Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI CD pipelines, and productivity tools with GitGuardian code security platform.
    4.4

    Overview

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    36-month contract (1)

     Info
    Dimension
    Description
    Cost/36 months
    25 developers
    GitGuardian Business Secret detection for 25 Developers
    $16,500.00

    Vendor refund policy

    Full refund within 90 days of purchase. Contact support via email.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform or submit a support ticket in the platform. You can reahc out to our support team for any issue you encounter at support@gitguardian.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.4
    18 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    61%
    39%
    0%
    0%
    0%
    4 AWS reviews
    |
    14 external reviews
    External reviews are from PeerSpot .
    Sanket-Shinde

    Secret scanning has protected sensitive data and now streamlines fixing vulnerabilities

    Reviewed on Apr 19, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I use GitGuardian Platform  to ensure that there are no secrets committed, such as hardcoded values, database credentials, API keys, or any secrets that could be exposed to external users of our application. To maintain security and data accuracy, confidential data should not be shared with other platforms. GitGuardian Platform  checks our local code first, then it passes through our CI/CD pipeline as well. When we push code to GitHub , it scans and sends a report via Gmail, so we have to fix those security vulnerabilities.

    What is most valuable?

    The best features of GitGuardian Platform are that it detects everything being pushed through the repository and scans everything comprehensively. It checks the possibility of exposure, so if there are API keys or database passwords being used, it warns us to either remove, rotate, or replace them, ensuring they should not be present in a GitGuardian Platform scan.

    Our company has seen many benefits from using GitGuardian Platform, especially since there have been numerous cyber attacks and security threats in the last two to three years. Our company has remained very safe in this regard because we need to secure our data effectively, being in the insurance reinsurance sector. GitGuardian Platform ensures our data is protected by regularly scanning the repositories and sending us reports on how to fix vulnerabilities, keeping us safe from cyber attacks.

    What needs improvement?

    GitGuardian Platform could improve by providing a more user-friendly UI with tips or solutions. With AI advancements, they could offer AI-specific solutions in scanning reports, suggesting fixes for GitGuardian Platform incidents, and even permit automated fixes, which would significantly reduce the developer's workload.

    For how long have I used the solution?

    I have been using GitGuardian Platform for the last one year.

    What do I think about the stability of the solution?

    Stability and availability of GitGuardian Platform are commendable; it is stable and available.

    It is stable because when I push changes, it scans immediately, confirming fixes. There is no downtime during scanning, maintaining stability and availability.

    How are customer service and support?

    I find support good since we have not needed much help from them. The guidelines provided are sufficient for guiding us on what to fix.

    Which other solutions did I evaluate?

    There are many tools in our organization for similar purposes, but GitGuardian Platform is specifically for exposing secrets. We also use Snyk  for vulnerability scanning, among others, though I cannot recall all of them.

    The decision was made by my organization, not me, so I am not sure about the parameters they considered before choosing GitGuardian Platform.

    What other advice do I have?

    GitGuardian Platform prioritizes incidents in our workflow through automated validity checks. There are high risk, low risk, and medium risk incidents raised, and the infosec team prioritizes them and approaches us, the developers who pushed those changes, to fix them accordingly.

    GitGuardian Platform's public leakage detection influences our company's data security as a precaution. We are not sure if data might be exposed, but taking this precaution by scanning the repositories is crucial. A cyber attacker just needs one piece of data, so we ensure at least that one thing is secured. It is about cyber attack prevention, ensuring all our data remains safe.

    It rates the effectiveness of severity in incident management based on the severity of the change. This allows us to address the most important ones first. It checks what has been pushed from the code, raising a high-level vulnerability if database-related passwords are involved and reports it urgently. For low-level issues like hardcoded values for APIs, it is reported accordingly based on priority.

