# Truffle Security

**Canonical:** https://apis.io/providers/truffle-security/  
**Website:** https://trufflesecurity.com  
**APIs profiled:** 0

Truffle Security Co. is an open-source security software company founded in 2021 and backed by a16z. It builds TruffleHog, the widely adopted secrets-scanning engine that detects, verifies, and helps remediate leaked credentials across source code, git history, container images, cloud storage, SaaS tools, and CI/CD pipelines. TruffleHog classifies 800+ credential types, actively verifies whether a found secret is live, and ships as a Go CLI (open source, AGPL-3.0) plus a commercial TruffleHog Enterprise platform with continuous monitoring, 20+ integrations (GitHub, GitLab, Confluence, Jira, Slack, SharePoint, GCP, and more), a triage dashboard, and a v3 Enterprise API. Products include TruffleHog open source, TruffleHog Enterprise, Analyze, and Forager.

## Kin Score — 36.4 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 36.4).

| Facet | Score |
|---|---|
| Discoverability | 57.4 |
| Contract Quality | 45.1 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 45.2 |
| Commercial Clarity | 23.7 |
| Access Clarity | 23.7 |

## Agent readiness — 20.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## Security (1)

- **Truffle Security Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Security, Secrets Detection, Secrets Scanning, DevSecOps, Application Security, Credential Scanning, TruffleHog, Open-Source

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/truffle-security/). Scores are computed from the provider's own public artifacts under a published rubric.
