TruffleHog

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

TruffleHog is ranked #4 of 19 in secrets scanning software on Inferse. It runs on Linux, macOS, Self-hosted, Windows. There is a free plan.

Compared on secrets scanning software

Free plan
Yestrufflesecurity.com
Supported VCS
GitHub, GitLab, Git, Bitbucket, Gerrit, Azure Repostrufflesecurity.com
CI/CD scanning
Yestrufflesecurity.com
Pre-commit scanning
Yestrufflesecurity.com
Pull-request scanning
Yestrufflesecurity.com
Push protection
Yestrufflesecurity.com
Custom detection rules
Yestrufflesecurity.com

Facts

Purpose
TruffleHog scans code repositories and other sources to find exposed secrets, passwords, and sensitive keys.trufflesecurity.com · 30 Sept 2026
Detection
It scans version history across branches and can find secrets in comments, Docker images, and other locations beyond repositories.trufflesecurity.com · 30 Sept 2026
Verification
For detected credentials, TruffleHog uses their protocol or API to verify whether they are live and reduce false positives.trufflesecurity.com · 30 Sept 2026
Analysis
TruffleHog Analyze identifies the resources and permissions associated with API keys and other secrets without requiring access to a provider’s UI.trufflesecurity.com · 30 Sept 2026
Prevention and remediation
Pre-commit and pre-receive hooks can scan before commits, and alerts can link to credential rotation and security guides.trufflesecurity.com · 30 Sept 2026
Integrations
The integrations page lists GitHub, GitLab, Bitbucket, Gerrit, Docker, Jenkins, Slack, Teams, Jira, Confluence, Google Drive, S3, and SharePoint, among others.trufflesecurity.com · 30 Sept 2026
Notifications
When a secret is discovered, TruffleHog can send a Slack message, create a Jira ticket, or use Splunk, webhooks, email, and stdout.trufflesecurity.com · 30 Sept 2026
Secret handling
The company says scanning occurs in memory and it stores only finding location metadata and redacted credential information, not the secrets themselves.trufflesecurity.com · 30 Sept 2026
Deployment security
The company says each customer installation has a private environment and isolated database encrypted at rest, and deployments receive randomly generated infrastructure credentials.trufflesecurity.com · 30 Sept 2026
Deployment options
The product can run on the company’s isolated servers or on-premises, where scanners can reach internal sources and source credentials can remain in the customer’s infrastructure.trufflesecurity.com · 30 Sept 2026
Support
The Enterprise plan lists deployment and onboarding support plus ongoing priority technical support.trufflesecurity.com · 30 Sept 2026
Open-source license
The project’s GitHub repository identifies its license as AGPL-3.0.github.com · 30 Sept 2026
Operating systems
The project documents Homebrew installation for macOS, Windows Docker examples, and binary releases; its installer supports Darwin, Linux, and Windows on amd64 and arm64.github.com · 30 Sept 2026
Company
Truffle Security Co. identifies itself as the company behind TruffleHog, and its website footer says “Since 2021.”trufflesecurity.com · 30 Sept 2026

Company

Founded
2021trufflesecurity.com · 23 Sept 2026

Best TruffleHog alternatives

See all 12

Where it ranks on Inferse

Sources