Private source pilot

KeyControl

Find the owner, understand the impact, and plan the fix without storing the secret.

KeyControl turns safe indicators for API keys, service accounts, application identities, and automation credentials into owned remediation work with approvals and retained evidence.

Private pilots use safe fingerprints and sanitized metadata. Raw discovered credentials are not stored or used to authenticate.

Machine-identity sourceKeyControl
Safe findingFingerprint, provider, type, confidence
Owner and impactResponsible team, affected systems, urgency
Reviewed fixPlan, approval, status, completion record
Evidence recordApproved remediation summary

Response workflow

Turn an exposed credential indicator into owned, reviewed remediation work.

KeyControl maps safe findings to owners, affected systems, blast radius, remediation state, approvals, and retained evidence without exposing the underlying secret value.

1Safe finding
2Owner resolution
3Blast radius
4Dry-run plan
5Audit evidence

What your team can review

Control machine identities before exposed secrets become incidents.

KeyControl is built around safe metadata, explicit ownership, reviewed remediation, and evidence that security and audit teams can review.

Safe fingerprint

Keep a keyed fingerprint, limited hints, repository context, detector, confidence, and status without storing the secret.

Machine identity map

Track AWS IAM users and roles, GitHub Apps, CI/CD secrets, service accounts, bot accounts, and credential references.

Blast-radius context

Explain what each identity can reach, which resources are sensitive, and how rotation affects service continuity.

Approval-gated remediation

Plan rotation, disablement, deletion, quarantine, or exception workflows through dry-run and human approval first.

Response model

Separate detection metadata from destructive execution.

KeyControl keeps raw secrets out of persistence, UI, API responses, logs, tests, seed data, and telemetry. Production connectors should use least-privilege read-only inventory and separate approval-gated execution roles.

Safe import and findings Store provider, secret type, safe fingerprint, repository context, timestamps, confidence, and evidence summary only.
Owner and workflow routing Resolve likely owners through repository metadata, CODEOWNERS-style rules, tags, and operational context.
Dry-run remediation Validate replacement, rotation, disablement, monitoring, and deletion plans before live action is approved.
KairnexEvidence export Send safe fingerprints, owner and blast-radius metadata, remediation status, approvals, and audit evidence.

Security boundaries

Defensive blue-team response only.

KeyControl does not scrape public repositories, use discovered credentials to authenticate, collect raw secrets, or build offensive tooling. It is designed for authorized defensive response inside customer-approved environments.

No plaintext secrets, API keys, passwords, cookies, private keys, session material, raw tokens, or raw credentials stored
Safe HMAC fingerprints and sanitized metadata only
Cross-tenant access is treated as a security failure
Destructive remediation requires approval and typed confirmation
Every sensitive action creates an immutable audit log entry