    I use GitGuardian Platform's automated playbooks for scanning. Productivity-wise, these playbooks help me know if I am going to push code with secrets. I am aware now, so I intentionally avoid that, ensuring I write good code. It increases my productivity by helping me fix issues proactively. If GitGuardian Platform were not here and vulnerabilities were discovered later, there could be severe consequences. Currently, that impact has been reduced, minimizing our efforts significantly through early precautions.

    Our organization is currently innovating on the AI side, which includes creating a custom agent to fix vulnerabilities, similar to GitHub  Copilot. This agent automates changes required based on GitGuardian Platform scanning, closing incidents directly. This support reduces our efforts and timelines.

    Fixing vulnerabilities now takes approximately 60% less time. If fixing took ten days, I now do it in six. I am not sure about multi-vault integration because I am just a developer using it to fix my code changes. I am not sure if I am using GitGuardian Platform's Honey Tokens feature. I would rate this product an 8.5 overall.

    reviewer2740785

    Supports application security by detecting a wide range of secrets and allows integration into existing vulnerability management processes

    Reviewed on Jul 16, 2025
    Review from a verified AWS customer

    What is our primary use case?

    My use case for the GitGuardian Platform  is application security for our enterprise repository.

    How has it helped my organization?

    The solution has improved our organization. We are still in the rollout, but the users who are utilizing it are very happy, especially about the feature that enables pre-commit hooks in Git  that will not raise to the remote repository. This is a very good feature that our developers use very heavily.

    What is most valuable?

    The best features of the GitGuardian Platform  are that it finds many different secrets, more than other competitors, and the support from the colleagues is also very good.

    The GitGuardian Platform helps in monitoring and protecting our code repositories from leakage. It helps significantly because we connected our vulnerability management process to this, and the colleagues from vulnerability management have much easier work since we have the GitGuardian Platform installation due to the dedicated incidents or issues which are opened automatically.

    The alerting capabilities and threat intelligence features of the GitGuardian Platform are managed by another team; we only host the platform.

    The audit logs and compliance reports from GitGuardian are very helpful because, in the past, we needed to do it manually by scanning the repos. Now with GitGuardian Platform, we have a really good overview of what is open, what is closed, and how critical the issues are.

    What needs improvement?

    The areas that have room for improvement involve the missing feature to add custom detectors for the GitGuardian Platform, which would help us check if internal secrets are still valid or not.

    I assess the accuracy of the detection from the GitGuardian Platform as very good because we don't have many false positives, which means the quality is very good. The only thing we want to have are some additional detectors which help us to prioritize, especially since enterprise secrets are found, but they cannot verify if they are valid or not.

    For how long have I used the solution?

    I have been using the GitGuardian Platform for one and a half years.

    What do I think about the stability of the solution?

    The stability of the GitGuardian Platform is excellent. We don't have any problems with the stability of the system at all.

    What do I think about the scalability of the solution?

    The scalability of the GitGuardian Platform is excellent.

    How are customer service and support?

    The technical support from the GitGuardian Platform deserves a rating of nine out of ten.

    What about the implementation team?

    The deployment of the GitGuardian Platform is very easy because it's a Helm chart which is very easy to install for us. The deployment took several days.

    What's my experience with pricing, setup cost, and licensing?

    I have no information about pricing, but since they won the request for quotation, I believe it's a good price.

    Which other solutions did I evaluate?

    We created a technical evaluation and checked against other providers, though I don't remember the names. The GitGuardian Platform has the best technical capabilities, and our procurement handles the pricing part.

    What other advice do I have?

    The GitGuardian Platform is used worldwide in our environment.

    Currently, we have approximately 1,300 licenses for the GitGuardian Platform, but we will increase to 2,000 next year.

    The solution requires maintenance from our side only for user management, which is normal for each application.

    I cannot quantify how much time or resources the GitGuardian Platform saves us because this is spread across all teams worldwide.

    I would recommend the GitGuardian Platform to other users because the integration with GitHub  and Azure DevOps  is very easy, and you also have the possibility to use it locally on your IDE . This is a very good solution.

    I rate the GitGuardian Platform a nine out of ten because room for improvement is always possible, but it's really good.

