#113 · Updated Handling of Secrets & Sensitive Data in Escape
We’re rolling out a significant evolution in how we surface exposed secrets and sensitive data - laying the groundwork for a new era of AI-powered secret detection and prioritization that will change how you protect your most critical assets.
What’s new¶
We’ve retired the standalone Exposed Secrets tab in All Risks and the Sensitive Data tab from individual scan reports to unify these findings as standard issues within your risk ecosystem. This shift aligns sensitive data detection with the broader risk framework, making it easier for you to:
- Understand and prioritize secrets and sensitive data exposures in the proper business context,
- Quickly triage and remediate through familiar workflows,
- Leverage powerful filtering and search — by test category, risk type, asset, and more.
How to access your secrets today:
- Re-running scans will surface new true positives and previously undetected secret combinations.
- At the application level, visit the Issues tab and filter by Category → Sensitive Data
- Globally, use All Risks filtered by Risk Type → Sensitive Data
What’s Next: Bringing Inventory-Based Secrets Into the Fold¶
Currently, secrets discovered through Inventory, Inventory Frontends, and Inventory Integrations are temporarily hidden due to an ongoing migration effort. We’re actively working to restore full visibility here, seamlessly integrating these findings into the new sensitive data experience.
This migration is foundational, enabling us to introduce powerful AI capabilities soon — dramatically improving accuracy, context-awareness, and proactive remediation.
Our new approach will be more than a UI change, we want to genially improve how you handle sensitive data detection:
- You’ll be able to distinguish what truly matters, differentiating public vs. private data, dev vs. production environments, and sensitive personal info vs. less critical disclosures. For example, leaking personal emails with SSNs is flagged with higher severity than a few generic professional emails.
- Access validation: You’ll see whether exposed secrets can actually grant access (e.g., AWS keys, DB credentials), reducing false positives.
- AI-driven prioritization: Leveraging a proprietary machine learning algorithm that is not trained on customer data, Escape will adapt over time, only surfacing sensitive data alerts that pose genuine risk in relevant contexts, learning from your feedback and historical issue handling.