Guard
Secrets never leave your machine.
Guard scans commits, PRs, and whole files for secrets, credentials, and PII — on-device, before anything ships. It runs as a git hook, a CLI command, and an MCP tool.
On-device
Scanning happens locally at commit time. Your source and secrets never touch the network — that's the whole privacy guarantee.
Everything sensitive
API keys, tokens, private keys, DB URLs, JWTs, payment-card numbers (Luhn-checked), high-entropy strings, and your team's configured terms.
Three surfaces
A pre-commit git hook, the sentinel-suite scan CLI, and a scan_secrets MCP tool — same engine everywhere.
Tunable, not noisy
.sentinel-guard.json sets allowlists, severities, and optional live verification — silence false positives without disabling real detection.
Illustrative — categories caught on a typical repo scan.