| Name | Type | Collection | Scope | Tags | Updated |
|---|
Finds secrets committed in git history, present in tracked files or log files, and secret-bearing files missing from .gitignore. Read-only — concealer never rewrites your history.
| Score | File | Value | Reason | Command |
|---|
AI agents may only read secrets through a registered agent token. Per call caps a single response; the window quota caps how many distinct secrets an agent may reveal within the window — repeated queries can't reassemble the whole vault. Set the window quota to 0 to fully block an agent.
Optional. Only used for the email breach check (Risks → Exposure). Get one at haveibeenpwned.com/API/Key.
Export encrypts the whole vault with your master password (age). Import merges records into this vault (also restores a .cerbak backup).
A .cerbak backup is the whole vault encrypted with a dedicated backup password (separate from your master password) — an opaque binary you can't open to read. Restore it via Import above. Automatic backups write a .cerbak to a local folder on unlock once the interval has elapsed.