GitGuardian Platform logo

    GitGuardian Platform

    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.

    Ratings and reviews

    4.8
    299 ratings
    2 star
    1 star
    89%
    10%
    1%
    0%
    0%
    6 AWS reviews
    |
    293 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (299)
    Rohit P.

    Seamless Workflow Integration with Fast, Reliable Secret Detection

    Reviewed on Jul 31, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about GitGuardian is how seamlessly it fits into our development workflow while making secret detection simple and reliable. The interface is clean and easy to navigate, the integrations with our repositories were straightforward to set up, and scans run quickly without affecting our development process. The alerts provide enough context to understand the issue and fix it efficiently, which has helped us prevent accidental credential leaks before they become security incidents. The documentation and onboarding made it easy to get started, and overall the value it provides in reducing security risks and saving developer time makes it well worth the investment.
    What do you dislike about the product?
    One area that could be improved is reducing occasional false positives, as some alerts still require manual verification before taking action. I would also like to see more customization options for notification rules and reporting, especially for larger teams managing multiple repositories. While the platform is easy to use overall, some advanced settings can take a bit of time to discover, and more in-app guidance for those features would make the experience even better.
    What problems is the product solving and how is that benefiting you?
    GitGuardian helps solve the problem of accidentally exposing sensitive credentials like API keys, tokens, and passwords in source code. Instead of relying on manual code reviews to catch these issues, it automatically detects and alerts us early in the development process. This has reduced the risk of security incidents, saved time during reviews, and given our team greater confidence that we're protecting sensitive information before code is merged or deployed.
    Antonio Tirado Peña

    Automated secret detection has eliminated code leaks and enforces secure commits in pipelines

    Reviewed on Jul 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use GitGuardian Platform mainly to prevent and detect exposed credentials, API keys, database connection strings, cloud credentials, and SSH keys within our repository and within the CI/CD pipelines. It works as a safety net that automates everything to ensure the code is clean and can reach production properly and that there are no credential leaks.

    When we have made a commit with some secret hardcoded in the code, it has automatically notified us by email saying that the Git commit cannot be done because it has exposed secrets.

    We trust it and we see that it is really working. It detects if there is any code leakage, and it is very useful when you have public repositories.

    What is most valuable?

    The best features offered by GitGuardian Platform are historical scanning, since it incorporates all existing repositories and all legacy repositories. The ability to analyze histories is amazing. It brings to light exposed credentials in old commits, forgotten branches, and it is a pretty good, quite complete standard scanner. It has real-time detection and CI/CD integration. It intercepts secrets in the pipeline itself or through a pre-commit hook. This is useful because you do not even get to make the commit; instead, you detect the leak beforehand. It directly notifies the specific developer so they can fix the problem, which is great.

    Regarding CI/CD integration and real-time detection, it has impacted the number of incidents or security leaks we have in the company. In the company we have ISO 27000 and the National Security Scheme, and one of the KPIs we have specifically is security leaks or security breaches. Since we have GitGuardian Platform, secrets in code are better monitored.

    The reduction of security leaks since we implemented GitGuardian Platform has been drastic and we have brought the indicator down to zero percent of secrets revealed within the code.

    What needs improvement?

    GitGuardian Platform has the occasional false positive in testing. Sometimes it detects simulated or dummy keys that are put into unit tests. The management of custom patterns could be a bit more streamlined or a bit more automated, as it detects certain formats with internal tokens.

    For how long have I used the solution?

    I have been using this tool for two or three years.

    What do I think about the stability of the solution?

    GitGuardian Platform is super stable, a ten out of ten. It works without any latency, everything working in real time, without penalizing compilation time.

    What do I think about the scalability of the solution?

    It scales without problems across multiple repositories and developer accounts without loss of performance at peak working hours.

    How are customer service and support?

    I have not needed to use GitGuardian Platform support.

    Which solution did I use previously and why did I switch?

    We did not use any similar solution previously.

    How was the initial setup?

    For costs, we are on the free version for up to twenty-five developers, so we are totally covered. As for the implementation, it is super simple. You open GitHub, open the GitGuardian Platform connector, configure the repositories you want it to monitor, and it is running. The learning curve and monitoring are almost zero. We use GitGuardian Platform's SaaS. What we did was configure it with the GitHub connector, which took just a few clicks, and you just set it to work and notifications and responses start arriving about all your repositories that you share.

    What about the implementation team?

