Customer Success

How Swimlane Went From Hunting Credentials to Eliminating Them

Hush gives Swimlane full visibility into every non-human identity, clearing the way to eliminate static credentials altogether.

Industry

Cybersecurity

Hush Products

  • NHI Access Management
  • Agentic Identity Gateway

Use Cases

  • Runtime Discovery & Visibility
  • Identity-Based Access
  • Runtime Risk Analysis
  • Ownership Attribution
  • Governance & Audit

Tech Stack

Challenge

Scattered ownership

Credentials sat across cloud, SRE, security operations, application, and network teams, with no shared record of what existed, where it lived, or when it was last used.

False positives

Custom detection built on TruffleHog returned high volumes of findings, many of them false positives, with no context for ranking the rest.

Rotation meant downtime risk

Credentials baked into applications meant changing one could take the application down, so long-lived keys stayed in place.

Solution

Findings that arrive with an owner

Runtime discovery gave Swimlane one view of every secret, certificate, and non-human identity, each mapped to an accountable owner, so work routes to the team that can fix it instead of landing on security.

A findings list they could act on

Runtime evidence of what was actually in use separated the certificates CertManager already rotated from the long-lived database key that mattered.

Credentials they no longer have to rotate

Policy-based, secretless access replaced static credentials, with rotation automated through CI/CD instead of hand-edited YAML.

Deployment that didn’t fight engineering

Agentless integrations and a lightweight runtime sensor, no code changes, and risks surfacing immediately.

Rotation without downtime

Credentials revoked and reissued by API call

Hours to minutes

Reduced credential-exposure triage time

Chasing owners to self-service

Business units now remediate with the context attached

Hunting Credentials, Drowning in False Positives

Swimlane builds agentic AI automation for security operations teams. Michael Lyborg, its Chief Information Security Officer, had already built the controls most mature security programs rely on: shift-left scanning, secret blocking in CI/CD, PCAPs pulled from scaled-down production workloads, eBPF evaluated for risky transport.

Non-human identity wasn’t new to him. He dates it back to “the good old days of Active Directory forests and trees and service accounts,” and says the last 20 years of API keys are what made it big: “often over-provisioned and over-privileged.”

Those controls covered the commit stage, but not every place a credential could end up. “A lot of times, because we’re humans, maybe somebody copies an API key or a token and puts it in a Jira ticket,” he says.

So the team built its own detection, and got buried. “We started building out, through TruffleHog and all these custom automations, that would go and hunt and search for credentials,” says Lyborg. “But then you had all these false positives.”

The findings piled up. Ranking them needed context that sat in other teams’ systems.

As you try to prioritize and figure all this out, if you don’t have the context, then you don’t really know what you’re protecting and what’s being used.”

Michael Lyborg, Chief Information Security Officer, Swimlane

What You Didn’t See Before, Now You See

Rather than build the missing layer in-house, Lyborg looked for a partner who could get there faster. Hush went in without a rebuild: API integrations pulled inventory from the tools Swimlane already ran, while a lightweight eBPF sensor watched workloads at runtime to show which identities were genuinely in use. The secrets themselves never left Swimlane’s environment.

“Very easy to spin up, connect our tools into your ecosystem, and then immediately start seeing some of the risks float up to the top,” says Lyborg.

Then came the harder problem. What to do with the findings. Certificates CertManager already rotated were noise. A long-lived database key was not, and chasing one down meant asking another team to do work it hadn’t planned for.

“Now you become part of the problem and the friction, because what you didn’t see before, now you see,” says Lyborg. “And when you tell people about it, that’s work that they don’t necessarily want to do.”

Ownership is what changed that. Every secret, certificate, and non-human identity Hush finds is mapped to an accountable owner, so a finding stops being an anonymous alert. It arrives with the team that owns it, the workload using it, and the reason it matters. Security is no longer the middleman.

“That’s been the biggest change,” says Lyborg. “Otherwise it always felt like we were pushing whatever business unit to change something. Now we can actually have them self-service and see and get all the context and data on here’s why.” It also gives him something to report against: “it’s really important to be able to track and trend and see how we’re reducing operational risk.”

Secretless Access, Automated Through CI/CD

Visibility was the first half. The second was removing the credential.

Swimlane now runs policy-based, secretless access, proven first in the team’s labs and then in production. “The deployment into the secretless agents, and really the automations that we can now run through our CI/CD — that’s been pretty transformative,” says Lyborg. “A couple of months ago we were dealing with a lot of YAMLs and everything else. And now it’s automated.”

Policy is written the way the rest of the infrastructure is written: as code. An engineer names the policy, its owner, and the rotation frequency, generates the definition in the AI coding tools the team already uses, and ships it through staging and production. A leaked credential stops being an incident and becomes an API call.

The difference shows up in response. When Swimlane moved a test secret from development into staging, Hush flagged the reuse immediately. Swimlane’s own automation took it from there, finding the Jira ticket where the team had been troubleshooting and the vault item holding the secret.

“From an investigator and responder’s perspective, this triage — it could have taken several hours — was literally done in minutes. That’s a really good success story of our partnership.”

Michael Lyborg, Chief Information Security Officer, Swimlane

The Agentic Future Needs a Partner, Not a Product

The agentic wave is arriving faster than the last one, with the same problem attached. Swimlane’s own staff are building AI agents and wiring in MCP servers, and Lyborg’s team tests continuously for prompt injection and guardrails. What he expects is the API-key era at speed: a long-lived, over-privileged token dropped “into some vault somewhere, hopefully,” and then “they press play, and then they forget about it.”

He holds agents to the standard he already set for non-human identities: “zero trust, least privilege, by design, always.” Swimlane is now putting Hush’s AI Agent Gateway through its paces on exactly that, giving every agent its own identity, scoped access, and a full audit trail.

Which leaves every security leader the same question: build it, or find someone who already has.

“Just because you can, doesn’t mean you should,” says Lyborg. “It’s never been easier to build your own applications. But then you’ve got to feed it, maintain it, patch it, secure it, train on it 
 It’s awesome to be a Lego master, because you know where each block goes. But sometimes the business impact, if that application goes down, can be far more than you planned for.”

“Make sure you can build trust with them, and that it’s not just a product that you consume. It’s truly a partnership, where we design together and we solve what’s next together.”

By that measure, Hush qualifies. Lyborg points to the weekly touchpoint: “knowing what’s coming means we can tee things up.”

“Secrets are the past. Policy-based, secretless access is the future. We solved identity for people with automation and Zero Trust. Now it’s time to do the same for machines. By eliminating secrets and adopting policy-based, runtime access, we can finally secure machine identities at the scale and speed the future demands.”

Michael Lyborg, Chief Information Security Officer, Swimlane