Discovery: find exposed secrets without collecting them
With VaultPilot Discovery, approved users review private-network login pages, certificate risks, and authorized files. The aim is to find secrets that may sit outside the encrypted vault.
- Mode
- Read-only review
- Finding content
- Redacted signals and hashes
- Import
- Human-approved only

You set the scope before a run
The operator chooses what a run may touch. File review needs a separate confirmation. VaultPilot refuses system directories and its own data paths.
What a finding stores
A finding records the detector, candidate type, severity, confidence, a masked asset reference, a redacted excerpt, and hashes. It also carries the review state and the reason behind it. Discovery never saves the following.
Import starts from one reviewed finding
Only a file finding an operator has marked ready can be imported. VaultPilot reads the value from the approved source again, and the unlocked browser encrypts it with the vault key. The server then stores the encrypted record together with the redacted finding details and an audit entry.
Limits to know
- Discovery does not do the work of PAM, asset inventory, vulnerability or malware scanning, or RDP and SSH management.
- It does not brute-force, spray passwords, submit login forms, or bypass access controls.
- It does not modify, delete, quarantine, or clean the files it reviews.
- Reopening a suppressed finding leaves its suppression rule in place, and this screen has no control to delete the rule.
Check step by step
Read more in the guides: VaultPilot Discovery guide, Discovery screen guide, Discovery finding review