Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.
    4.8

    Overview

    Play video

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    Business Plan, per 25 contributing developers (annual contract)
    $5,500.00

    AI Insights

     Info

    Dimensions summary

    This listing offers one pricing dimension: the Business Plan, sold as an annual contract. You buy in blocks of 25 contributing developers. Pricing scales with your developer count, so you add units as your team grows. A developer counts as any active contributor who has made at least one commit in the last 90 days to a project you secure. To cover more than the base block, you add additional 25-developer units. Large organizations needing several hundred licenses can request a private offer instead.

    Top-of-mind questions for buyers

    A developer is any active contributor to a project you secure who made at least one commit in the last 90 days. Contributors to your open-source projects count only if they are actual employees. Repositories hosted under your organization stay free for scanning purposes.
    You add units in blocks of 25 contributing developers. Cost scales with the number of units you buy under the annual contract. If your active contributor count crosses a block boundary, you purchase another 25-developer unit to cover the additional developers.
    Developer count reflects active contributors who made at least one commit in the last 90 days to a project you secure. Because this can shift as teams change, you can contact the vendor to get a count based on your repository activity before sizing your units.
    www.gitguardian.com
    Helpful?

    Vendor refund policy

    Please contact sales@gitguardian.com  to learn more about GitGuardian's refund policy.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform https://docs.gitguardian.com  or submit a support request at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    100
    In Application Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    18 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secrets Detection and Classification
    Supports detection of over 450 types of secrets including API keys, private keys, and database credentials across source code and productivity tools
    Multi-Platform Integration
    Integrates with major Version Control Systems (GitHub, GitLab, BitBucket, Azure DevOps), CI/CD tools (Jenkins, Travis CI), and productivity platforms (Slack, Jira, container registries)
    Public Repository Monitoring
    Scans public GitHub repositories to detect sensitive information in both organizational and personal developer accounts
    Policy Enforcement Engine
    Provides robust policy engine enabling security teams to enforce rules and detect policy violations across integrated platforms
    Honeytokens Deployment
    Deploys honeytokens as a defense mechanism to detect unauthorized access and misuse of secrets
    Centralized Secrets Management
    Centrally secures, rotates, and manages secrets across multi-cloud and hybrid environments with a unified view across multiple AWS accounts and AWS Secrets Manager instances.
    Multi-Platform Integration
    Offers REST APIs and integrates with a wide range of DevOps tools, container platforms, vulnerability scanners, RPA, and automation tools for credential delivery.
    Secrets Rotation and Lifecycle Management
    Automatically rotates secrets in AWS Secrets Manager and across cloud environments without requiring changes to developer workflows or applications.
    Audit and Access Control
    Provides centralized control and comprehensive auditing of how applications, DevOps tools, and automation platforms use secrets and privileged credentials to access sensitive resources.
    Enterprise-Scale Architecture
    Designed to support massive scalability with data sovereignty requirements for large global enterprises across multi-cloud and hybrid infrastructure.
    Secrets Management and Orchestration
    Centralized platform for syncing, managing, orchestrating, and rotating secrets automatically across projects, teams, and environments
    Credential Rotation
    Automated credential rotation capabilities without downtime to actively safeguard secrets from data breaches
    Multi-Environment Integration
    Automatic synchronization and deployment of secrets across all environments and infrastructure through expanding suite of integrations
    Developer Tools and IDE Integration
    VS Code extension for editing secrets alongside code with bidirectional sync, and Doppler CLI for consuming secrets as environment variables
    Access Control and Compliance
    Scalable and flexible access controls with detailed activity logs for real-time access management, compliance tracking, and configurable alerts through Slack, Teams, Splunk, or Discord

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    316 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    89%
    10%
    1%
    0%
    0%
    6 AWS reviews
    |
    310 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2886744

    Continuous secret monitoring has improved our incident response and protected exposed credentials

    Reviewed on Oct 02, 2026
    Review provided by PeerSpot

    What is our primary use case?

    One specific example of how my team has used GitGuardian Platform to catch an issue was when it detected an API key that had accidentally been committed to a repository; we were able to quickly identify the exposed credential, revoke and replace it, and then clean up the repository so that the secret wasn't left exposed.

