For engineering leaders whose repos have grown faster than their secret hygiene.

Most teams have secrets in git they've forgotten about — hardcoded credentials, leaked API keys, committed .env files, and rotated-but-not-revoked tokens. This is secret sprawl: credentials scattered across repos and history, some still live, most of it noise. You suspect they're there. You don't know which are live exposures versus noise.

Get a Baseline Assessment Our Trust Model

Turn the noise into a prioritized action list.

Your secret scanning is probably already running, producing a wall of findings nobody opens. I do a read-only assessment across your organization's repositories, classify every finding by real risk — not just "secret found" — and deliver a prioritized remediation report:

  • ✔ Rotate Today: Confirmed live exposures with high impact.
  • ✔ Rotate This Week: Validated secrets with lower immediate risk.
  • ✔ Log and Ignore: Confirmed noise, placeholders, and test strings.

No false-positive dump. No changes to your systems. No tooling to install or maintain.

SecretDebtReport_Final.pdf PDF
Critical: Rotate Today
AWS_ACCESS_KEY_ID: AKIA... (Verified Live)
Warning: Rotate This Week
STRIPE_API_KEY: sk_test... (Live/Low-Impact)
Noise: Log & Ignore
DB_PASSWORD: "password123" (Placeholder)

The Offer

Two ways to engage. Both are read-only, fixed scope, no tooling to install, and delivered as a prioritized remediation report a busy engineering leader can actually act on.

Baseline Assessment

One-time · delivered in one week

Establish your current risk baseline. Read-only, fixed scope — the full scan, the triage, and a prioritized remediation report.

  • ✔ Deep scan of all repositories
  • ✔ Human-judged noise filtration
  • ✔ Prioritized remediation report
  • ✔ Liveness verification
Request a baseline
Recommended

Monthly Monitoring

Ongoing · cancel anytime

Keep your secret hygiene clean after the baseline. Recurring monitoring and rotation guidance — we flag the credential and API key rotations that matter — so new exposures get caught before they age.

  • ✔ Monthly re-scan & report
  • ✔ 30-minute monthly review call
  • ✔ New exposure alerts
  • ✔ Cancel anytime
Start monitoring

Trust-First Access Model

Safe & Scoped Access

Access is granted via a read-only GitHub token scoped to contents:read and metadata:read at the organization level. Tokens are time-bound and revocable by you at any moment.

A mutual NDA is signed before any access is granted.

The "No-Value" Guarantee

I read rotation metadata to confirm liveness, but I never read or store secret values from your vaults.

For cautious teams, a client-run variant is available: you run the scan inside your environment and send me the raw findings.

Harvey Ramer

Who's behind Unrotated Security

Harvey Ramer has spent more than 20 years building and architecting software — from solo client engagements to systems that have to stay up. Unrotated Security is that engineering discipline turned on a problem nobody owns: credentials committed to version control that get found and never rotated — the unrotated credentials and secret debt no one will touch.

He scans read-only, verifies liveness without ever reading your secret values, and hands you a prioritized report a busy engineering leader can actually act on. You're hiring an engineer who treats your exposures like live incidents. They are.