KeyDrift
Free scan

KeyDrift

Who KeyDrift is for

The failure is structural, not personal: output outgrew review, builds substitute values after approval, and agents imitate whatever pattern is already there. Different teams meet that reality with different constraints.

These pages translate one mechanism into each audience’s working week — and end with the same five-minute check.

The same leak lands very differently depending on who shipped it. A service_role key in a founder's first Lovable app is a weekend of panic and a support thread with a BaaS provider. The same string in an agency's client handover is a reputational line item. In a healthtech intake form it is a conversation with counsel. The mechanics never change — build-time substitution, agent imitation, one letter between publishable and secret — but the constraints, the vocabulary, and the right response order all do.

These pages translate one mechanism into each audience's reality.

If you ship alone or lead a small team, your review capacity is the bottleneck the whole industry is talking about. You cannot read every bundle; you barely have time to read every diff. The honest answer is not "be more careful" — it is to automate the one check that dominates AI-built failures, keep the manual skill as a quarterly instinct, and let drift alerts catch the reintroductions that happen when velocity outruns memory.

If you run an agency or consultancy, exposure is contractual before it is technical. The scan-before-touch ritual gives you a dated baseline report you can attach to kickoff, a defensible story at offboarding, and a retainer-shaped monitoring line item that costs less than the coffee budget. Your clients do not need a security lecture; they need evidence in a shareable report and someone who can say "already watched".

If you are heading toward due diligence, know that technical DD has started asking deployment-hygiene questions because investors have been burned by them. What wins the room is not a policy document — it is process evidence: scan history, resolved findings with timestamps, regression alerts configured. Forty-eight hours of cleanup beats forty slides.

Verticals — storefronts, marketplaces, fintech, healthtech, devtools, open source — differ mainly in what their bundles carry and who gets hurt when it leaks. Payment keys mean money movement; email provider keys mean phishing under your own DKIM; demo deployments carry real keys because fake ones "don't look right" in screenshots. Each vertical page names its three most common finds and the rotation paths specific to its providers.

Whatever brought you here, the check at the end of every page is the same ten minutes: fetch what the public fetches, search for the shapes that matter, classify public-by-design against genuinely secret, rotate anything in the second category before touching code. If you would rather the fetching happened on a schedule, everything on this hub connects to monitoring from a free tier.

By audience

One mechanism, translated into each team’s working week.

Run one check now

Every page on this hub ends the same way, because there is only one honest way to know what a deployment serves: fetch it and look. The scan is free, needs no account, and takes about as long as reading this sentence.

No account. Read-only — the scanner only ever issues GET requests, and never stores a key: findings carry a masked prefix and a fingerprint.

KeyDrift · free URL or paste-source scan