    We did not evaluate other options initially. We discovered GitGuardian Platform and since the implementation was very fast, the license we use for the number of developers we have in the company is the free one, and everything worked the first time and everything is working perfectly, we have not evaluated other options.

    What was our ROI?

    I have seen a return on investment by the reduction of security incidents. We have reduced security incidents related to secret leaks.

    What's my experience with pricing, setup cost, and licensing?

    For costs, we are on the free version for up to twenty-five developers, so we are totally covered.

    Which other solutions did I evaluate?

    We did not evaluate other options initially. We discovered GitGuardian Platform and since the implementation was very fast, the license we use for the number of developers we have in the company is the free one, and everything worked the first time and everything is working perfectly, we have not evaluated other options.

    What other advice do I have?

    GitGuardian Platform is a ten. I give GitGuardian Platform a ten because it is super stable, it has no service interruptions, the webhooks and real-time analysis respond with total consistency, without penalizing pull request compilation times. It is very scalable; it has grown as our team has grown. It protects us and we are quite happy with it.

    They should try it without any doubt. It is a marvel that fulfills everything it promises. If you are applying shift-left security policies within your company and you want to put a hard stop to credential leaks within your microservices architecture or your cloud infrastructure, GitGuardian Platform is one of the most effective tools I have found on the market. It covers the gap between DevSecOps and development very well. As long as you dedicate some initial time to adjusting exceptions in test environments, it works wonderfully.

    I give GitGuardian Platform an overall rating of ten out of ten.

    Aquib J.

    Great at Catching Accidental Secrets in MRs

    Reviewed on Jul 30, 2026
    Review provided by G2
    What do you like best about the product?
    It’s good at finding secrets that have accidentally been included in MRs.
    What do you dislike about the product?
    It’s not very good at finding SAST static issues in the MR.
    What problems is the product solving and how is that benefiting you?
    We integrated GitGuardian with our GitLab and local systems, and it has helped a lot with identifying and resolving sensitive data that was being pushed to the repository.
    Aswin K.

    Seamless GitHub Secret Scanning with High Signal-to-Noise Alerts

    Reviewed on Jul 25, 2026
    Review provided by G2
    What do you like best about the product?
    As a small startup where developers move fast and security isn't always the first thing on everyone's mind, GitGuardian fills a gap that genuinely needed filling. The moment you connect it to your repositories, it starts doing something valuable, quietly watching every commit for exposed API keys, tokens, credentials, and secrets that should never have made it into code in the first place.

    The automatic scanning of commits and real-time alerts for potential threats are the standout features, and the integration with GitHub is seamless, slotting into our existing workflow without requiring developers to change how they work. That last part matters more than it sounds. Security tools that demand behavioral change from developers tend to get worked around, GitGuardian just sits in the background and does its job.
    Software Finder

    The true positive rate is impressively high, and the smart alert grouping helps reduce fatigue by consolidating related incidents rather than flooding your inbox with noise. For a lean startup team that can't have someone dedicated to triage all day, that signal-to-noise ratio is genuinely important.

    Real-time incident detection and reporting also increase confidence that potential leaks are caught quickly, minimizing the window between a secret being exposed and someone acting on it.
    What do you dislike about the product?
    The mixed experience mostly comes down to three things, false positives, UI friction, and pricing opacity.

    False positives are the most consistent frustration, some alerts are overly sensitive, flagging things that aren't actual secrets, which clutters the dashboard and creates extra manual review work. For a small team already stretched thin, spending time validating whether an alert is real or a false flag is friction you didn't budget for.

    The UI could be more intuitive, especially in high-stress moments when you've just received an alert and need to quickly understand what leaked and exactly where to fix it. That's precisely the moment you need clarity, and the interface doesn't always deliver it fast enough.

    Pricing is another sticking point, it's not always clear upfront what features sit at which price tier, which makes planning and budgeting harder than it needs to be. For a startup watching every dollar, vague pricing tables create unnecessary friction before you've even committed.
    TrustRadius

    The purchasing process itself can also be convoluted, getting a quote and finalising payments has been known to take longer than expected, which feels out of step with a product aimed at developer teams who expect things to just work.
    What problems is the product solving and how is that benefiting you?
    The core problem it solves is one every startup faces but rarely talks about openly, developers accidentally committing secrets into repositories. It happens faster than anyone expects, especially under deadline pressure, and the consequences of an exposed API key or database credential sitting in a public or even private repo can be severe.

    GitGuardian mitigates sensitive data exposure by detecting credentials early, reducing security-related bugs, and bridging the gap between development speed and security discipline, without requiring heavy manual intervention from a security team.

