467 Patterns. BPE Tokenization. 20 Live Verifiers.

Netallion AI Assurance combines traditional regex patterns with byte-pair encoding tokenization analysis, delivering substantially higher recall on generic secrets than entropy-only approaches.

467

Detection patterns

20

Live verifiers

< 5%

Target false positive rate

~0%

Near-zero false positives on verified types

How BPE Tokenization Works

Traditional entropy analysis measures randomness but produces excessive false positives. BPE tokenization analyzes the structure of strings to distinguish real secrets from legitimate high-entropy content.

Regex + Entropy (Traditional)

  • Matches known patterns via regular expressions
  • Falls back to Shannon entropy for unknown formats
  • High false positive rate on UUIDs, hashes, and encoded data
  • Misses generic secrets with non-standard formats
  • Lower recall on generic secrets than BPE-based detection

Regex + BPE (Netallion AI Assurance)

  • Matches known patterns via regular expressions
  • Analyzes token structure with byte-pair encoding
  • Distinguishes secrets from legitimate high-entropy strings
  • Catches generic secrets that regex alone misses
  • Catches generic secrets that regex- and entropy-only scanners miss

Pattern Categories

Cloud Provider Keys

80+

AWS Access Keys, Azure SAS Tokens, GCP Service Account Keys, Azure Connection Strings

Source Control Tokens

30+

GitHub PATs, GitLab Tokens, Bitbucket App Passwords, Azure DevOps PATs

SaaS API Keys

120+

Stripe, Twilio, SendGrid, Datadog, Slack, PagerDuty, Sentry, HubSpot

Database Credentials

40+

PostgreSQL, MySQL, MongoDB, Redis, SQL Server connection strings

Infrastructure

60+

SSH keys, Docker Hub tokens, npm tokens, PyPI tokens, Terraform tokens

PII Patterns

50+

SSN, email, phone, credit card, address, passport, driver license

AI Hygiene

30+

OpenAI keys, Anthropic keys, secrets in LLM prompts, AI-generated credentials

Generic Secrets

50+

High-entropy strings, password assignments, base64-encoded secrets, JWT tokens

20 Live Verifiers

Every high-confidence finding is tested against the provider's API to confirm the secret is still active — so every alert is a confirmed-active exposure, not a dead, rotated, or test token. You triage confirmed-active exposures, not noise.

AWSAzureGCPGitHubGitLabDatadogSlackStripeTwilioSendGridDockerHubnpmPyPISentryPagerDutyCloudflareNew RelicHubSpotAtlassianLaunchDarkly

How We Compare

CapabilityNetallion AI AssuranceGitGuardianTruffleHogNightfall
Detection Patterns467550+800+100+ ML
BPE TokenizationYesNoNoNo
Live Verification20 verifiers20+ verifiers20+ verifiersN/A
Azure Monitor ScanningNativeNoNoNo
Generic Secret DetectionCatches secrets regex/entropy missEntropy-basedEntropy-basedML-based
PII DetectionYes (regex)LimitedNoBest-in-class (ML)
Custom PatternsYesYesYesLimited
Auto-RemediationKey Vault, GitHub, AWSNoNoNo

Experience the detection engine firsthand

Start your free trial and scan your first workspace with all 467 patterns.