Secrets compliance · Zero custody · Git-native · PR enforcement
How it works

Secrets governance for secrets-as-code

Compliance that lives
in your repo.

The Clef CLI enforces secrets policy on every PR via a scaffolded workflow — without ever touching a secret. Run clef cloud init for a compliance dashboard that reads live from your CI artifacts and stores nothing.

custody

0
secrets or customer data stored by Clef

overhead

0
lines of infrastructure to operate or maintain

evidence

100 %
git-native audit evidence, verifiable by anyone

already using clef?

Connect the dashboard in one command.

Run clef cloud init to install the GitHub App and open your compliance dashboard. Free for up to 3 repos.

how it works

Enforce. Monitor. Govern.

One CLI command scaffolds enforcement. Every PR gets checked by your own CI. The dashboard shows you what's compliant.

01 · enforce
Install the CLI. Scaffold the workflow.

Run clef init in your repo. It creates a policy file and scaffolds a CI workflow that runs scan, lint, and compliance checks on every PR. No infrastructure required.

$ clef init ✓ Created .clef/policy.yaml ✓ Created .github/workflows/clef.yml # your next PR gets checked automatically
02 · monitor
See your repos' compliance state in one place.

Run clef cloud init to connect the dashboard. It reads compliance artifacts from your CI — nothing is stored on our servers. Free for up to 3 repos.

03 · govern
Org-wide posture. Rotation alerts. Audit exports.

Upgrade to see compliance state across every repo in your org. Track rotation deadlines, get alerted before they lapse, and export audit evidence to PDF. Your git history does the rest.

features

Why Clef?

Secrets governance that only exists because your secrets live in git.

Zero custody

Never decrypts your secrets and never stores your data. Reads SOPS metadata and PR diffs — nothing else. Nothing to breach because nothing is kept.

PR policy enforcement

Every pull request is scanned for plaintext leaks, linting violations, and policy compliance. Bad changes get blocked before they land.

Git-native evidence

Every secret change is a commit with a PR, reviewer, and approval. Compliance evidence is in git — auditors can verify it independently.

CI-produced evidence

Your workflow runs clef policy report on every merge. The artifact stays in GitHub Actions — the dashboard pulls it via the GitHub API on demand. Nothing is stored on our side.

Rotation tracking

Know which secrets are overdue for rotation across every repo. Get alerts before compliance deadlines, not after.

Multi-platform

GitHub today. GitLab and Bitbucket next. Your compliance story works everywhere your code lives. No platform lock-in.

pricing

Free to enforce. Pay to govern.

The CLI and CI enforcement are open source — no account required. The cloud dashboard adds visibility and governance for teams.

Free
1 account · up to 3 repos
$0 / forever
CLI & CI enforcement always free

Included
  • Encrypt & decrypt with SOPS
  • age, PGP, AWS KMS, GCP KMS, Azure KV
  • Lint, drift, scan, policy commands
  • Scaffolded CI workflow (scan + lint on every PR)
  • Compliance dashboard for up to 3 repos in 1 account
Growth
10 accounts · up to 50 repos
Coming soon
For teams with compliance requirements

Everything in Pro, plus
  • Up to 10 GitHub accounts
  • Up to 50 repos covered across them
  • SOC2 / PCI / HIPAA framework mapping
  • PDF export for auditors
  • Org-wide rollups & cross-org governance
Enterprise
Unlimited accounts · unlimited repos
Custom
Annual contract

Everything in Growth, plus
  • Unlimited accounts and repos
  • GHES / self-hosted bot
  • SSO (SAML / OIDC)
  • Custom compliance frameworks
  • Dedicated support & SLA
CLI enforcement is free forever · each paid tier adds capacity and features

get started

Ready to automate secrets compliance?

One CLI command scaffolds enforcement. Your next PR gets compliance checks automatically. No infrastructure, no custody, no ongoing ops.

Install Clef

Already set up? Open the dashboard →

GitHub GitLab Soon Bitbucket Soon