    Day-to-day, we mainly use GitGuardian Platform as an additional security layer around our development workflow, helping us continuously monitor repositories, investigate alerts, and work with developers to remediate exposed secrets before they become larger security issues.

    How has it helped my organization?

    GitGuardian Platform has positively impacted our organization by improving our visibility into credential exposure and reducing the time it takes to identify and respond to leaked secrets; it also gives developers earlier feedback so security issues can be addressed closer to the source instead of becoming larger incidents later.

    We haven't tracked a formal percentage for response time improvement since using GitGuardian Platform, so I wouldn't want to give an artificial number; practically, alerts have helped us move from discovering exposed secrets during reviews to identifying them much closer to when they are committed, often within the same working day.

    What is most valuable?

    The best features GitGuardian Platform offers are secret detection and real-time monitoring, which are probably the most useful for us; I also appreciate the alerting and incident investigation capabilities because they make it easier to trace when a secret was exposed and coordinate remediation with the development team.

    The real-time monitoring and alerting features of GitGuardian Platform have significantly helped my team respond to incidents; for example, the alerting has helped us catch exposed credentials shortly after they were committed rather than finding them during a later security review, and in one case, the team was notified the same day, allowing us to revoke the key, replace it, and clean up the repository before it caused any downstream impact.

    Another useful aspect of GitGuardian Platform is the visibility it provides to security and development teams into secret exposure across repositories; the remediation workflow and historical context around alerts are also helpful when investigating whether a credential is still active or when determining immediate action.

    What needs improvement?

    One area for improvement in GitGuardian Platform would be reducing false positives and making alert prioritization even more precise for larger environments; more customization around notifications and remediation workflows would also help teams avoid alert fatigue as the number of repositories grows.

    Regarding improvements needed for GitGuardian Platform, I would appreciate more flexibility in integrations, especially with different DevOps, ticketing, and security tools used across enterprise environments; while the UI is generally easy to use, better customization of dashboards and alert views would make it easier to manage a large number of repositories.

    I chose eight out of ten for GitGuardian Platform mainly because there is still room for improvement in enterprise integrations and customization; for larger environments, better alert prioritization, dashboard flexibility, and integration with more DevOps and security tools would strengthen the overall experience.

    The main areas we discussed primarily cover everything, but beyond those, I would appreciate more granular role-based controls and easier customization of alert workflows, especially for larger teams where different groups may need different levels of visibility and access.

    For how long have I used the solution?

    I have been using GitGuardian Platform for a little over a year, primarily to monitor our code repositories for exposed secrets and credentials, and to help the development teams identify and remediate potential leaks early.

    What do I think about the stability of the solution?

    In my experience, GitGuardian Platform has been stable during the time we have used it; we haven't encountered major availability or reliability issues, and the monitoring and alerting generally work consistently as part of our development workflow.

    What do I think about the scalability of the solution?

    So far, GitGuardian Platform has scaled well as we have added more repositories and development teams; the cloud-based model makes it relatively easy to expand coverage without managing additional infrastructure, although larger environments require good alert management and configuration.

    How are customer service and support?

    The customer support experience with GitGuardian Platform has been generally good for the issues and configuration questions we have raised; responses have been reasonably clear and helpful, though response times can vary depending on the complexity of the issue.

    I would rate customer support for GitGuardian Platform eight out of ten, as the team has generally been responsive and helpful, especially for configuration and troubleshooting questions; however, there is some room for faster responses on more complex issues.

    Which solution did I use previously and why did I switch?

    We previously relied more on built-in repository scanning and manual checks rather than a dedicated secret management monitoring platform, and we moved to GitGuardian Platform because we wanted centralized visibility, more consistent detection across repositories, and faster alerting and remediation workflows.

    What was our ROI?

    We haven't calculated a formal dollar ROI or headcount reduction with GitGuardian Platform, so I would not want to put an artificial number on it; the main day-to-day benefit is that secret detection and initial investigation are automated, saving developers and security teams time and allowing them to focus on remediation instead of manually checking repositories.

    What's my experience with pricing, setup cost, and licensing?