    Kingsley Zikora

    Efficiently manages sensitive data but needs improvement in credential differentiation

    Reviewed on Jul 07, 2025
    Review from a verified AWS customer

    What is our primary use case?

    We initially integrated GitGuardian Platform  into our organization in 2023 into our GitHub  repository. We implemented it because we did not want our secret credentials to be exposed to the internet or to a third party such as GitHub . It flags when credentials have been exposed so we can remediate and fix them. GitGuardian Platform  was what my tech lead suggested we use, and we had to incorporate it into our repositories. We use the Platform version.

    What is most valuable?

    What I appreciate the most about GitGuardian Platform is its efficiency when triggering our pipeline and notifying us if secrets have been exposed, such as APIs, variables, our database, or anything being exposed. Currently, we have numerous repositories and pushes that happen in our repo. It would be humanly impossible for us to manually search for these secrets. GitGuardian Platform can do this automatically. All we need to do is wait for an email notification that indicates a secret has been exposed. It points out the repository that has the secret exposed, and we can fix it. This saves us the time of manual review.

    What needs improvement?

    The main disadvantage I feel they should improve upon is that apart from flagging credential issues or secrets, they could incorporate something else to make it more dynamic. If their product focuses majorly on secrets leaking, similar to Amazon Macie , they could expand their capabilities. Amazon Macie  primarily flags secrets being exposed over the internet.

    For example, we use Dependabot for code review. Dependabot helps us follow best practices such as code quality and code analysis, as we cannot manually check 10,000 lines of code to ensure they follow structural standards. If GitGuardian Platform could incorporate code analysis into their system, not just for secrets alone, it would make them more dynamic.

    This would allow users to have just one tool instead of multiple third-party tools running in GitHub. It would reduce management overhead as you wouldn't have to manage multiple tools.

    For how long have I used the solution?

    I have been using GitGuardian Platform in my career for almost two years now.

    What do I think about the stability of the solution?

    For my organization, GitGuardian Platform has been stable. Since installation, we haven't had to optimize it, and I am unsure about new versions. It has been functioning effectively, and its performance is satisfactory. The only limitation is that it performs just one task. While it is efficient at credential flagging, it could offer more functionality.

    What do I think about the scalability of the solution?

    Regarding scalability, in my organization, we have about 44 repositories running, and GitGuardian Platform has been able to handle these repositories efficiently. I am uncertain about its capability to handle 100 repositories. For our organization, which is just four years old and not a large platform with numerous features, it functions adequately with our 44 repositories.

    Some tools can function properly until demand increases or usage reaches a certain extent, at which point they might start deteriorating. For instance, with our GitHub account, we had to pay for more capacity usage. I am unsure if GitGuardian Platform has similar limitations on the number of repositories it can handle. However, for our current 44 repositories, it has been working exceptionally.

    How are customer service and support?

    I have never contacted any technical support or customer support through phone or ticket system. We have never experienced any issues with it. It effectively helps us with credentials security and has been performing satisfactorily.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I have not compared GitGuardian Platform with any alternatives in my organization. For GitHub repositories credentials, we use GitGuardian Platform. For AWS , we use Amazon Macie because we run our infrastructure on Amazon Web Services . We use Macie to protect our credentials from being exposed.

    How was the initial setup?

    The initial deployment and installation was very easy for us.

    What about the implementation team?

    For this deployment, my tech lead handled the implementation. We were on a call with him while he deployed it. It required only one person to complete the setup.

    What was our ROI?

    It does not require any maintenance on our end as it has been working autonomously. I am unaware of new versions, but what we have been using has not required maintenance.

    What's my experience with pricing, setup cost, and licensing?

    I am not involved with the pricing of GitGuardian Platform, as the tech lead handled those aspects. Initially, I thought it was an open-source tool. There are private and public versions available. The private version requires payment, but for the public version we use, we did not make any payments.

    Which other solutions did I evaluate?

