Your .env just got committed. Again.

Pre-commit secret detection that catches leaked credentials before they hit git. 76 patterns. 100% local. Zero telemetry.

$ brew install lefthook && clawhub install envguard click to copy
$ git commit -m "add config"
 
🔐 EnvGuard: Scanning staged files...
 
  !! CRITICAL  config/aws.js:12  AWS Access Key
     Match: AKIA****...****3QWZ
 
  !  HIGH      .env.prod:3      Database URI
     Match: post****...****5432/db
 
  2 secrets found (1 critical, 1 high)
  Commit blocked. Run 'envguard scan' for details.

One commit. One leaked AWS key. $240,000 in charges.

Secrets leak every day through accidental commits. By the time you notice, attackers have already used them. EnvGuard stops the leak at the source.

4 min
Avg. time to exploit a leaked key
$4.45M
Avg. cost of a credential leak
19%
of repos with exposed secrets

Three steps to bulletproof commits

1

Install

One command sets up EnvGuard and hooks into your git workflow via Lefthook.

brew install lefthook && envguard hooks install
2

Code

Write code normally. EnvGuard silently watches your staged files every time you commit. Zero friction.

3

Block

If a secret is detected, the commit is blocked instantly with clear remediation steps. No secrets reach git.

Everything you need to stop secret leaks

🔍

76 Secret Patterns

Detects AWS, Stripe, GitHub, Slack, Google, Firebase, database URIs, private keys, and dozens more out of the box.

🪝

Pre-commit Hooks

Blocks secrets before they ever reach git. Integrates with Lefthook for zero-config hook management across your team.

Allowlist Management

Suppress false positives with file-level and pattern-level allowlists. Stays out of your way on known-safe patterns.

📜

Git History Scanning

Find secrets already buried in your repo history. Scan every commit to identify credentials that were committed in the past.

📊

SARIF Reports

Generate compliance-ready SARIF output for integration with GitHub Code Scanning, Azure DevOps, and audit workflows.

🔧

Custom Patterns

Define your own secret formats with regex. Catch internal tokens, proprietary API keys, and organization-specific credentials.

How EnvGuard compares

Feature EnvGuard GitGuardian Gitleaks TruffleHog
Price Free / $19 / $39 $50/dev/mo Free (OSS) Free (OSS)
Runs Locally (SaaS)
Pre-commit Hook
Zero Telemetry
Git History Scan
SARIF Reports
Custom Patterns
License Compliance (via DepGuard)
Built-in Patterns 76+ 350+ ~150 ~700

Simple, transparent pricing

Start scanning for free. Upgrade for pre-commit protection.

Free
$0
  • One-shot secret scanning
  • CLI tool
  • 76 built-in patterns
  • Markdown report output
Install Free
Team
$39/user/mo
  • Everything in Pro
  • Git history scanning
  • SARIF reports
  • Custom patterns
  • Policy enforcement
  • Compliance reporting
Get Team

Get notified about updates

No spam. One email per week max. Unsubscribe anytime.

Your next commit could leak a secret

Install EnvGuard in 30 seconds. Free, local, and silent until it matters.

$ brew install lefthook && clawhub install envguard click to copy