envman
Mission & Philosophy Zero Cloud Egress v3.0.2 Architecture

Guarding codebases
at the speed of thought.

Envman was born from a fundamental frustration: developers live in constant fear of pushing an API key into Git, while traditional scanners are slow, noisy, and evaluate code after damage is already done.

01

The Genesis of Envman

Every day, thousands of engineering teams leak credentials into GitHub repositories. A single git add . on a repo where .env was missing from .gitignore can expose live AWS keys, Stripe tokens, OpenAI API secrets, and production database URLs.

Cloud-based SAST platforms and GitHub secret scanning are valuable, but they operate reactively: by the time an alert is generated, the commit has already landed on remote servers and exists permanently in Git history. Rotating compromised production credentials takes hours of stressful incident response.

We engineered Envman (@fronik/envman) to solve this problem entirely at the client side. By compiling high-speed AST parsing and Shannon entropy heuristics into native Git pre-commit hooks, Envman intercepts every commit in under 1.4 milliseconds—blocking leaks before secrets ever leave your machine.

Our Architectural Pillars

Engineered with four uncompromising technical guarantees.

Absolute Zero-Egress

Zero cloud sockets, zero remote API pings, and zero telemetry collection. Envman executes 100% locally inside volatile RAM, making it fully compliant with air-gapped enterprise environments and zero-trust security postures.

1.4ms In-Memory AST Scanning

Security that introduces developer friction gets bypassed. Envman builds an Abstract Syntax Tree of staged files and validates signatures in 1.4ms—so fast you will never feel commit delay or workflow interruption.

H

Shannon Entropy Math

Instead of brittle regex pattern matching that floods developers with false alarms, Envman computes Shannon character randomness (H > 4.5). This cuts false positives by over 92% while catching novel high-entropy keys.

Hardware AES-256-GCM Vault

Never store unencrypted plaintext secrets on disk. Envman provides seamless hardware-accelerated enclave encryption, allowing developers to share encrypted bundles safely while decrypting into memory only at runtime.

Open Source & Community Driven

Free software released under the permissive MIT license.

1,535
Verified npm Downloads
1.4ms
Pre-Commit AST Latency
40+
Cloud Vendor Signatures
0 KB
Network Telemetry Egress

Protect your Git repository today

One command installs native pre-commit hooks in under 3 seconds.

$ npx @fronik/envman init