FeaturesOverview
API KEY INTELLIGENCE LAYER

Built for engineering teams who can't afford a breach.

bottomlire gives your security and DevOps teams a complete API key intelligence layer — from discovery to remediation. No blind spots. No guesswork. No compromised keys slipping through.

100{20160502c07174839a5b17a84cff805c1e68f69f7d3dbe57159271d5cb837e34}Key Surface Coverage
<2 minMean Time to Detection
SOC 2Type II Compliant
PLATFORM CAPABILITIES

Engineering-grade security,
end to end

Four interlocking capabilities that give you complete control over every API key in your organization.

01 / CONTINUOUS DISCOVERY

Every surface. Every push. Zero blind spots.

bottomlire's scanner integrates with your existing toolchain and runs on every commit. It inspects source code, CI/CD pipeline definitions, cloud IAM configurations, dotenv files, and container image layers — so no leaked credential slips through undetected.

  • Git-native integration: GitHub, GitLab, Bitbucket
  • Supports 60+ cloud services out of the box
  • Container layer scanning with digest-level precision
  • Detects keys in build logs & artifact registries
Source Scanner — Live Run● SCANNING

Click a source to expand details

Risk Scoring Engine
87/ 100
STRIPE_SECRET_KEY
High Risk
Scope breadth92
Key age100
Rotation recency60
Public exposure90
Service criticality95
02 / RISK SCORING ENGINE

A composite risk score for every key, not just a flag.

Rather than binary pass/fail alerts, bottomlire calculates a 0–100 risk score across five dimensions. Security teams gain the context they need to triage accurately and remediate in the right order — highest impact first.

Scope Breadth
How many services the key can access
Key Age
Days since issuance vs. policy baseline
Rotation History
Compliance with rotation schedule
Public Exposure
Detected in public repos or pastes
Service Criticality
Business impact tier of the target service
Composite Score
Weighted aggregate across all dimensions
03 / AUTOMATED REMEDIATION

Policy-driven workflows. No manual triage at 2 a.m.

Define once, enforce everywhere. When a key's risk score crosses your configured threshold, bottomlire executes a configurable action chain — from instant revocation through to Jira ticket creation and Slack notification — with a full audit trail attached.

  • Instant one-click revocation or provider-level auto-revoke
  • Bi-directional Jira, Linear & GitHub Issues integration
  • Slack / Teams / PagerDuty alerting on policy breach
  • Dry-run mode to test policies before enforcing
Remediation WorkflowClick a node to inspect
Compliance Report Preview
SOC 2 Type II
Generated Sep 9, 2026
16/18
controls passing
CC6.1Logical Access Controls
✓ Pass
CC6.7Transmission of Confidential Info
✓ Pass
CC7.2System Anomaly Detection
✓ Pass
CC9.2Risk Mitigation — Third Parties
✓ Pass
04 / COMPLIANCE REPORTING

Audit-ready reports your compliance team will actually trust.

bottomlire maps every finding directly to control requirements in SOC 2 Type II, ISO 27001, and PCI-DSS. Generate exportable PDF or CSV reports in seconds — giving auditors exactly what they need and keeping your certification cycles on track.

📋
SOC 2 Type II
Maps to Trust Services Criteria CC6, CC7, CC9
🔒
ISO 27001
Covers A.9 Access Control & A.12 Operations
💳
PCI-DSS v4.0
Addresses Req. 3, 7, 8 on key and access management
Security & Trust

We protect your keys — we never store them.

Trust isn't a marketing promise. At bottomlire, it's an architectural constraint — verified by independent auditors, not just asserted by us.

Read-Only OAuth

Zero write access to your repositories

bottomlire connects via read-only OAuth scopes. We can scan — not modify. Your codebase, your pipelines, and your repository permissions remain entirely under your control. We request the minimum necessary access, and you can revoke it at any time from your provider dashboard.

End-to-End Encryption

AES-256 at rest · TLS 1.3 in transit

Every byte of scan data is encrypted using AES-256 before it touches our storage layer. All communication between your systems and bottomlire runs exclusively over TLS 1.3 — the current gold standard for transport encryption. Encryption keys are rotated automatically and managed via a dedicated KMS. Your data is never readable in plaintext.

Third-Party Verified

SOC 2 Type II certified · Annual penetration testing

Our security posture is independently verified every year. bottomlire holds SOC 2 Type II certification — audited for security, availability, and confidentiality controls across a continuous observation period. We also commission annual penetration tests from a CREST-accredited third-party firm. Results inform our ongoing hardening roadmap.

0bytesplaintext key storage
AES-256encryption standard
TLS 1.3transport security
SOC 2Type IIcompliance certification

Security Whitepaper

A detailed technical overview of our architecture, encryption model, access controls, and audit practices.

By requesting the whitepaper you agree to our Privacy Policy and Terms of Service. We do not sell or share your data.

bottomlire

Your API Keys, Audited.
Your Bottom Line, Protected.

Enterprise-grade API key auditing and lifecycle management for security-first teams.

© 2026 bottomlire Inc.

[email protected]+1 (415) 800-2290340 Pine St, Suite 800, San Francisco, CA 94104
SOC 2 Type IIISO 27001GDPR CompliantCCPA Ready