Tag
secrets
2 posts
Client-Side Secret Exposure in Modern SPA/JAMstack Applications
How we found hardcoded signing keys and BaaS credentials in production JS bundles across two separate engagements, and how we triaged them.
2026-07-02·5 min read
methodologysecretsspa
Old Commits, Live Credentials: The Git History Blind Spot
Why secret scanning limited to HEAD misses a whole class of long-lived exposure, and the sweep methodology we now run on every engagement.
2026-06-25·4 min read
researchsecretsgit

