Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.
    4.8

    Overview

    Play video

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    Business Plan, per 25 contributing developers (annual contract)
    $5,500.00

    AI Insights

     Info

    Dimensions summary

    This listing offers one pricing dimension: the Business Plan, sold as an annual contract. You buy in blocks of 25 contributing developers. Pricing scales with your developer count, so you add units as your team grows. A developer counts as any active contributor who has made at least one commit in the last 90 days to a project you secure. To cover more than the base block, you add additional 25-developer units. Large organizations needing several hundred licenses can request a private offer instead.

    Top-of-mind questions for buyers

    A developer is any active contributor to a project you secure who made at least one commit in the last 90 days. Contributors to your open-source projects count only if they are actual employees. Repositories hosted under your organization stay free for scanning purposes.
    You add units in blocks of 25 contributing developers. Cost scales with the number of units you buy under the annual contract. If your active contributor count crosses a block boundary, you purchase another 25-developer unit to cover the additional developers.
    Developer count reflects active contributors who made at least one commit in the last 90 days to a project you secure. Because this can shift as teams change, you can contact the vendor to get a count based on your repository activity before sizing your units.
    www.gitguardian.com
    Helpful?

    Vendor refund policy

    Please contact sales@gitguardian.com  to learn more about GitGuardian's refund policy.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform https://docs.gitguardian.com  or submit a support request at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    100
    In Application Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    1 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secrets Detection and Classification
    Supports detection of over 450 types of secrets including API keys, private keys, and database credentials across source code and productivity tools
    Multi-Platform Integration
    Integrates with major Version Control Systems (GitHub, GitLab, BitBucket, Azure DevOps), CI/CD tools (Jenkins, Travis CI), and productivity platforms (Slack, Jira, container registries)
    Public Repository Monitoring
    Scans public GitHub repositories to detect sensitive information in both organizational and personal developer accounts
    Policy Enforcement Engine
    Provides robust policy engine enabling security teams to enforce rules and detect policy violations across integrated platforms
    Honeytokens Deployment
    Deploys honeytokens as a defense mechanism to detect unauthorized access and misuse of secrets
    Centralized Secrets Management
    Centrally secures, rotates, and manages secrets across multi-cloud and hybrid environments with a unified view across multiple AWS accounts and AWS Secrets Manager instances.
    Multi-Platform Integration
    Offers REST APIs and integrates with a wide range of DevOps tools, container platforms, vulnerability scanners, RPA, and automation tools for credential delivery.
    Secrets Rotation and Lifecycle Management
    Automatically rotates secrets in AWS Secrets Manager and across cloud environments without requiring changes to developer workflows or applications.
    Audit and Access Control
    Provides centralized control and comprehensive auditing of how applications, DevOps tools, and automation platforms use secrets and privileged credentials to access sensitive resources.
    Enterprise-Scale Architecture
    Designed to support massive scalability with data sovereignty requirements for large global enterprises across multi-cloud and hybrid infrastructure.
    Secrets Management and Orchestration
    Centralized platform for syncing, managing, orchestrating, and rotating secrets automatically across projects, teams, and environments
    Credential Rotation
    Automated credential rotation capabilities without downtime to actively safeguard secrets from data breaches
    Multi-Environment Integration
    Automatic synchronization and deployment of secrets across all environments and infrastructure through expanding suite of integrations
    Developer Tools and IDE Integration
    VS Code extension for editing secrets alongside code with bidirectional sync, and Doppler CLI for consuming secrets as environment variables
    Access Control and Compliance
    Scalable and flexible access controls with detailed activity logs for real-time access management, compliance tracking, and configurable alerts through Slack, Teams, Splunk, or Discord

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    323 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    89%
    10%
    1%
    0%
    0%
    6 AWS reviews
    |
    317 external reviews
    External reviews are from G2  and PeerSpot .
    Brad Dyke

    Governance over CI/CD security has improved and analytics integration still needs work

    Reviewed on Oct 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are leveraging GitGuardian Platform first to augment governance over security control mechanisms in relationship from the developer through the CI/CD process out to resources such as vaults and so on, so that we can get active control over how security is, what is security, and how we can improve it.

