Secrets & Credentials Collection
The ALTR Managed - Secrets & Credentials default collection detects columns that store credentials – API keys and tokens, private keys, passwords in connection strings, cloud provider access keys, and multi-factor authentication (MFA) seeds – so you can find where credentials sit in your data.
How the Secrets & Credentials Collection Matches
Section titled “How the Secrets & Credentials Collection Matches”Each classifier in the Secrets & Credentials collection combines its conditions with AND logic, pairing a Data Entropy condition with a structural check. The structural check confirms that a column looks like a credential, by its value format, its value length, or its column name. The Data Entropy condition confirms that the values carry key-like randomness, measured by its Minimum evidence and Minimum key size fields. Order IDs, UUIDs, and hashes that share a credential’s format score low on the Data Entropy condition, so the classifier doesn’t match them.
The classifiers evaluate wherever Data Entropy conditions evaluate: ALTR Hosted, In-Warehouse, and OLTP Classification Agent jobs. OLTP jobs require OLTP Classification Agent 1.23.0 or later.
Every classifier in the collection carries the tier:red tier tag.
On API Payloads
Section titled “On API Payloads”In AI Data Shield, the Column Name and Data Length checks in these classifiers don’t apply, and a Data Entropy condition scores each segment of the payload on its own rather than a column of sampled values. See API Payload Classification.
Classifiers
Section titled “Classifiers”The Secrets & Credentials collection contains these classifiers, listed with the data each one detects and the conditions it combines.
| Classifier | What it detects | How it matches |
|---|---|---|
| ALTR Managed - Generic API Key or Token | API keys and tokens from any provider. | The column name indicates a credential (for example, it contains api_key, secret, token, or password), or the values start with a known vendor key prefix. The values are at least 20 characters long, with a Minimum evidence of 13.3 bits and a Minimum key size of 112 bits. The column name doesn’t end in an identifier suffix such as id, uuid, or hash. |
| ALTR Managed - Private Key Material | Private keys in Privacy-Enhanced Mail (PEM) format, including RSA, EC, PKCS #8, OpenSSH, and PGP private keys. Certificates, public keys, and certificate signing requests don’t match. | The values contain a PEM private key header. The key content has a Minimum evidence of 13.3 bits and a Minimum key size of 256 bits, in a Base64 alphabet. |
| ALTR Managed - Credential in Connection String | Connection strings that embed a user name and password, in the form scheme://user:password@host. |
The values match the connection-string format, and the embedded password has a Minimum evidence of 6.6 bits and a Minimum key size of 80 bits. |
| ALTR Managed - Cloud Provider Access Key | AWS access keys, Google API keys, and Google OAuth tokens. | The values start with a cloud provider’s key prefix and have a Minimum evidence of 4.0 bits, which excludes placeholder and example values. |
| ALTR Managed - MFA / TOTP Seed | Shared secrets for time-based one-time password (TOTP) MFA, as Base32 seeds of 16 or more characters or as otpauth:// URIs. |
At least 50% of the values are Base32 seeds or otpauth:// URIs, with a Minimum evidence of 13.3 bits and a Minimum key size of 80 bits. The column name doesn’t end in an identifier suffix such as id, uuid, or hash. |