- Known-format detection: ~42 known credential formats across LLM providers, cloud platforms, source control, messaging, and developer tools
- Unknown secret detection: Catches unknown or custom secrets that don’t match a known format (labeled
Possible Secret) - Fast: Sub-millisecond latency — no inference overhead
- Secret leakage detection: Identify credentials in LLM prompts or responses
- Compliance auditing: Scan text datasets for inadvertently captured credentials
- Data sanitization: Locate and redact secrets in datasets before training or fine-tuning
Score per detected secret:
- No secrets detected: Returns an empty list
- Secrets detected: Returns one
Scoreper detection, withnameset to the secret type label andvalueset to1.0
Parameters
- text (str) – The text to scan for secrets and credentials.
- score_name_prefix (str | None)
- score_fn_kwargs_mapping (ScoreFnKwargsMappingType | None)
Returns
A list of Score objects, one per detected secret:
- name: The secret type label (e.g.,
"Anthropic API Key","AWS Access Key ID") - evaluator_name:
"FTLSecretDetection" - value:
1.0for each detection (binary — present or absent)
Raises
ValueError – If the text is empty or None.Example
FTLSecretDetection uses a lightweight, deterministic detection engine rather than an ML
model. Known credential formats are detected reliably, though random-looking non-secret
strings may occasionally be flagged as
Possible Secret.name = ‘ftl_secret_detection’
score()
Scan a text string for secrets and credentials.Parameters
str
required
The text to scan for secrets and credentials.
Returns
A list of Score objects, one per detected secret. Empty list if no secrets found.