Treat an exposed credential as a path to investigate—not a password to try.
A credential-related signal is sensitive evidence. BotXpose preserves provenance, minimizes displayed secret material and separates correlation from any active authentication attempt. Validation against a customer system requires a distinct, explicit authorization path.
- 01Discover
- 02Correlate
- 03Validate
- 04Prioritize
- 05Guide remediation
Inputs must carry their boundaries with them.
Each input is shown with its intended purpose and a support state. The page does not turn an architecture subject into a production claim.
Credential signals
Approved signals with provenance and handling controls.
GitHub secrets
Repository findings connected to ownership and affected services.
SharePoint secrets
Credential or secret exposure found within the customer-approved content boundary.
Asset relationships
Services and systems plausibly affected by the identity or secret.
DECISION MODEL
The graph should answer a question.
- 01
Where did the signal come from and may it be processed?
- 02
Which identity or service appears affected?
- 03
Can the value be masked while preserving actionability?
- 04
What approved action confirms or closes the exposure?
Evidence enters.
An owned action leaves.
- 01Masked exposure record with provenance
- 02Affected identity, asset and owner context
- 03Defined validation state and handling history
- 04Rotation, revocation or investigation action
What this page does not claim.
- No active credential use without separate written authorization.
- Secret values should be masked and access-controlled.
- Sources and legal basis require product and legal confirmation.
- No guarantee that every signal is current or exploitable.
Confirm the use case before promising the connector.
We will establish the exposure question, approved sources, data boundary and current support status before representing a deployment path.