qualitylab

Adversarial exposure · Feedback latency

A detected secret is revoked automatically, on a clock

tier II/cost to adopt: medium/active

Finding a committed credential does not remove the exposure — over 90% of leaked secrets were still valid five days after leaking — so revocation has to be automatic and time-bounded rather than a task assigned to whoever owns it.

Do this firstNo secret is ever committed, and something checks

The gap this closes is between knowing and acting, and it is much larger than anyone assumes before they measure it.

The detection half is solved: scanning a billion commits a year finds millions of secrets, and the owners get told. What happens next is the finding. Most credentials stay live for days after their exposure is known and reported, because revoking one means finding every consumer, rotating them, and risking an outage — a task that is never the most urgent thing on anyone’s list.

So the control is not “rotate secrets”. It is that rotation is mechanical and on a deadline, which is the same shape as a quarantined test with an expiry and a flag with a removal date. Every one of those exists because the manual version was measured and did not happen.

The decoy

An alert to the owner. It was measured at scale: 1.8 million notification emails, and 2.6% of leaks revoked within an hour. Detection that ends in a human being told is not a control, it is a statistic.

Evidence

Last reviewed 2026-08-19.