How Swimlane Went From Hunting Credentials to Eliminating Them
Hush gives Swimlane full visibility into every non-human identity, clearing the way to eliminate static credentials altogether.
Challenge
Scattered ownership
Credentials sat across cloud, SRE, security operations, application, and network teams, with no shared record of what existed, where it lived, or when it was last used.
False positives
Custom detection built on TruffleHog returned high volumes of findings, many of them false positives, with no context for ranking the rest.
Rotation meant downtime risk
Credentials baked into applications meant changing one could take the application down, so long-lived keys stayed in place.
Solution
Findings that arrive with an owner
Runtime discovery gave Swimlane one view of every secret, certificate, and non-human identity, each mapped to an accountable owner, so work routes to the team that can fix it instead of landing on security.
A findings list they could act on
Runtime evidence of what was actually in use separated the certificates CertManager already rotated from the long-lived database key that mattered.
Credentials they no longer have to rotate
Policy-based, secretless access replaced static credentials, with rotation automated through CI/CD instead of hand-edited YAML.
Deployment that didnât fight engineering
Agentless integrations and a lightweight runtime sensor, no code changes, and risks surfacing immediately.
Rotation without downtime
Credentials revoked and reissued by API call
Hours to minutes
Reduced credential-exposure triage time
Chasing owners to self-service
Business units now remediate with the context attached
Hunting Credentials, Drowning in False Positives
Swimlane builds agentic AI automation for security operations teams. Michael Lyborg, its Chief Information Security Officer, had already built the controls most mature security programs rely on: shift-left scanning, secret blocking in CI/CD, PCAPs pulled from scaled-down production workloads, eBPF evaluated for risky transport.
Non-human identity wasnât new to him. He dates it back to âthe good old days of Active Directory forests and trees and service accounts,â and says the last 20 years of API keys are what made it big: âoften over-provisioned and over-privileged.â
Those controls covered the commit stage, but not every place a credential could end up. âA lot of times, because weâre humans, maybe somebody copies an API key or a token and puts it in a Jira ticket,â he says.
So the team built its own detection, and got buried. âWe started building out, through TruffleHog and all these custom automations, that would go and hunt and search for credentials,â says Lyborg. âBut then you had all these false positives.â
The findings piled up. Ranking them needed context that sat in other teamsâ systems.
As you try to prioritize and figure all this out, if you donât have the context, then you donât really know what youâre protecting and whatâs being used.â
![]()
What You Didnât See Before, Now You See
Rather than build the missing layer in-house, Lyborg looked for a partner who could get there faster. Hush went in without a rebuild: API integrations pulled inventory from the tools Swimlane already ran, while a lightweight eBPF sensor watched workloads at runtime to show which identities were genuinely in use. The secrets themselves never left Swimlaneâs environment.
âVery easy to spin up, connect our tools into your ecosystem, and then immediately start seeing some of the risks float up to the top,â says Lyborg.
Then came the harder problem. What to do with the findings. Certificates CertManager already rotated were noise. A long-lived database key was not, and chasing one down meant asking another team to do work it hadnât planned for.
âNow you become part of the problem and the friction, because what you didnât see before, now you see,â says Lyborg. âAnd when you tell people about it, thatâs work that they donât necessarily want to do.â
Ownership is what changed that. Every secret, certificate, and non-human identity Hush finds is mapped to an accountable owner, so a finding stops being an anonymous alert. It arrives with the team that owns it, the workload using it, and the reason it matters. Security is no longer the middleman.
âThatâs been the biggest change,â says Lyborg. âOtherwise it always felt like we were pushing whatever business unit to change something. Now we can actually have them self-service and see and get all the context and data on hereâs why.â It also gives him something to report against: âitâs really important to be able to track and trend and see how weâre reducing operational risk.â
Secretless Access, Automated Through CI/CD
Visibility was the first half. The second was removing the credential.
Swimlane now runs policy-based, secretless access, proven first in the teamâs labs and then in production. âThe deployment into the secretless agents, and really the automations that we can now run through our CI/CD â thatâs been pretty transformative,â says Lyborg. âA couple of months ago we were dealing with a lot of YAMLs and everything else. And now itâs automated.â
Policy is written the way the rest of the infrastructure is written: as code. An engineer names the policy, its owner, and the rotation frequency, generates the definition in the AI coding tools the team already uses, and ships it through staging and production. A leaked credential stops being an incident and becomes an API call.
The difference shows up in response. When Swimlane moved a test secret from development into staging, Hush flagged the reuse immediately. Swimlaneâs own automation took it from there, finding the Jira ticket where the team had been troubleshooting and the vault item holding the secret.
âFrom an investigator and responderâs perspective, this triage â it could have taken several hours â was literally done in minutes. Thatâs a really good success story of our partnership.â
![]()
The Agentic Future Needs a Partner, Not a Product
The agentic wave is arriving faster than the last one, with the same problem attached. Swimlaneâs own staff are building AI agents and wiring in MCP servers, and Lyborgâs team tests continuously for prompt injection and guardrails. What he expects is the API-key era at speed: a long-lived, over-privileged token dropped âinto some vault somewhere, hopefully,â and then âthey press play, and then they forget about it.â
He holds agents to the standard he already set for non-human identities: âzero trust, least privilege, by design, always.â Swimlane is now putting Hushâs AI Agent Gateway through its paces on exactly that, giving every agent its own identity, scoped access, and a full audit trail.
Which leaves every security leader the same question: build it, or find someone who already has.
âJust because you can, doesnât mean you should,â says Lyborg. âItâs never been easier to build your own applications. But then youâve got to feed it, maintain it, patch it, secure it, train on it ⊠Itâs awesome to be a Lego master, because you know where each block goes. But sometimes the business impact, if that application goes down, can be far more than you planned for.â
âMake sure you can build trust with them, and that itâs not just a product that you consume. Itâs truly a partnership, where we design together and we solve whatâs next together.â
By that measure, Hush qualifies. Lyborg points to the weekly touchpoint: âknowing whatâs coming means we can tee things up.â
âSecrets are the past. Policy-based, secretless access is the future. We solved identity for people with automation and Zero Trust. Now itâs time to do the same for machines. By eliminating secrets and adopting policy-based, runtime access, we can finally secure machine identities at the scale and speed the future demands.â
![]()