Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    Vendor Insights
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.
    4.8

    Overview

    Play video

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    Business Plan, per 25 contributing developers (annual contract)
    $5,500.00

    Vendor refund policy

    Please contact sales@gitguardian.com  to learn more about GitGuardian's refund policy.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform https://docs.gitguardian.com  or submit a support request at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    100
    In Application Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    18 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secrets Detection and Classification
    Supports detection of over 450 types of secrets including API keys, private keys, and database credentials across source code and productivity tools
    Multi-Platform Integration
    Integrates with major Version Control Systems (GitHub, GitLab, BitBucket, Azure DevOps), CI/CD tools (Jenkins, Travis CI), and productivity platforms (Slack, Jira, container registries)
    Public Repository Monitoring
    Scans public GitHub repositories to detect sensitive information in both organizational and personal developer accounts
    Policy Engine and Enforcement
    Includes a robust policy engine that enables security teams to enforce rules and manage secrets lifecycle across integrated platforms
    Honeytokens and Incident Detection
    Deploys honeytokens for defense and monitors for incidents, policy violations, and illegitimate use of secrets in both public and internal environments
    Centralized Secrets Management
    Centrally secures, rotates, and manages secrets across multi-cloud and hybrid environments with a unified view across multiple AWS accounts and AWS Secrets Manager instances.
    Multi-Platform Integration
    Offers REST APIs and integrates with a wide range of DevOps tools, container platforms, vulnerability scanners, RPA, and automation tools for credential delivery.
    Secrets Rotation and Lifecycle Management
    Automatically rotates secrets in AWS Secrets Manager and across enterprise environments without requiring changes to developer workflows or applications.
    Audit and Access Control
    Provides centralized control and comprehensive auditing of how applications, DevOps tools, and automation platforms authenticate and access sensitive resources including databases and cloud environments.
    Enterprise-Scale Architecture
    Designed to support massive scalability with data sovereignty requirements for large global enterprises and eliminates vault sprawl across distributed environments.
    Secrets Management and Centralization
    Centralized platform for managing secrets across projects, teams, and environments to eliminate secrets sprawl
    Automated Credential Rotation
    Automatic rotation of credentials without downtime to safeguard against data breaches
    Multi-Environment Integration
    Automatic synchronization and deployment of secrets across environments and infrastructure through expanding suite of integrations
    Access Control and Audit Logging
    Scalable and flexible access controls with detailed activity logs for real-time access management and compliance
    Developer-Centric Tools
    VS Code extension for editing secrets alongside code with bidirectional synchronization and Doppler CLI for consuming secrets as environment variables

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    291 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    90%
    9%
    1%
    0%
    0%
    5 AWS reviews
    |
    286 external reviews
    External reviews are from G2  and PeerSpot .
    Pranay Jain

    Automated secret scanning has protected our repositories and now reduces costly key exposure

    Reviewed on Jul 17, 2026
    Review from a verified AWS customer

    What is our primary use case?

    The main use case for using GitGuardian Platform  is storing my confidential information, including secrets and credentials that I have been using in my repository. Whenever I want to store something like secret credentials, I put it in GitGuardian Platform . What it does is detect and provide us with reliable secret detection with accurate alerts, and it has a very clean interface. It is very good with Git , which was developed by Linux. Whenever we have any CI/CD pipeline running, it automatically integrates with it, fetches the secrets from it, and we can put that secret in our code so that code can run easily.

    I have a use case with GitGuardian Platform for AWS  secrets. For example, I integrated GitGuardian Platform in my project, which is developed in Node.js. Whenever I am developing and I accidentally commit any ENV file that contains any API keys, I remove the secrets, rotate the key, and update the .gitignore file to prevent it from happening again. It was a good reminder of how useful automated secret scanning is. I also evaluated GitGuardian Platform on my personal GitHub . It successfully detected an exposed API key in a test.env file and provided clear remediation steps. It is very good in that sense.

    GitGuardian Platform fits into my development workflow because it acts as an automated safety net for secrets. I mainly work with Node.js and GitHub , so having scans on every push helps catch accidentally committed API keys, which is great for me. Those API keys are very costly; it can be $100 to $200 per month for us because it uses tokens and everything. Those keys should not be made public because if they are, people can use them, and it will increase my costs. It complements our code review and CI/CD by adding an extra layer of security without disrupting development. After evaluating it, I can see how it fits into my GitHub-based development process. It automatically detects exposed secrets and reduces the risk of credential leaks, which is very great.

    What is most valuable?

    The best feature that GitGuardian Platform offers is its great UI, or user interface, which we can use to check keys, etc. It also detects secrets being exposed in real time. It has continuous repo monitoring; whenever we push something, it monitors it, and if there is an ENV file where secrets are moved, it can throw an error. It is very developer-friendly because it integrates. We are using GitHub right now, but I have also worked with Bitbucket  and GitLab , and it works very well with them too. The fourth feature is smart alerting, which is great because it alerts the user that their keys have been exposed, for instance, if you have put a key in the ENV file. The risk is reduced with these features.