    For instance, we envision using GitGuardian Platform with developers using IDEs or APIs, AI tools, operating through the automated pipelines of CI/CD, up to a vault out there in the cloud environment that contains the security rules that we have in play. We want to watch that process, whether it be a container, an artifact, or a pipeline, and see how, first, what is it? And then secondly, how can we improve it? So that we can use security key template models versus access account models.

    We are also wanting to gravitate from the strategy of using traditional style security templates that require account access, ID/user password models, and use GitGuardian Platform to develop a strategy to use API keys and signature encryption keys instead. To do that, we need a tool that gives clear transparency for that requirement.

    How has it helped my organization?

    GitGuardian Platform has positively impacted our organization during the evaluation phase as this is a new realm. These are new tools, and they do not really have a standard. So the key thing by working with this is to get a better sense overall of the guardianship and governance, setting the standard for what that inevitable gold standard needs to be when working with these kinds of tools.

    A gold standard for my organization using GitGuardian Platform would look like using the guardian process to establish the regular nature of a code update process from the developer who initiates the code change through the guidelines that they have to follow, which will not allow them to do anything else except for the steps that are required to be tested with quality assurance and walk through a regimented series of processes that have human intervention involved in that process to make sure that they clear the proper security requirements.

    I think GitGuardian Platform could add value and help regulate unnecessary man hours in a phased approach. Using the governance platform to help cover what we would have normally done with man hours would be a value add. The more important thing is it shows transparency of compliance, which is a very important detail.

    What is most valuable?

    GitGuardian Platform has good integration with Git. It works well with pull requests and Git actions. It does not have too much difficulty with Docker images, different CI/CD environments, Ansible, Puppet, and so on. The current integration to Confluence, Jira, and Slack for working with different environments is valuable for bringing the common form of tools into this particular style tool and having ease of work with those environments.

    All integrations including Git, Jira, Slack, and CI/CD environments add value for our team, but they have to happen in a specific process because the actions generate analytics. Those analytics drive up through Jira and Confluence and so on to generate analytic reporting. It is all important, and there is not just one tool.

    GitGuardian Platform meets the CDE security requirements guidelines specified for secops and infosec. I would describe the overall user experience and interface design of GitGuardian Platform as usable and functional.

    What needs improvement?

    I think it would be advantageous to see GitGuardian Platform's CI/CD protection get better developed because of the new adaptations that are coming with CI/CD. More flexibility regarding installations versus code updates versus bug fixes versus incidents in which we will generate RCA reports, and that they also concur with this same tool, would be beneficial. All of that needs to be clearly and transparently shown in this tool.

    GitGuardian Platform can be improved with better analytics and better analytics integration, specifically with Confluence for generating leadership levels of reports so that leadership can translate all of this information into something that is viable for the profit loss margins that they have to address each month.

    I chose seven out of ten because better and more seamless dashboard analytics design and better analytics integration would help it get to a higher score for me.

    Regarding GitGuardian Platform's AI capabilities, its accuracy and reliability of output is getting there, but along with all the new introductions of AI services versus chat forms, there is still a lot to be desired about the functionality and the integration. It is something that is ongoing because this year is the year that these features and functions are coming in. I expect it to improve over time, and that will improve the reliability and output as well.

    The biggest challenge my team has faced so far with GitGuardian Platform is integration, specifically integrating it to everything.

    For how long have I used the solution?

    GitGuardian Platform is currently in the evaluation phase.

    What do I think about the stability of the solution?

    GitGuardian Platform is stable.

    What do I think about the scalability of the solution?

    We have not gotten to the point where we can initiate scalability with GitGuardian Platform. Right now, we are establishing the framework of the services and their roles and then look to scale it across multiple clouds.

    How are customer service and support?

    GitGuardian Platform's documentation has been helpful during my evaluation.

    GitGuardian Platform's customer support has been good so far.

    I rate GitGuardian Platform's customer support an eight on a scale of one to ten.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution. We used open source and manual processes. Now we are looking for a consolidation platform to do the same work.

