Enterprises today increasingly rely on credentials to secure the connections between people, systems, and data, a need that has grown more complex with the advent of AI. GitGuardian offers a solution to manage this complexity through a three-step process: Detect, Remediate, and Prevent. Starting with detection, organizations can identify the existence, location, and access level of credentials, forming the foundation of their security strategy.
Acceleration of Software Production
The pace of software development has surpassed the expectations that informed current security measures. GitHub’s COO, Kyle Daigle, noted that the platform experienced a surge from 1 billion commits in 2025 to 2.9 billion by August 2026. This acceleration necessitates infrastructure capable of accommodating growth up to 30 times the current scale. Consequently, the increasing volume of code leads to more credentials and secrets scattered across various systems.
The proliferation of applications, integrations, and automation tools demands a robust authentication process, yet credential exposure remains a growing concern. GitGuardian reports that in 2025, 28.65 million hardcoded secrets were found in public GitHub commits, marking a 34% increase from the previous year. Leaked credentials related to AI services rose by 81%, highlighting the urgent need for security teams to gain visibility into this expanding landscape.
The Elusive Credential Perimeter
The credential layer, which encompasses the credentials linking people, applications, and infrastructure, lacks a clear boundary. Developers often create secrets within sanctioned environments, but these keys can appear elsewhere, such as in shared repositories. Some credentials remain on developer laptops or are created outside the usual oversight, particularly by ‘citizen developers’ utilizing AI services.
Research from GitGuardian’s State of Secrets Sprawl 2026 reveals that internal repositories are six times more likely than public ones to contain secrets. Additionally, 28% of incidents originate outside source-code repositories, occurring in collaboration and productivity tools. This scattered nature of credentials presents a discovery challenge that security teams must address to manage risks effectively.
Complexity of Attack Surfaces
Attackers have adapted to the dispersed nature of credentials, exploiting them across both managed and unmanaged environments. According to the 2026 Verizon Data Breach Investigations Report, compromised credentials accounted for 22% of initial breaches, with many incidents traced back to unmanaged devices.
The rise of self-propagating malware, like Shai-Hulud and S1ingularity, has turned developer laptops into prime targets. These attacks search for authentication data across browser histories, local files, and application storage, underscoring the need for comprehensive visibility into the credential layer.
Security measures must extend to AI agents, which can read files, execute commands, and interact with external services. This access can be misused, either by attackers or through unintended actions by the AI, such as deleting critical data.
Understanding the full scope of credentials and their context is crucial for assessing risk. Validity, location, ownership, and permissions are all factors that contribute to a complete view. GitGuardian’s findings show that even years-old credentials can remain valid, highlighting the importance of continuous monitoring and management.
With software production accelerating, security teams must adapt by prioritizing detection and prevention to protect against evolving threats. Knowing what credentials exist and securing them is more critical than ever as organizations scale their operations.
