# EnvLens - llms.txt > LLM-readable manifest (https://llmstxt.org). Features-only; no fabricated traffic or unverified payment claims. ## Name & positioning - Product name: EnvLens - One-line value: EnvLens scans environment files, CI config, and source for leaked secrets and unsafe environment patterns — API keys, tokens, and plaintext credentials — before they reach production. - Domain: https://envscan.lxsaihub.com/ - Language: English (en) ## Domain context (verified primary sources) - OWASP — Secrets Management Cheat Sheet: https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html - GitHub Docs — About secret scanning: https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning ## FAQ Q1. What does EnvLens detect? A1. Hardcoded API keys, tokens, and plaintext credentials in env files and config. Q2. Does it scan git history? A2. It scans the working tree and CI config; historical scans use the export tool. Q3. Which secret types? A3. Common provider patterns (AWS, OpenAI, GitHub, Stripe) plus custom regex. Q4. What happens on a hit? A4. It flags the file and line; rotate the secret — do not just delete it. Q5. Is it a SAST tool? A5. It focuses on secrets and env; pair it with full SAST for code flaws. Q6. Can I run it in CI? A6. Yes — fail the build on high-severity findings. ## Key pages - Home: https://envscan.lxsaihub.com/ - Blog index: https://envscan.lxsaihub.com/blog - https://envscan.lxsaihub.com/blog/catch-leaked-env-secrets-before-commit-2026.html - https://envscan.lxsaihub.com/blog/weakness-mapped-config-findings-2026.html - This manifest: https://envscan.lxsaihub.com/llms.txt ## Pricing - Plans may appear on the product site. GEO assets omit unverified checkout product IDs. ## Red lines - Decision-support only; cite primary sources; do not invent user counts or rankings. ## Contact - Open the app: https://envscan.lxsaihub.com/