    How was the initial setup?

    GitGuardian Platform is deployed in a mixture, usually between a hybrid cloud and on-premise. For my hybrid cloud deployment, we use an on-premise localized cloud deployment.

    Integrating GitGuardian Platform with my existing tools and workflows during my evaluation has been fifty-fifty, because some of their APIs are custom made.

    The reason the learning curve for GitGuardian Platform is so high is because I am introducing a whole new platform to what we already know, and that process is nothing we are familiar with. So there is a learning curve.

    What was our ROI?

    I would expect GitGuardian Platform to not require hiring additional resources, but to more effectively use the resources we have on hand now regarding return on investment.

    What's my experience with pricing, setup cost, and licensing?

    Regarding my experience with pricing, setup cost, and licensing, we have not identified what the licensing model will look like depending on how much of the compliance components we will use versus cost. We are still working that out with the reps.

    Which other solutions did I evaluate?

    The main factors that influenced my decision to evaluate GitGuardian Platform over other solutions include the need for a centralized single pane of glass of governance and compliance, which has been very fractured over the past three years. But now companies are starting to understand what these look like.

    Before choosing GitGuardian Platform, I am in evaluation of three different vendors. I cannot disclose those at this time due to NDA agreements, but GitGuardian Platform is and was actively being compared to two other vendors at this time.

    What other advice do I have?

    The most critical advice I would give to others looking into using GitGuardian Platform is to understand that it is brand new technology and a brand new standard, with nothing truly written in stone. The learning curve will be significant as an adaptation is put in place. The key thing is to fully know all of your key tools that you use in your CI/CD processes, as well as planning for future tools, so that you can properly map the right compliance tool that supports those tools you have picked and become part of your platform.

    I am not in it that much yet to get a full scope of its yearly add-ons or features and improvements regarding how satisfied I am with the pace of innovation and new features being released by GitGuardian Platform. But for now, they are adequate.

    I rate GitGuardian Platform a seven out of ten.

    YASH L.

    Timely Error Notifications and Updates

    Reviewed on Oct 07, 2026
    Review provided by G2
    What do you like best about the product?
    It gives me timely notifications and updates about my errors.
    What do you dislike about the product?
    Lately, it sometimes sends me notifications, and because of that my work ends up getting left pending.
    What problems is the product solving and how is that benefiting you?
    If my API key gets leaked, it sends me a notification.
    Vinayak K.

    Automatically Detects Exposed Secrets Without Complicating Security

    Reviewed on Oct 05, 2026
    Review provided by G2
    What do you like best about the product?
    It solves a very real problem without making security feel too complicated. Like automatically detect exposed API keys, passwords, and other secrets in code, alert you quickly, and integrate into the Git workflow.
    What do you dislike about the product?
    UI can sometimes feel a bit confusing. Also that pricing gets expensive as usage and team size grow
    What problems is the product solving and how is that benefiting you?
    Detecting exposed API keys, passwords, and other secrets in code, alert you quickly, and integrate into the Git workflow.
    Nayana M.

    Peace of Mind for Incident Response and Leaked API Key Alerts

    Reviewed on Oct 05, 2026
    Review provided by G2
    What do you like best about the product?
    It gives us time for updates, or to respond if any API keys are leaked, or whenever an incident happens.
    What do you dislike about the product?
    At first, the number of false positives can be quite high, which means you may need to spend a lot of time fine-tuning the alerts.
    What problems is the product solving and how is that benefiting you?
    GitGuardian helps address the risk of accidentally hardcoding secrets, API keys, and credentials that can leak into source code repositories.
    NISARGA P.

    Natures review on githuardian

    Reviewed on Oct 05, 2026
    Review provided by G2
    What do you like best about the product?
    It gives me live notifications about which API keys are getting leaked.
    What do you dislike about the product?
    Nothing to complain about—everything is good overall. The only issue I’ve noticed is that sometimes it sends notifications late.
    What problems is the product solving and how is that benefiting you?
    monitoring api keys
    View all reviews