API spend · quotas · credential governance
SubScope watches your API credentials across AI, security, and cloud vendors — spend, quota burn, stale keys, and public leaks — from one isolated workspace, encrypted with keys you control.
Already have a workspace? sign in →
scope
OpenAI, Anthropic, Shodan, Censys, AWS and 30+ more — quota and spend in a single live view, fetched on your schedule.
govern
Reused keys, stale credentials, weak defaults, and secrets found in public leaks are flagged automatically with a health score.
isolate
Physically isolated per tenant, AES-256 encrypted at rest under a key you own. Rotate it on demand, bring your own, or read straight from your vault — SubScope never has to hold the secret.
Security posture
SubScope is a credential-governance platform first and a dashboard second. Every design decision starts from “what happens when this is breached” — so the honest answer stays “nothing useful leaks.”
Every secret and license key is pgcrypto-encrypted in the database. Nothing is ever written in plaintext.
Each workspace is encrypted under its own customer-managed key — not a shared platform key. Rotate it whenever policy demands.
Bring your own key: SubScope re-encrypts your entire vault under a key you supply and control. Lose it, and even we can't read your secrets.
A dedicated Postgres schema per tenant with enforced search-path scoping — a query physically cannot reach another tenant's data.
Read credentials directly from HashiCorp Vault (AppRole) or GCP Secret Manager via workload identity federation. SubScope holds a reference, never the secret — no long-lived cloud IAM material.
Admin, editor, and viewer roles scoped per workspace. Every credential mutation is authorization-checked and audit-logged.
The average security team runs 30+ API keys across 9 vendors with no shared view of spend or exposure. SubScope is that view.
Request early access