What I like best is the secret detection across our Git history. When we ran a historical scan on one of our repositories it surfaced real exposed credentials we had no idea were sitting in the commit history. The alerts are clear and actionable, which made planning the remediation (rotating the secrets and rewriting the Git history) much easier. Onboarding a repo was quick and the scan reports are easy to share with the rest of the dev team. Review collected by and hosted on G2.com.
Remediating secrets that are already committed to history still takes manual work on our side (rotating the credential and rewriting the Git history), which can be intimidating for smaller teams. I'd love even more guided or partly automated remediation steps directly from the dashboard. The volume of alerts can also feel like a lot at first until you tune what matters. Review collected by and hosted on G2.com.
