API spend · quotas · credential governance

Every key, quota,
and dollar — in scope.

SubScope watches your API credentials across AI, security, and cloud vendors — spend, quota burn, stale keys, and public leaks — from one isolated workspace, encrypted with keys you control.

.subscope.work

Invite-only during early access · no spam, just your invite

Already have a workspace? sign in →

credential scope● live
OpenAIAI
$27,561month-to-date
healthy
AnthropicAI
$9,879month-to-date
healthy
ShodanINTEL
328Kscan credits
healthy
CensysINTEL
4.6Kqueries left
stale
AWSCLOUD
$4,182month-to-date
healthy
prod-openai-keyAI
exposed
LEAKED
6 vendors/1 exposure/$41,622 tracked this month

scope

One scope for every vendor

OpenAI, Anthropic, Shodan, Censys, AWS and 30+ more — quota and spend in a single live view, fetched on your schedule.

govern

Governance, not just graphs

Reused keys, stale credentials, weak defaults, and secrets found in public leaks are flagged automatically with a health score.

isolate

Your keys never leave your control

Physically isolated per tenant, AES-256 encrypted at rest under a key you own. Rotate it on demand, bring your own, or read straight from your vault — SubScope never has to hold the secret.

Security posture

Built for teams that treat API keys like production secrets.

SubScope is a credential-governance platform first and a dashboard second. Every design decision starts from “what happens when this is breached” — so the honest answer stays “nothing useful leaks.”

AES-256 at rest

Every secret and license key is pgcrypto-encrypted in the database. Nothing is ever written in plaintext.

Per-tenant CMEK

Each workspace is encrypted under its own customer-managed key — not a shared platform key. Rotate it whenever policy demands.

BYOK

Bring your own key: SubScope re-encrypts your entire vault under a key you supply and control. Lose it, and even we can't read your secrets.

Schema-per-tenant isolation

A dedicated Postgres schema per tenant with enforced search-path scoping — a query physically cannot reach another tenant's data.

Bring your own vaultenterprise

Read credentials directly from HashiCorp Vault (AppRole) or GCP Secret Manager via workload identity federation. SubScope holds a reference, never the secret — no long-lived cloud IAM material.

RBAC

Admin, editor, and viewer roles scoped per workspace. Every credential mutation is authorization-checked and audit-logged.

The average security team runs 30+ API keys across 9 vendors with no shared view of spend or exposure. SubScope is that view.

Request early access