    The day-to-day feature that I rely on most is the real-time secret detection. It automatically detects any exposed API key, password, tokens, SSH keys, cloud credentials, and other secrets in Git  repositories, even before they can become security incidents. Prevention is better than cure, and GitGuardian Platform provides that for us, which is great.

    What needs improvement?

    There are a few things that can be improved with GitGuardian Platform, but altogether it is a great platform. It could have a better UI. The user interface is very user-friendly and developer-friendly, but there are a few things here and there, which is true of almost every platform. It can be improved by allowing more customization for fine-tuning detection rules. Sometimes it also provides false positives, which are wrong, so that can be improved. An improved onboarding experience for new users would be great.

    I think the documentation is good. I have been using it, and it is great for that. The interface and integration are also very good, but there are a few enhancements needed related to onboarding. The documentation could be a little better. Tutorials could be provided, and guidance for new users would help them gain experience with it. Those things can be improved.

    What other advice do I have?

    It is great because three or four times we were able to identify security breaches. After that, we implemented GitGuardian Platform. We were using API tokens in AI services where we were fetching and calling the Grok  4.0 and Grok  4.5 cursors. We were using it because we wanted to parse resumes and do some other things there, but we were accidentally putting the keys in the ENV file. One person put it there, which increased the risk because those keys could be used by anyone.

    It definitely saved us on cost. Those API keys, which were running for Grok 4.0, take around 200,000 tokens for one API hit. That costs around 17 cents, or $0.17 USD. If that key is exposed, people can hit those APIs with that token, and it would cost us thousands of dollars per month. This would increase our costs, which is very bad. Our monthly bill was already around 10,000 USD, and if it was used by another person, it could go up to 100,000. The cost was reduced significantly.

    I have not used the AI features of GitGuardian Platform that much, but overall, it is well-designed. The platform emphasizes protecting sensitive data. It is also recommended for providing security against exposing secrets. Access control, audit logs, and integration with enterprise security workflows make it suitable for my organization. Continued transparency around AI decision-making and ongoing model improvement would better strengthen confidence, which is great.

    Accuracy-wise, GitGuardian Platform is very accurate. I have used GitGuardian Platform's AI capabilities as well. It is good because, for example, the contextual insights help us reduce false positives and make remediation more efficient. While no AI system is perfect, it is dependable enough for day-to-day use. With human review, it is very good. That is the main thing.

    If your application is big enough and your team size is large, there are chances you can expose secrets. You have a lot of cross-dependency secrets that you are putting in your secrets file. If you mistakenly put a secret in an ENV file and that code is public—for example, in GitHub, you can have private or public repositories, but if the code is public—then those keys can be used by any hacker or anyone. Those keys can be used randomly, which will increase the cost for your company. Those costs can be reduced if you use GitGuardian Platform. You purchase GitGuardian Platform through their website, and it will automatically detect if any API key is exposed. It will provide you with security as well as cost-effectiveness. I would rate this product an 8 overall.

    Food & Beverages

    Clear, Helpful Email Warnings That Explain the Issue

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    It gives me a warning if anything is wrong with my email, and it actually explains what the problem is.
    What do you dislike about the product?
    Sometimes it mistakenly identifies regular variables as env variables.
    What problems is the product solving and how is that benefiting you?
    The biggest problem GitGuardian helps solve for me is security, especially identifying potential vulnerabilities in my app.
    Jayshil P.

    Quick Alerts for Accidental Credential Pushes 🦉🦉🦉🦉

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    GitGuardian gives me a quick alert when I accidentally push my credentials to GitHub.
    What do you dislike about the product?
    I don’t particularly think there’s anything I don’t like about GitGuardian.
    What problems is the product solving and how is that benefiting you?
    Credential safety is a major challenge for me, and GitGuardian helps address this issue in my development work.
    Amrithesh S.

    Highly Accurate, Proactive Repository Monitoring That Prevents Hardcoded Credentials

    Reviewed on Jul 13, 2026
    Review provided by G2
    What do you like best about the product?
    It provides highly accurate, continuous repository monitoring and proactively helps prevent hardcoded credentials from making their way into production environments.
    What do you dislike about the product?
    Occasionally, it flags dummy credentials or mock variables in our test files, which can lead to a bit of alert fatigue and unnecessary noise during reviews.
    What problems is the product solving and how is that benefiting you?
    The problem it tackles is credential exposure in version control. It smartly groups multiple occurrences of the same leaked secret and actively validates whether the credentials are still active. This drastically speeds up the remediation process.
    Ashish P.

    Automatically Scans Repos and Clearly Flags Security Risks

    Reviewed on Jul 13, 2026
    Review provided by G2
    What do you like best about the product?
    It automatically scans our repositories for security risks and clearly tells us where the issues are.
    What do you dislike about the product?
    Sometimes it flags an issue when there isn’t actually one, and other times it passes even when the issue really exists. For example, if I use the keyword "Password" but I’m not using any credentials there, it still shows an issue. However, when I change the key/password that’s actually being used to something like "p_char", it passes it.
    What problems is the product solving and how is that benefiting you?
    If someone accidentally puts any credentials in the repo, it scans and lets us know very quickly.
    View all reviews