Triage leaked credentials.
Notify owners the right way.
Redactpoint turns a scraped hit list into a reviewable queue: each finding scored offline for whether it is worth a disclosure, kept redacted, and routed to the correct channel — with a draft that names the location and never the secret.
offline scoring · no live-key checks · no raw secrets in drafts · manual send only
| Score | Recommendation | Repo | Path | Detected | Status |
|---|---|---|---|---|---|
| 92 | Send it | acme/payments-api | config/prod.env | aws_access_key | new |
| 78 | Send it | northwind/mobile-app | ios/Release.xcconfig | stripe_secret | drafting |
| 54 | Needs review | jdoe/thesis-ml | notebooks/train.ipynb | mnemonic_phrase | new |
| 18 | Do not send | acme/docs-site | examples/keys.md | hex_private_key | ignored |
Fragments stay masked in this view. A disclosure draft for the first row would cite config/prod.env and its commit SHA — and contain no key material.
Workflow
Four steps, and you approve each one
The console does the reading and the bookkeeping. The judgement calls — what is worth sending, and when — stay with you.
Import the hit list
Paste CSV, drop a file, or upload the PDF your scan produced. Rows are parsed in your browser, validated, and written only to your own account under row-level security.
Score before you send
Every row is scored 0–100 on format, entropy, word structure, and deployment path — offline. Weak shapes, placeholders, and test vectors drop to the bottom so you never burn credibility on a dud.
Route to the right channel
The tool resolves the correct path per finding: repo SECURITY.md, GitHub private vulnerability reporting, the org's security contact, and the issuing provider's own revocation page.
Draft, review, send yourself
A disclosure draft is generated per finding naming the location, commit, and remediation — never the value. It opens in your mail client or the advisory form. You send it. Nothing goes out automatically.
Inside the console
Built so a disclosure holds up later
CSV & PDF import
Permissive CSV parsing plus in-browser PDF text extraction, with skipped-line warnings before anything is written.
Offline confidence scoring
Issuer format match, Shannon entropy, BIP-39 word structure, JWT expiry, path context, and known test vectors — no network calls.
Redaction by default
Fragments are masked in the UI. Revealing one is a deliberate click and lands in the audit trail with a timestamp.
Channel resolution
SECURITY.md, private vulnerability reporting, org security contact, or a public issue as the last resort — in that order.
Provider revocation
For recognized formats — AWS, Stripe, GitHub, Google, OpenAI, Slack, SendGrid, Twilio, Mailgun — the issuing provider's revocation path is surfaced alongside the owner contact.
Audit trail
Status transitions, reveals, draft generation, and notes are recorded per finding, so your outreach is reconstructable months later.
Ground rules
What this tool will not do
These are enforced in the code, not left to goodwill. A disclosure tool that can quietly become an exploitation toolkit is a liability to the people it contacts.
- 01
No live-key validation. The tool never derives wallet addresses, queries balances, or test-calls API providers. Operating on a leaked secret before its owner knows is pre-theft recon, not research — and it is the fastest way to become the suspect.
- 02
No raw secret in any generated message. Drafts reference the file, commit, and type. The owner and the issuing provider already have the value when it matters; the recipient does not need it to act.
- 03
Manual send only. Drafts open in your mail client or the correct advisory form for you to review and send. There is no bulk outbound, no scheduled mail, and no templated mass contact.
- 04
Prefer the issuing provider. For recognized key formats, revoking at the provider is usually faster and safer than waiting on a repo owner who may have left the project.
For repo owners
If a disclosure from Redactpoint reaches you
What a disclosure contains
- The repository and file path, and the commit SHA where the item appears.
- The detected type and a masked preview, e.g. AKIA••••••••••••••3F.
- Why it is a problem, and how to remove it: git filter-repo or the BFG repo cleaner, then rotate.
- Where to send confirmation, and an offer to re-check after you rotate.
What it never contains
- The secret value, in any form — not the full string, not a screenshot, not an attachment.
- Any proof that the credential works. Nothing was used, called, or derived from it.
- Any request for payment, credit, or a bounty. Reports are not for sale.
- Any follow-up pressure. Reply once and that is the end of it.
To report one of our messages as unwanted, or to ask us to stop contacting you: