Truffle Security announced a $25 million Series B on November 6, 2025, to expand TruffleHog Enterprise, its secrets detection and non-human identity (NHI) security product. Intel Capital and Andreessen Horowitz (a16z) led the round. The company also introduced TruffleHog GCP Analyze, an Enterprise add-on for assessing access associated with leaked Google Cloud service accounts.
Who invested in Truffle Security’s Series B?
Truffle Security said Intel Capital and a16z led the $25 million round. Other participants were Abstract, Lytical Ventures, and security leaders Casey Ellis, founder of BugCrowd; Emilio Escobar, Datadog’s CISO; and Haroon Meer, Thinkst’s founder and CEO. The company announced the financing on November 6, 2025. Truffle Security’s announcement and SecurityWeek’s coverage reported the round.
What does Truffle Security plan to do with the funding?
The company said it would invest in TruffleHog Enterprise, customer success and go-to-market efforts, and product innovation. It also named expanding NHI analysis beyond Google Cloud to AWS and Azure as a goal. That is a stated plan, not confirmation that those capabilities have shipped.
What is TruffleHog GCP Analyze?
Truffle Security introduced GCP Analyze as an add-on for TruffleHog Enterprise. The company says it provides context about leaked Google Cloud service accounts, including which resources they can access, how permissions are inherited, and the potential blast radius. The aim is to help security teams judge exposure and prioritize remediation. These are vendor-described functions; the available reporting does not independently evaluate the product.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
What does TruffleHog do?
Truffle Security describes TruffleHog as a tool for finding exposed secrets and NHIs, such as API keys, passwords, and tokens, across sources including code, chat, and support systems. The company says it can scan hidden content, deleted code, and version history; verify more than 800 credential types with providers; and analyze related resources and permissions. These descriptions come from the company website and should not be read as independent performance findings.
TruffleHog is both an open-source project and the foundation for the company’s enterprise product. The distinction matters: the funding announcement concerns Truffle Security and its commercial expansion, while the company presents TruffleHog’s detection and verification capabilities as part of a broader platform for secrets and NHIs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What growth figures did the company report?
In its November 6, 2025 announcement, Truffle Security reported more than 23,000 GitHub stars, 15 million downloads, and over 250,000 daily runs worldwide. It also said revenue had more than doubled in the prior year, without providing a revenue baseline. These are company-reported figures from the announcement, not independently audited results or current 2026 metrics.
The announcement cited credential misuse as a security concern and referred to Verizon’s 2025 Data Breach Investigations Report, but it did not provide a specific statistic in the material reported here. Martin Casado, a general partner at a16z, characterized the company’s focus as “protecting codebases from secret exposure at scale.”
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

