You should not trust automatic tools to do that. They will inevitably be subject to both false negatives and false positives, and will most probably just give you a false sense of security but will not protect you from the actual leak.
You should better review stuff that you publish. That includes commit review, package contents review before publishing them, config files review, logs review before sharing them.
If you have an org — it would better to educate your devs more and make each commit go through an independent review. Also, don't forget about checking package contents.