    For a small startup without a dedicated security engineer, that kind of automated safety net is genuinely valuable. It catches mistakes before they become incidents and nudges developers toward better habits without being heavy-handed about it.

    Bottom line: GitGuardian is worth having in your security stack, especially at startup scale where developer speed and security rigour are constantly in tension. Just go in prepared for some alert tuning, a UI that rewards patience, and a pricing conversation that takes longer than it should.
    Banking

    GitGuardian Helps Catch Secrets and PII Before They Reach Remote Repos

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    GitGuardian is very helpful for finding secrets and PII that might otherwise get pushed to remote repositories. I think yes
    What do you dislike about the product?
    It does not currently provide the option to run SAST scans, so having static code analysis available here would be a nice addition.
    What problems is the product solving and how is that benefiting you?
    Gitguardian offers both a local setup and CI integration, so developers can feel confident that no PII code gets pushed, while the CI pipeline continues to run as expected.
    Eleonora B.

    User-Friendly, Responsive, and Reliable—Highly Recommended

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    Idee friendly website responsive and reliable
    Very natural interview
    What do you dislike about the product?
    nothing everything works very well, highly recommended
    What problems is the product solving and how is that benefiting you?
    Job interview
    Udit Parekh

    Continuous secret detection has strengthened DevSecOps and improves real-time incident response

    Reviewed on Jul 24, 2026
    Review from a verified AWS customer

    What is our primary use case?

    GitGuardian Platform is used to detect exposed secrets such as API keys, AWS credentials, database passwords, SSH keys, and tokens across the Git repository before they become a security incident.

    What is most valuable?

    GitGuardian Platform offers secret detection across repositories, real-time alerts, broad account support for cloud credentials and API keys, easy integration with GitHub, and incident tracking.

    Real-time alerts and incident tracking features help significantly by enabling immediate alerts after credentials are committed rather than discovering leaked credentials during periodic audits. In real time, monitoring and remediating exposed credentials is very helpful.

    GitGuardian Platform positively impacts the organization by strengthening the DevSecOps process, reducing the risk of credential exposure, and increasing developer awareness around secure coding practices.

    Specific outcomes from using GitGuardian Platform include faster detection of exposed credentials, reduced manual repository reviews, improved developer awareness of secret management, and better compliance with internal security policies.

    Regarding GitGuardian Platform's AI capabilities, security is clearly the platform's main focus as it provides strong visibility into secret exposure and helps organizations establish better governance around credential management.

    GitGuardian Platform's AI detection engine is accurate, and relatively few false positives are experienced. The alerts are actionable and easy to investigate, and the accuracy and reliability are strong.

    What needs improvement?

    GitGuardian Platform can be improved with better integration with enterprise ticketing platforms, enhancing the dashboard for executive reporting, and providing more automation for remediation.

    Needed improvements for GitGuardian Platform should focus on enhancing the detection capabilities, reporting, workflow automation, and enterprise integration.

    What other advice do I have?

    GitGuardian Platform should be integrated early into the development lifecycle and secret detection should be made part of the pull request and CI/CD process. It works best as a preventive control rather than something that is only used during periodic security audits, making it valuable for teams currently dealing with security audits and frequently exposed secrets. I would rate this solution 9 out of 10.

    Dev Mittal

    Automated secret scanning has protected our code and prevents accidental credential exposure

    Reviewed on Jul 22, 2026
    Review from a verified AWS customer

    What is our primary use case?

    GitGuardian Platform serves as a security shield for our organization to prevent API keys and database credentials from being pushed to GitHub. Although we know we should not push credentials, anyone can make mistakes. GitGuardian Platform has a CLI tool called gg shield, which we have set up on our laptops. Since we already use Git version control with GitHub, the process is straightforward. Whenever we push code to GitHub, it scans the code and checks for API keys and database credentials. Even if credentials are commented out, GitGuardian Platform flags them because commented credentials remain readable on GitHub and can still be caught by bad actors.

    The most problematic situation occurs when a developer pushes credentials to GitHub and then attempts to remove them by pushing again. The issue is that Git does not work that way. The credential still remains in our GitHub repository history. GitGuardian Platform rescans our GitHub repositories for API keys to address this situation.

