Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    Vendor Insights
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.
    4.8

    Overview

    Play video

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    Business Plan, per 25 contributing developers (annual contract)
    $5,500.00

    Vendor refund policy

    Please contact sales@gitguardian.com  to learn more about GitGuardian's refund policy.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform https://docs.gitguardian.com  or submit a support request at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    100
    In Application Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    18 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secrets Detection
    Advanced platform capable of identifying over 450 types of sensitive credentials including API keys, private keys, and database credentials
    Policy Enforcement
    Robust policy engine that enables rule implementation across multiple version control systems, CI/CD tools, and productivity platforms
    Public Repository Monitoring
    Comprehensive scanning of public GitHub repositories to detect sensitive information leakage from organizational and personal accounts
    Non-Human Identity Security
    Integrated approach for managing and protecting service accounts, application credentials, and other non-human authentication mechanisms
    Incident Detection
    Real-time monitoring and identification of compromised, misused, or illegitimate secrets across internal and external environments
    Secrets Management
    Centralized platform for securely managing and rotating credentials across multi-cloud and hybrid environments
    Identity Authentication
    Secure authentication mechanism for applications, automation tools, and non-human identities accessing sensitive resources
    DevSecOps Integration
    REST API-enabled solution with extensive integration capabilities for DevOps tools and container platforms
    Access Control
    Centralized control and auditing of privileged credentials and secrets usage across databases and cloud environments
    Scalability
    Enterprise-grade solution designed to support large-scale deployments with data sovereignty and global enterprise requirements
    Secret Management
    Cloud-hosted platform for centralized secrets management and orchestration
    Access Control
    Scalable and flexible access controls with detailed activity logs for real-time management
    Environment Integration
    Automatic secret synchronization across multiple projects, teams, and infrastructure environments
    Development Workflow
    Native VS Code extension with two-way secret synchronization and CLI support for local development
    Credential Security
    Automated credential rotation mechanism to prevent potential data breaches and security vulnerabilities

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    252 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    66%
    31%
    3%
    0%
    0%
    3 AWS reviews
    |
    249 external reviews
    External reviews are from G2  and PeerSpot .
    Pedro P.

    (mainly) monitoring apikey disclosure

    Reviewed on Dec 11, 2025
    Review provided by G2
    What do you like best about the product?
    I appreciate how quickly and accurately incidents are reported.
    What do you dislike about the product?
    Sometimes the reports are a bit hard to read.
    What problems is the product solving and how is that benefiting you?
    (Mainly) to monitor my git repository changes and prevent unauthorized disclosure of API keys (or other sensitive credentials).
    Jaret Gadir H.

    The Best Solution for Secure Key Sharing

    Reviewed on Dec 06, 2025
    Review provided by G2
    What do you like best about the product?
    This tool is the best solution I've found for addressing the issue of sharing secret keys through bad practices.
    What do you dislike about the product?
    At the moment, this isn't an issue for me.
    What problems is the product solving and how is that benefiting you?
    The tool helped me resolve issues related to my secret keys and addressed the problems assigned to me. I found the settings easy to understand, and I am grateful for this tool.
    Takudzwa S.

    Instant Secrets Detection with Actionable Alerts

    Reviewed on Nov 27, 2025
    Review provided by G2
    What do you like best about the product?
    GitGuardian delivers immediate detection and response. When a sensitive file, credential, or secret slips into a commit, it flags it within seconds and pinpoints the exact line that triggered the alert. The platform forces clarity: it shows the severity, lets me classify the criticality, and pushes fast remediation instead of noise. The value is precision, speed, and zero guesswork.
    What do you dislike about the product?
    The alerting is fast, but the volume can feel heavy when working across multiple repos with frequent commits. False positives still appear, which adds review time. The remediation steps are clear, yet the interface for navigating multiple incidents can feel cluttered, and sorting through similar alerts requires extra manual filtering.
    What problems is the product solving and how is that benefiting you?
    It closes the gap between accidental secret exposure and detection. The moment a credential or sensitive file is committed, it identifies the leak, marks the exact line, and forces immediate remediation. This removes manual scanning, reduces the risk window, and keeps repos clean during SAST and secure code review.
    Shoib A.

    Excellent Protection for Project Privacy

    Reviewed on Nov 26, 2025
    Review provided by G2
    What do you like best about the product?
    It's a good software which always warna me if I had leaked any private information about my projects
    What do you dislike about the product?
    Nothing yet, everything is good the alert system is also good
    What problems is the product solving and how is that benefiting you?
    It is solving my API leaking problem sometimes I push my .env files with my project and it warns me immediately
    Ahmed A.

    Fast and Accurate Secret Detection

    Reviewed on Nov 19, 2025
    Review provided by G2
    What do you like best about the product?
    It is able to catch missed secrets, fast. It is automated so it is easy to sue and implemented/integrated automatically. It is always active so it detects new issues as fast as they are committed, usage is good. Never had to try to reach out to customer support, so that's a plus.
    What do you dislike about the product?
    Removing false flag has a not-good-enough UX.
    What problems is the product solving and how is that benefiting you?
    I am able to find out missed secrets, even placeholder values are detected, which I put during testing. So that's something that is forgettable to remove, but GitGuardian detecting comments as well is really smart.
    View all reviews