| Cloud object-storage key | Whether the key authenticates, and which containers and objects it reaches. Metadata enumeration sizes the exposure without reading anything inside it. | Rotating the key does not invalidate anything already copied out of the containers it opened. Reviewing activity and diagnostic logs to scope access is a separate and mandatory step, and its output is the input to a breach-notification decision. |
| Where a sample is genuinely needed to establish what the data is, it is bounded and read-only. Nothing is modified or deleted, personal data and secret values are redacted before anything is written down, and every request carries an audit identifier you can reconcile against your own cloud logs. |
| Cloud IAM access key | Whether it authenticates, and what the identity behind it is permitted to do. Permissions are enumerated, not exercised. | Deactivate before delete, so a dependency that breaks is recoverable. Then find every place the key was deployed: the second copy sitting in a build variable is what reinstates the exposure a week later. |
| Enumerating a permission is not using it. Where the enumeration itself falls outside authorised scope, the finding stays untested and says so on the row. |
| Third-party platform API key | Whether the issuer still honours it, and whether it is scoped or unrestricted. Issuers differ sharply in what they will disclose without the key being exercised. | The issuer revokes and you redeploy. The slow part is the inventory of consumers, which is routinely undocumented for a platform an external team built and runs. |
| Some issuers publish an introspection or metadata endpoint that answers this with no privileged call at all. Where none exists, no safe check exists either, and the finding stays untested and says so on the row: an untested key is never reported as a dead one. |
| Application signing key | Whether the key material is well-formed and matches a certificate or artefact you publish. Validity is a property of the material, so establishing it requires no call to anybody. | Re-issue, re-sign and redistribute. Everything already signed with the exposed key stays trusted by every client that has not yet received the new material, which makes this the class where rotation is a release programme rather than a console action. |
| A signing key is the class most often graded low by a scanner, because nothing about it authenticates to a service. Blast radius here is a function of what trusts it, not of what it opens. |
| Database connection string | Whether the host answers from the public internet at all. Many do not, which changes the grade without changing the fact that the credential is public. | Change the credential, then find every application, scheduled job and dashboard holding it. Unreachable today is not unreachable after the next network change, so the grade is not a reason to leave it. |
| Where the host does answer publicly, authenticating into it is tested only where that is safe and authorised. |
| OAuth refresh or build token | Whether the token still exchanges for an access token, and which scopes come back with it. | Revoke the token and terminate the sessions it has already minted. A refresh token revoked on its own leaves the access it granted alive until those sessions expire by themselves. |
| This is the class most likely to be re-surfaced later by dark-web collection: the same token, traded, long after the repository itself is gone. |