    I have not compared GitGuardian Platform with any alternatives in my organization. For GitHub repositories credentials, we use GitGuardian Platform. For AWS, we use Amazon Macie because we run our infrastructure on Amazon Web Services. We use Macie to protect our credentials from being exposed.

    What other advice do I have?

    I will rate GitGuardian Platform a seven out of ten. The reason for this rating is that I wish they could have an agent embedded into their system that helps to identify real credentials from mock credentials, as this sometimes causes false alarms.

    We are users of the product with no partnerships with GitGuardian Platform. They can contact me regarding any questions about this review. I am open to anything that benefits the community and makes everything better.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Ney Roman

    Facilitates efficient secret management and improves development processes

    Reviewed on Jun 23, 2025
    Review from a verified AWS customer

    What is our primary use case?

    My use case for the GitGuardian Platform is application security.

    What is most valuable?

    My impression of the GitGuardian Platform's capability to detect secrets in real time is actually really amazing, because it lets us protect or block the pipelines in which we deploy new applications so we can acknowledge when a secret is hardcoded in a repository, or when we have already hardcoded secrets within templates in our repos.

    We adopted it a year ago, and it has been doing great in our teams, especially for developers. The impression so far has been good.

    The severity scoring has helped us in incident management because it is doing the correct job. We got many secrets leaked within our platform and it was making the correct warnings regarding that particular secret, as we had a hardcoded Google Cloud API key. It was marked as a critical severity, so we had the chance to correct it, regenerate that secret and work again on not hardcoding secrets within our code.

    GitGuardian's public leak detection significantly enhances our organization's data security by continuously monitoring public repositories. It allows us to proactively identify accidental exposures of sensitive credentials or secrets.

    What needs improvement?

    Regarding the exceptions in GitGuardian Platform, we know that within the platform we have a way to accept a path or a directory from a repository, but it is not that visible at the very beginning. You have to figure out where to search for it, and once you have it, it is really good, but it is not that visible at the beginning. This should be made more exposed.

    The documentation could be better because it was not that comprehensively documented. When we started working with GitGuardian Platform, it was difficult to find some specific use cases, and we were not aware of that. It might have improved now, but at that time, it was not something we would recommend.

    For how long have I used the solution?

    I have been using the GitGuardian Platform for almost a year now.

    What do I think about the stability of the solution?

    From 1 to 10, I rate the stability of the GitGuardian Platform a 10, as there are no downtimes.

    What do I think about the scalability of the solution?

    I would rate the scalability as a 10, since we did not have any problems.

    How are customer service and support?

    For technical support, I would give a solid 10. They have someone who speaks Spanish, which made it easier for us.

    Which solution did I use previously and why did I switch?

    I am comparing it with Advanced Security from GitHub and Cycode.

    How was the initial setup?

    Two of us were involved in the deployment process.

    It took a week to deploy the GitGuardian Platform, just to standardize the process.

    What about the implementation team?

    Two of us were involved in the deployment process.

    What was our ROI?

    Regarding return on investment, we have actually saved time and resources because before having GitGuardian Platform, we had two or three people working in every repository looking for secrets with open-source tools. It took a long time to find secrets or many patterns, and at the time, we had to configure our own patterns to find them. I cannot specify the exact return on investment, but I can surely say that we have saved significant time and resources, particularly in terms of people and automation.

    Which other solutions did I evaluate?

    I would compare the GitGuardian Platform to other solutions or vendors on the market as being easier to use, but it is not integrated with the CSM that we are using right now. That is the difference. It is easy to use, but it could be easier.

    What other advice do I have?

    We are customers in our company's relationship with the vendor.

    I work primarily with the CLI, focusing on pipelines and automations rather than the platform itself. The platform has remained almost the same within the year that we have been working with it.

    We are not utilizing the automated playbooks yet.

    I cannot determine if the pricing is cost-effective.

    The vendor can contact me if they have any questions or comments about my review.

