Blog

Notes on keeping keys small.

Incidents we have seen, guides we wish existed, and what shipped. No growth hacks, no listicles.

Posts · 8
RSS · feed.xml
Guide
2026-08-26

How much are your API keys costing you?

API credential spend usually skips the AP process entirely — no PO, no contract review, no line item until the invoice posts.

3 min
Guide
2026-08-24

How do you manage your API keys?

SOC 2 prep, a customer's security questionnaire, a due-diligence data room — the question always arrives eventually.

3 min
Guide
2026-08-21

What's actually running your product?

Cost, vendor sprawl, and ownership gaps live one layer below the roadmap — invisible until a bill, an audit, or a renewal forces the question.

3 min
Engineering
2026-08-19

sk-admin- vs sk-proj-: one string, one blast radius

SubScope's one real scope-detection rule is a single prefix check on OpenAI keys. Here's exactly what it does, and why it's narrower than it sounds.

4 min
Changelog
2026-08-14

What shipped: cost history and three new AI providers

A real changelog — multi-tenant governance foundation at launch, then a July-August push on cost visibility: daily cost history, Claude usage, spend-guardrail visibility, and three new AI providers.

3 min
Policy
2026-07-28

Zombie keys: flagging unused credentials safely

How SubScope's 30/90/180-day rules actually work — and why 'unused' and 'stale' are different risks with different fixes.

4 min
Guide
2026-07-14

Shodan and VirusTotal keys belong beside AWS

Security-intelligence APIs are high-privilege and usually invisible to credential governance. That's backwards.

4 min
Incident
2026-06-30

The $4,200 loop: one unscoped OpenAI key, one weekend

A retry loop, a wildcard scope and a Slack DM. How a test key became a four-figure invoice, and how faster visibility would have changed the outcome.

6 min
Recommendation

Shrink your blast radius this week.

Connect one vendor. SubScope will show you what you have been trusting. Free during public beta.

Sign in Talk to us