SAASPOCALYPSEverdict #BETTERLEAKS-9D41
scanned 2026.08.07 · 10:49
subject of investigation

betterleaks.com

open-source secrets scanner
verdictSOFT
wedge score
76
/100
wedge thesis

the door is distribution: they're an open-source scanner with no clear hosted offering or enterprise channel, so competing by packaging a managed, CI-integrated service and focused integrations is the obvious wedge.

wide-open walls — wedgeable·ship in 6 weeks·run for $27.00/mo
the doorcapital
wedge

where the walls are.

methodology →
the door

their capital wall is paper-thin — runs on commodity cloud + free tiers.

watch out

the technical wall is real — research-grade engineering, not a weekend.

capitaldoor
1.0/10
investment the incumbent had to make
why this scorehigh confidenceNo evidence of significant non-software spend, proprietary infrastructure, or large compliance/legal costs; project...

No evidence of significant non-software spend, proprietary infrastructure, or large compliance/legal costs; project is OSS and self-hosted.

  • Project is open-source MIT-licensed and self-hosted with zero current cost.
  • Estimated competing cost shows only small hosted infra (Supabase, Vercel, R2) totaling ~$27/month.
  • No mention of enterprise implementation or proprietary hardware/inventory.
technical
4.0/10
depth of the underlying engineering
why this scoremedium confidenceScanner has engineering work (scalable scanning, live validation, integrations) but core detection is portable and...

Scanner has engineering work (scalable scanning, live validation, integrations) but core detection is portable and not deeply proprietary.

  • Core scanner is a CLI/library (detection portable, MIT-licensed).
  • Challenges list includes scalable scanning, incremental diffs, and provider-specific live validation as medium/hard work.
  • Detected stack is simple web stack (Cloudflare CDN, Supabase, Vercel) implying no exotic infra.
network
1.0/10
users compound users
why this scorehigh confidenceNo marketplace, UGC, social graph, or multi-sided liquidity; distribution is OSS, not a platform with network effects.

No marketplace, UGC, social graph, or multi-sided liquidity; distribution is OSS, not a platform with network effects.

  • Wedge thesis emphasizes distribution via OSS and no hosted offering or enterprise channel.
  • No mention of marketplaces, partner ecosystems, or user-generated content.
  • Pricing gate is public and deterministic distribution signals absent.
switching
3.0/10
stickiness of customer data + workflow
why this scoremedium confidenceSome workflow lock-in possible via integrations and CI hooks, but scanner is CLI-first and results/data are portable,...

Some workflow lock-in possible via integrations and CI hooks, but scanner is CLI-first and results/data are portable, so migration pain is modest.

  • Betterleaks is CLI/library-first, making detection portable and embeddable into other workflows.
  • Buyers care about integrations (CI, ticketing) and validation/false-positive tooling which a hosted product could replicate.
  • No evidence of trapped non-exportable customer data or long approval chains.
data
2.0/10
proprietary data accumulates over time
why this scorehigh confidenceNo proprietary or non-exportable dataset; scanner rules are open and detection data is portable, limiting a...

No proprietary or non-exportable dataset; scanner rules are open and detection data is portable, limiting a data-driven moat.

  • Core detection is MIT-licensed and portable per take_sub.
  • No mention of accumulated unique behavioral/fraud/risk data or proprietary corpora.
  • Users can run scanner locally (self-hosted), implying exportable results.
regulatory
2.0/10
real licenses, not SOC 2 theater
why this scorehigh confidenceNo regulated duties or licenses indicated; legal/abuse concerns exist but don't equate to formal regulatory moat like...

No regulated duties or licenses indicated; legal/abuse concerns exist but don't equate to formal regulatory moat like HIPAA/FINRA/KYC.

  • Challenges include legal/abuse boundaries and safe validation, but no required licenses or regulated obligations noted.
  • Project is an open-source secrets scanner, not a regulated financial or healthcare product.
  • SOC 2 or similar compliance not mentioned and would be typical but insufficient for high regulatory moat.
take

the blunt take.

Betterleaks solves detection well but exposes its weakness: it's a library/CLI-first OSS project without a polished hosted product or go-to-market motion; that gap is where a small team can wedge in by owning the workflow and UX around scanning results.

Because detection is MIT-licensed and portable, buyers care about integration, validation (are keys still live?), deduping, false-positive reduction, and easy enforcement in CI and ticketing — all areas a managed product can add value without redoing the core scanner.

cost

cost of competing.

what they charge
open-source / self-hosted
$0
/ free
Betterleaks is MIT-licensed OSS; no hosted price listed
annual:$0
what running yours costs
01 · Vercel hobby (dashboard + docs)$0.00
02 · Supabase Pro (auth + Postgres small)$25.00
03 · Cloudflare R2 (artifact storage/light uploads)$1.00
04 · Domain$1.00
TOTAL / mo$27.00
▸ break-even:immediately for teams paying >$1/mo per seat — hosting a small managed wrapper will cost less than typical security tooling subscriptions; for free/open-source users it's a value-add paid conversion.
build

what you're up against.

1 week: product spec + mocks · 2 weeks: CI integrations, GitHub/GitLab apps · 2 weeks: results UI, filtering, live-validated findings · 1 week: auth, hosting, docs, initial marketing
easy
medium
hard
nightmare
01
easy
Packaging CLI into a web dashboard
Invoke scanner, display results. Mostly plumbing and UI work.
02
easy
GitHub/GitLab app setup
OAuth/webhook apps are straightforward; follow platform docs.
03
medium
Live validation of leaked credentials
Implement safe 'is key live' checks per provider without triggering abuse.
04
medium
False-positive tuning and suppression rules
Mapping filters, allowlists, and contextual heuristics to reduce noise.
05
hard
Scalable scanning and artifact retention
Handling large repos, PR scans, incremental diffs, and storage costs needs engineering.
06
nightmare
Legal/abuse and permissive scanning boundaries
Scanning external sources, validating keys, and storing credentials has legal and safety implications that require careful policies and possibly counsel.
stack

their position.

detected signals· measured
cdnCloudflare
recommended stack · inferred
inferBetterleaks CLI (embedded scanner, MIT)inferGitHub App + GitLab App (integrations)inferSupabase Pro (auth + Postgres)inferVercel hobby (dashboard/docs)
rivals

who else has tried this.

option A
run betterleaks-cli locally (self-host)
full control, free, integrates into CI scripts; best for engineers comfortable with CLI.
option B
gitleaks (OSS)
another mature open-source scanner with existing CI integrations.
option C
lower-tech: pre-commit + git-secrets
prevent secrets in commits with small config and no hosted service.
compare

similar scans.

same shape - different moat
ready to wedge in?
Get the wedge plan. Ship a contender by Sunday.
▸ generated with love, by a heartless robotverdict v2.5 · saaspocalypse.dev