    I have rated the GitGuardian Platform a 10 out of 10.

    reviewer2721312

    Custom detectors streamline workflow and real-time detection enhances security

    Reviewed on Jun 11, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Our current use cases for GitGuardian Platform  involve monitoring external and internal GitHub  and GitLab , Bitbucket , and other code repositories that it supports for secrets.

    What is most valuable?

    The newest addition that we appreciate about GitGuardian Platform  is the ability to create a custom detector, which we built and worked with the team, and that works very effectively.

    GitGuardian Platform performs the capability to detect secrets in real time exceptionally, as it activates from the commit and can detect it immediately.

    We utilize GitGuardian Platform's automated validity checks in some cases, and they seem to work effectively. We are still experimenting with them.

    The multi-vault integration plays a key role in our secrets management strategy because we have multiple different vaults, and that works effectively.

    What needs improvement?

    GitGuardian Platform does what it is designed to do, but it still generates many false positives.

    We utilize the automated playbooks from GitGuardian Platform, and we are enhancing them. We will probably stop using some of them, but we are building off of them. The one piece they do not include is contacting the person's manager or copying them, which we feel is necessary to prevent insider threat and other issues, but they do not have access to our hierarchy of employees.

    We are not using the honeytokens feature of GitGuardian Platform.

    Regarding improvements, there are two things we are working on with them. They have added charts, which is a new feature, but it is still not accurate. It has taken 4 to 5 months and it is fairly slow. We are looking for better metrics and audit data, wanting more features such as knowing which users are creating the most secrets or committing the most secrets, what repository, what directory, and who is not checking in secrets, which repo, user, or directory has not had any secrets committed. We want more metrics around both good and bad to see how we are performing.

    For how long have I used the solution?

    I have been using GitGuardian Platform for 5 years at the company, and my team has been using it for 3 years.

    What do I think about the stability of the solution?

    There has not been any instability with GitGuardian Platform; it performs reliably.

    What do I think about the scalability of the solution?

    Currently, what GitGuardian Platform is doing works effectively. It is quick and meets our needs. If we added more, I do not think that would really impact performance, so the scalability in that aspect is fine. I know they are trying to branch out and look for secrets in other types of tools, but I am not sure if we are going to use them for that or if that would impact performance or stability either.

    How are customer service and support?

    I have contacted technical support previously, but we usually work through our customer representative directly, and they create the tickets for us.

    How was the initial setup?

    We have one employee that primarily works on the deployment and configuration of GitGuardian Platform, and that took approximately a couple of weeks working directly with them. After that, she spends about an hour in there a week, so it requires minimal effort on our side.

    GitGuardian Platform requires very little maintenance on our end—just making sure the keys are connected and ensuring people are following through.

    Which other solutions did I evaluate?

    I have not used any alternatives to GitGuardian Platform in this specific scope, as I have not found one that fully integrates into as many different code repositories. We have used a couple of tool-specific ones, but GitGuardian Platform is the only one we have used that works across multiple platforms.

    What other advice do I have?

    We purchased GitGuardian Platform for a compliance checkbox because we needed to monitor secrets in our code repositories. We saw benefits immediately after implementation, but the reason my team took it over after a couple of years is that the original team did not really go beyond a compliance checkbox. We started seeing benefits in year 3 as we built out a workflow to contact the developers who committed code with secrets and get them to review and approve or revoke the process.

    In terms of how GitGuardian Platform Public Leakage Detection influences our data security, it helps us with our known developers, but it is fairly limited. It has to go to another developer who has to make it public or they have to put codes in there, so it works in the right scenario, but there are scenarios where it still misses.

    We do not really look at the automated security severity scoring in Incident Management . We still are getting false positives and others, so we are concentrating more on that versus any severity rating.

    The pricing for GitGuardian Platform is fair, though slightly high.

    We are customers of GitGuardian Platform; we do not have any partnerships or official partnerships, nor are we resellers.

    I rate GitGuardian Platform 8 out of 10.

    View all reviews