Coding-agent security
Catch silent agent leaks
Hervé mechanically checks every prompt, API call and tool use by your agents, and blocks the non-compliant ones.
6-week paid pilot, fully refunded if we find nothing actionable.
5 open alerts across 412 sessions
14 developers · Claude Code, CodexRead .env.production · D3Where your data goes
The short version for your security review.
Your sessions stay in your repo
Each developer's agent sessions are saved to a branch of your own repository, only where they ran rv install.
We never store your code
Code, diffs and session transcripts are read on demand. None of it is written to our database.
Secret values are never displayed
When a leak is detected, we display the key's name, like STRIPE_SECRET_KEY. Never its value.
Your first six weeks with Hervé
- Day 1 · Install
Each team member runs
rv installonce. Their agent sessions are captured to a branch in your own repo. - Week 2 · Findings
We walk you through what Hervé found across your team's sessions, and open the first fixes.
- Weeks 3–6 · Guard
Hervé checks every new session against your rules, with a weekly update.
Questions
We already run GitGuardian. Why Hervé?
Secret scanners check what gets committed. A key pasted into a prompt, or printed by an agent, never becomes a commit. Hervé allows you to see what happened beneath the surface.
Does Hervé rotate the keys for us?
No. Hervé tells you which keys leaked, in which session. You rotate them with the provider, then mark them as rotated.
Which agents are covered?
Claude Code, Cursor, GitHub Copilot CLI, OpenAI Codex and OpenCode. Each developer runs rv install once.
What happens after the six weeks?
You continue with a monthly license, or stop and we delete your data. See pilot details & pricing →
See what your agents have already leaked.
Talk to a founder6-week paid pilot, fully refunded if we find nothing actionable.