Skip to main content
megaphone icon

Build Cloud Native Apps

Ready for AI? Discover how to build and scale cloud-native apps with Azure.

LEARN, CONNECT, BUILD

Microsoft Reactor

Join Microsoft Reactor and engage with developers live

Ready to get started with AI and the latest technologies? Microsoft Reactor provides events, training, and community resources to help developers, entrepreneurs and startups build on AI technology and more. Join us!

LEARN, CONNECT, BUILD

Microsoft Reactor

Join Microsoft Reactor and engage with developers live

Ready to get started with AI and the latest technologies? Microsoft Reactor provides events, training, and community resources to help developers, entrepreneurs and startups build on AI technology and more. Join us!

Go back

The Quote-to-Cash Blind Spot: Secret Scanning for Enterprise Revenue Systems

9 September, 2026 | 5:00 PM - 6:00 PM (UTC) Coordinated Universal Time

  • Format:
  • alt##LivestreamLivestream

Topic: Security

Language: English

Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.

Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.

A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.

  • DevSecOps
  • Security
  • GitHub Copilot
  • GitHub Advanced Security

Speakers

Already registered and need to cancel? Cancel registration

Registration

Sign in with your Microsoft Account

Sign in

Or enter your email address to register

*

By registering for this event you agree to abide by the Microsoft Reactor Code of Conduct.