nowfound

Alternatives

Products that do what aiexposuretool does

Find exposed secrets and weak security in seconds

  1. 1

    Discover, Scan, and Secure every API at scale

    2025

  2. 2KD

    I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

    Nov 2025 · github.com

  3. 3

    See your leaked API keys before attackers do

    Jan 2026

  4. 4EH
  5. 5

    Check if your secrets and API keys have leaked on GitHub.

    2023

  6. 6LP

    OP here. I built this because I recently caught myself almost pasting a block of logs containing AWS keys into Claude. The Problem: I need the reasoning capabilities of cloud models (GPT/Claude/Gemini), but I can't trust myself not to accidentally leak PII or secrets. The Solution: A Chrome extension that acts as a local middleware. It intercepts the prompt and runs a local BERT model (via a Python FastAPI backend) to scrub names, emails, and keys before the request leaves the browser. A few notes up front (to set expectations clearly): Everything runs 100% locally. Regex detection…

    Dec 2025 · github.com

  7. 7OT

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com

  8. 8

    Ask your cloud anything without breaking prod. Read-only.

    Jul 2026 · github.com

  9. 9

    Real-time compliance & security validation for AI coding

    Dec 2025

  10. 10

    LeakLake🔒Monitors AI chats, detects leaks, and alerts you⚠️

    Dec 2025

  11. 11

    60% of startups leak API keys on GitHub. Find & Auto fix.

    Mar 2026 · cyber-guard-nine.vercel.app

  12. 12

    Find AI vulnerabilities before hackers do

    Mar 2026

  13. 13

    Find exposed .env files in your GitHub repos instantly

    Apr 2026 · scan-guard-io.lovable.app

  14. 14

    Find exposed keys & missing policies before app review

    Jun 2026 · launchtrust.co

  15. 15

    Web Security Risk & AI authorship scanner

    27d ago · vulnexa.com

  16. 16

    Catch exposed API keys and secrets while you browse

    Jul 2026

  17. 17

    API Key & Secret Leak Detector

    Mar 2026 · marketplace.visualstudio.com

  18. 18AS

    Free and instant penetration testing for rest APIs. Please try and let me know what do you think? https://www.apisec.ai/free-api-pen-test

    2022

  19. 19IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  20. 20TO

    I'm an infrastructure architect who started using AI assistants to write code 3 months ago. After building several systems with Claude, I noticed a pattern: the code always had security issues I could spot from my ops background, but I couldn't fix them myself since I can't actually write code. Why I built this: I needed a way to verify AI-generated code was production-safe. Existing tools either required cloud uploads (privacy concern) or produced output too large for AI context windows. TheAuditor solves both problems - it runs completely offline and chunks findings into 65KB segments that…

    Sep 2025 · github.com

  21. 21

    Scan your site for security holes & compliance gaps in 2 min

    Jul 2026 · ai-cyber-shield.com

  22. 22

    Check your website against the EU's AI disclosure rules

    9d ago · swornmark.com

  23. 23

    Free security scan that tells you exactly how to fix it

    Jun 2026

  24. 24

    Scan any website for leaked secrets in seconds

    Feb 2026

Ranked by how close each launch is in meaning, then by votes. Refine with a description →