Code Audit API — leaked secrets + OSV dep scan
Info Inlet Inc. · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
Code Audit API — leaked-secret scanning and dependency vulnerability checks as a service, designed for CI gates, dev-tool integrations, and AI coding agents that want to refuse to ship dangerous code.
Two endpoints
Show the rest of the publisher’s description (4 more lines)
- — regex scan for AWS / GitHub / OpenAI / OpenRouter / Stripe / Slack / Google API keys, PEM private keys, JWTs, and assigned passwords. Returns findings with 1-based line numbers and a redacted preview (we never echo the actual secret back).
- — parse a (npm) or (PyPI) and query the public OSV.dev vulnerability database for each pinned version. Returns only the vulnerable packages with their CVE / GHSA IDs.
What this isn't — not a deep static analyzer, not a SAST replacement, not an SCA suite. It's a fast, predictable, agent-friendly check for the two highest-signal issues that 95% of "did we leave a secret in the repo?" / "are any of our deps known-bad?" questions need.
Plans — Starter $9/mo (25 scans, $0.10 overage) · Pro $29/mo (200 scans, $0.05 overage).
Preview
1 imageAgent build and provenance
Sign in to see the provenance.
The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.
Sign inCompliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Plans and pricing as listed
3 listedSources
Publisher resources
1 linkEvidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.


