales | - | - |

### Open Source

GitHub, S3, directory, GCS, and Docker scanning with 800+ secret detectors

- GitHub, S3, directory, GCS, and Docker scanning
- 800+ secret detectors
- GitHub Actions, pre-commit, and pre-receive hooks
- Custom regex and secrets verification
- Automatic updates
- On-premises and cloud scanning

### Enterprise (Contact sales)

Advanced features including continuous monitoring, integrations, SSO, and dedicated support

- 19+ integrations (GitHub, Confluence, Jira, Slack, more)
- Continuous monitoring
- Intuitive dashboard
- Alerting
- Monitor vast public datasets
- Single sign-on (SAML 2.0 or OAuth 2.0)
- Role-based access control
- Deployment and onboarding support
- Ongoing priority technical support
- Detailed analytics and reporting

## About

TruffleHog uncovers exposed non-human identities (NHIs) and their secrets, helping security teams prioritize risk and remediate faster. It scans for sensitive credentials across source code, chat systems, and cloud platforms.

_Independently observed._

## Platform & deployment

- **Platforms:** CLI, Web
- **Deployment:** Cloud / SaaS, Self-hosted

## Integrations (7)

_Independently observed._

- GitHub
- GitLab
- Bitbucket
- Gerrit
- Confluence
- Jira
- Slack

## Capabilities

_The capabilities that matter for DevSecOps Tools. "-" = undocumented, not absent._

| Capability | Supported |
|---|:--:|
| **Scan types** | |
| SAST (static analysis) | ✓ |
| DAST (dynamic analysis) | - |
| SCA / dependency scanning | - |
| Secret scanning | ✓ |
| Container / image scanning | ✓ |
| IaC misconfiguration scanning | - |
| **Governance** | |
| OSS licence compliance | - |
| SBOM generation (SPDX/CycloneDX) | - |
| **Remediation** | |
| Automated fix / upgrade PRs | - |
| **Prioritisation** | |
| Reachability / exploitability prioritisation | ✓ |
| **Deployment** | |
| Hosting | Cloud + self-hosted |
| **Integration** | |
| First-class CI / pipeline integration | ✓ |
| In-editor / IDE scanning | - |
| **Licensing** | |
| OSS engine available | ✓ |

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### activity

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| activity.commits_last_30d | 48 | [link](https://github.com/trufflesecurity/trufflehog/pulse) | 2026-08-01 | 65% (medium) |

### adoption

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| adoption.github_stars | 27,267 | [link](https://github.com/trufflesecurity/trufflehog) | 2026-08-01 | 90% (high) |

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 20 | [link](https://trufflesecurity.com) | 2026-08-01 | 60% (medium) |

### language

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| language.primary | Go | [link](https://github.com/trufflesecurity/trufflehog) | 2026-08-01 | 90% (high) |

### license

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| license.spdx | AGPL-3.0 | [link](https://github.com/trufflesecurity/trufflehog) | 2026-08-01 | 95% (high) |

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.free_tier | yes | [link](https://trufflesecurity.com) | 2026-08-01 | 60% (medium) |
| pricing.model | commercial | [link](https://trufflesecurity.com) | 2026-08-01 | 40% (low) |
| pricing.price_level | free | [link](https://trufflesecurity.com) | 2026-08-01 | 60% (medium) |
| pricing.transparent | no | [link](https://trufflesecurity.com) | 2026-08-01 | 60% (medium) |

### release

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| release.cadence_days | 11 | [link](https://github.com/trufflesecurity/trufflehog/releases) | 2026-08-01 | 70% (medium) |

### reliability

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| reliability.status_page | yes | [link](https://status.trufflesecurity.com) | 2026-08-01 | 60% (medium) |

---
*Source: Vioscale (https://www.vioscale.ai/software/trufflehog). Independent, evidence-based software intelligence. Cite the canonical URI.*