    From my experience, the pricing of GitGuardian Platform felt reasonable for the security coverage and visibility we get; although the overall cost depends on the number of repositories and users covered, setup was relatively straightforward, and licensing didn't require a lot of operational overhead once the initial configuration was completed.

    Which other solutions did I evaluate?

    Before choosing GitGuardian Platform, we looked at a few alternatives, mainly GitHub Advanced Security and GitLab's built-in security capabilities; we compared them based on secret detection coverage, alerting, integrations, and how easily the solution could fit into our existing development workflow.

    What other advice do I have?

    I would rate GitGuardian Platform eight out of ten; it has been reliable for secret detection and monitoring, with good visibility and useful alerting, although there is still room for improvement around integrations, customization, and alert management.

    Regarding the AI capabilities of GitGuardian Platform, I find them useful when they provide more context around detected secrets and reduce manual investigation; from a governance and security perspective, I still want clear controls around data access, privacy, auditability, and how AI-assisted analysis is used within our organization.

    I found the AI-assisted analysis of GitGuardian Platform generally useful for adding context to security alerts and helping with investigations; however, I still treat the output as a supporting signal rather than the final decision, especially for higher-risk findings where we validate the details before taking action.

    We deploy GitGuardian Platform as a public cloud SaaS solution that integrates with our development and source control workflows, meaning there is no separate on-premise infrastructure required for the platform itself.

    We use GitGuardian Platform as a SaaS platform and do not directly manage or choose the underlying cloud provider for the deployment; from our side, we primarily interact with the GitGuardian hosted service and integrate it with our development tools.

    My advice for others looking into using GitGuardian Platform is to first identify which repositories, teams, and secret types you need to monitor, then set up the integrations and alert workflow around that; also, spending some time tuning notification and remediation processes early on makes the platform much more useful as your environment grows. I rate this product eight out of ten overall.

    Vinayak K.

    Keeps Our API Keys Safe with Fast Leak Detection

    Reviewed on Sep 29, 2026
    Review provided by G2
    What do you like best about the product?
    I like this feature because it lets me know if my API key gets leaked, which helps keep my secret keys secure. It can detect API keys and tokens in commits, so I can remove them quickly.
    What do you dislike about the product?
    I get emails a bit late. Also we can make UI a bit more accessible and easier to navigate.
    What problems is the product solving and how is that benefiting you?
    It keeps a live track of my API keys, if I mistakenly hard code them, and so that saves me from API key or secret credential leak.
    DAKSH M.

    Instant Alerts When an API Key Leaks

    Reviewed on Sep 29, 2026
    Review provided by G2
    What do you like best about the product?
    It sends me notifications if an API key leaks, especially when it happens because of my own mistake.
    What do you dislike about the product?
    It sends notifications a little late, and I also wish I had known about it a bit earlier.
    What problems is the product solving and how is that benefiting you?
    Keeps me on live track if anything happens or my api or any personal key gets accidentally pushed
    Lekhraj S.

    Quick Secret Detection That Makes Security Monitoring Simple

    Reviewed on Sep 28, 2026
    Review provided by G2
    What do you like best about the product?
    I like GitGuardian’s ability to quickly detect exposed secrets and credentials in code. It makes security monitoring simple and helps prevent accidental data leaks.
    What do you dislike about the product?
    The interface can feel a little overwhelming at first, especially with frequent alerts. Better customization and simpler navigation would improve the experience.
    What problems is the product solving and how is that benefiting you?
    GitGuardian helps detect exposed secrets and credentials in code, reducing the risk of security incidents. It saves time by automatically identifying issues before they become bigger problems.
    Information Technology and Services

    Quickly Flags Potential Compromised Keys to Protect Production Apps from being compromised

    Reviewed on Sep 28, 2026
    Review provided by G2
    What do you like best about the product?
    Quick flag of a potential compromise keys that could endanger app in production by bad actors
    What do you dislike about the product?
    Well, the only reservation is that it sometimes treat some false positive error as critical
    What problems is the product solving and how is that benefiting you?
    Mainly a potential security problem, that could cause the company a whole lot, and in fact the benefit is that we often take quick steps towards its report that could cost us.
    View all reviews