Skip to content

Secrets & Credentials Collection

The ALTR Managed - Secrets & Credentials default collection detects columns that store credentials – API keys and tokens, private keys, passwords in connection strings, cloud provider access keys, and multi-factor authentication (MFA) seeds – so you can find where credentials sit in your data.

How the Secrets & Credentials Collection Matches

Section titled “How the Secrets & Credentials Collection Matches”

Each classifier in the Secrets & Credentials collection combines its conditions with AND logic, pairing a Data Entropy condition with a structural check. The structural check confirms that a column looks like a credential, by its value format, its value length, or its column name. The Data Entropy condition confirms that the values carry key-like randomness, measured by its Minimum evidence and Minimum key size fields. Order IDs, UUIDs, and hashes that share a credential’s format score low on the Data Entropy condition, so the classifier doesn’t match them.

The classifiers evaluate wherever Data Entropy conditions evaluate: ALTR Hosted, In-Warehouse, and OLTP Classification Agent jobs. OLTP jobs require OLTP Classification Agent 1.23.0 or later.

Every classifier in the collection carries the tier:red tier tag.

In AI Data Shield, the Column Name and Data Length checks in these classifiers don’t apply, and a Data Entropy condition scores each segment of the payload on its own rather than a column of sampled values. See API Payload Classification.

The Secrets & Credentials collection contains these classifiers, listed with the data each one detects and the conditions it combines.

Classifier What it detects How it matches
ALTR Managed - Generic API Key or Token API keys and tokens from any provider. The column name indicates a credential (for example, it contains api_key, secret, token, or password), or the values start with a known vendor key prefix. The values are at least 20 characters long, with a Minimum evidence of 13.3 bits and a Minimum key size of 112 bits. The column name doesn’t end in an identifier suffix such as id, uuid, or hash.
ALTR Managed - Private Key Material Private keys in Privacy-Enhanced Mail (PEM) format, including RSA, EC, PKCS #8, OpenSSH, and PGP private keys. Certificates, public keys, and certificate signing requests don’t match. The values contain a PEM private key header. The key content has a Minimum evidence of 13.3 bits and a Minimum key size of 256 bits, in a Base64 alphabet.
ALTR Managed - Credential in Connection String Connection strings that embed a user name and password, in the form scheme://user:password@host. The values match the connection-string format, and the embedded password has a Minimum evidence of 6.6 bits and a Minimum key size of 80 bits.
ALTR Managed - Cloud Provider Access Key AWS access keys, Google API keys, and Google OAuth tokens. The values start with a cloud provider’s key prefix and have a Minimum evidence of 4.0 bits, which excludes placeholder and example values.
ALTR Managed - MFA / TOTP Seed Shared secrets for time-based one-time password (TOTP) MFA, as Base32 seeds of 16 or more characters or as otpauth:// URIs. At least 50% of the values are Base32 seeds or otpauth:// URIs, with a Minimum evidence of 13.3 bits and a Minimum key size of 80 bits. The column name doesn’t end in an identifier suffix such as id, uuid, or hash.