    I also use GitGuardian Platform in my CI/CD pipelines with GitHub Actions. Although we store credentials in GitHub secrets, sometimes people hardcode credentials by mistake. Once the CI/CD pipeline is working properly, we do not edit it much, so if someone hardcoded credentials and everything is functioning well, no one may even review it. That credential could remain exposed for months. Even though our GitHub repositories are private, we still use GitGuardian Platform as a security measure. As a backend engineer, DevOps engineer, and AWS cloud engineer at my small company, I understand what situations could occur and these are real scenarios we face. We must use this solution even though we all know we should not do these things. However, no one knows what can happen in the future.

    What is most valuable?

    The public leakage detection feature of GitGuardian Platform influences my data security positively. This addresses a problem that could happen to anyone. Since we have this feature, we have peace of mind that our credentials will not be leaked or pushed somewhere by an employee.

    Sometimes, I have faced a specific problem. I work in the cloud and have cloud credentials. Our developers asked me to give them credentials for debugging on their local devices. If they push credentials somewhere and cannot communicate with me since I am the admin, that time gap becomes dangerous. GitGuardian Platform provides a good security measure for any company using it, though you cannot give it a specific percentage impact on the company.

    What needs improvement?

    GitGuardian Platform might work on their false positives. Sometimes it flags credentials that are not actually credentials, but this does not happen frequently since we always remove our credentials before pushing anywhere. We do not really encounter these flags.

    For how long have I used the solution?

    I have been using GitGuardian Platform for around one year. I have been working at my company for one and a half years, and we started using GitGuardian Platform after approximately ten months of my tenure.

    What do I think about the stability of the solution?

    GitGuardian Platform has good stability.

    What do I think about the scalability of the solution?

    GitGuardian Platform has pretty good scalability. Based on our usage, it is working well. Even our code repository works well with it, and I could say it is pretty scalable for us.

    How are customer service and support?

    I have not ever contacted the technical support or customer support for GitGuardian Platform. We do not need to contact them since the platform is simple to install. It is just there for precaution. We do not need it every day since it is simply for the rare chance that someone will accidentally push credentials and then it flags them.

    Which solution did I use previously and why did I switch?

    I have not ever used any similar solutions to GitGuardian Platform that I can compare it with. We simply use it and it is working well for us, so we did not switch from another solution.

    How was the initial setup?

    The initial deployment of GitGuardian Platform is pretty easy. GitGuardian Platform has a YouTube channel with three to four-minute introduction videos that show step-by-step how to install it. They also have documentation, so the setup is simple and easy.

    What's my experience with pricing, setup cost, and licensing?

    We are on the free tier of GitGuardian Platform. They offer a free tier, so we are using it for now.

    What other advice do I have?

    The effectiveness of GitGuardian Platform's automated severity scoring in incident management is good. When an incident happens, the incident manager receives an automated severity score based on the credential type. In my case, we mostly have development environment credentials, so the severity is not much, perhaps around six or seven.

    I did not use the automated playbooks of GitGuardian Platform.

    GitGuardian Platform does not require any maintenance on our end.

    I rate this review an 8 out of 10.

    PeterHenggeler

    Automated alerts have prevented secret leaks and save us time cleaning repository history

    Reviewed on Jul 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for GitGuardian Platform is secret detection.

    Every time we open a pull request, it scans the pull request and ensures that we did not accidentally put a database password in a pull request. That process has worked very well for my team as it has caught several things, it is very helpful, and it is easy to use.

    What is most valuable?

    The best features GitGuardian Platform offers include notification directly to the engineer who created the pull request.

    The direct notification feature has helped my engineers and my workflow overall by being effective. It is nice to know that no matter what happens, day or night, if someone puts up a change, they will get an alert, and the security team will get an alert.

    GitGuardian Platform has positively impacted our organization as it helps us reduce the number of secrets that we would accidentally commit into source code. We have definitely saved time, as we do not have to go clean out Git history because we can just rotate the secret quickly.

    What needs improvement?

    I do not have real feedback on how GitGuardian Platform can be improved as I think the team does a good job.

    For how long have I used the solution?

    I have been using GitGuardian Platform for four years.

    What other advice do I have?

    My advice to others looking into using GitGuardian Platform is that it is a very quick win to set up and very easy to configure. I would rate this review a 10.

    Food & Beverages

    Clear, Helpful Email Warnings That Explain the Issue

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    It gives me a warning if anything is wrong with my email, and it actually explains what the problem is.
    What do you dislike about the product?
    Sometimes it mistakenly identifies regular variables as env variables.
    What problems is the product solving and how is that benefiting you?
    The biggest problem GitGuardian helps solve for me is security, especially identifying potential vulnerabilities in my app.