Skip to content
Explore documentation

Secret scanning and prompt redaction: where each fits

Finding a key in a repository and replacing it before sending it to an AI assistant solve different problems. When evaluating a tool, start with where it inspects data and what it does with a detection.

What secret scanning inspects

A repository scanner looks for credentials in the content it receives: files, changes or history, depending on its configuration. It can help locate exposures and, when integrated at the right point, prevent certain secrets from entering a commit or push.

Not every product stops at the repository. Some also provide controls for AI agents. Evaluate the specific integration, inspection point and action; a category name alone does not establish coverage.

What prompt redaction inspects

Redaction before transmission inspects the content of a supported request and replaces identified sensitive values. It can act on data that was never stored in Git, such as tool output that becomes part of the assistant's context.

TigerMole applies this control locally in supported workflows. The remaining request content is sent to the provider. It is not a complete scan of repository history, does not remove past exposures and is not guaranteed to recognize every sensitive value.

An example without real credentials

Suppose an assistant receives a test configuration containing an access variable. Excluding the file from Git may keep it out of a commit, but it could still be read during the session. If a tool prints the value, it may enter the request even when the file is not shared directly.

The repository control checks the files or changes within its scope. A request control checks outgoing content on the path it covers. Test both paths with synthetic data; do not infer that one is protected from the result of the other.

Questions to ask before deployment

For a business evaluation, ask for evidence of the actual data path and the limitations of the version you intend to install.

  • Does it inspect files, commits, tool output or requests?
  • Does a detection produce a warning, a block or value substitution?
  • Where is the content processed, and what information is retained?
  • Which clients, versions and formats are covered?
  • How do you recognize an unprotected state and verify coverage after an update?

Combine controls with clear expectations

Keep repository scanning for the content and history within its scope. Reduce agent access to unnecessary secrets. Add local masking where you need to inspect context leaving for AI and a supported integration exists.

Assign an owner to each control and use deployment and verification documentation to repeat the evaluation across devices. Aim to cover specific paths with verifiable results, rather than accumulate tools without understanding their limits.