Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    Vendor Insights
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.
    4.8

    Overview

    Play video

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (1)

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    Business Plan, per 25 contributing developers (annual contract)
    $5,500.00

    AI Insights

     Info

    Dimensions summary

    This listing offers one pricing dimension: the Business Plan, sold as an annual contract. You buy in blocks of 25 contributing developers. Pricing scales with your developer count, so you add units as your team grows. A developer counts as any active contributor who has made at least one commit in the last 90 days to a project you secure. To cover more than the base block, you add additional 25-developer units. Large organizations needing several hundred licenses can request a private offer instead.

    Top-of-mind questions for buyers

    A developer is any active contributor to a project you secure who made at least one commit in the last 90 days. Contributors to your open-source projects count only if they are actual employees. Repositories hosted under your organization stay free for scanning purposes.
    You add units in blocks of 25 contributing developers. Cost scales with the number of units you buy under the annual contract. If your active contributor count crosses a block boundary, you purchase another 25-developer unit to cover the additional developers.
    Developer count reflects active contributors who made at least one commit in the last 90 days to a project you secure. Because this can shift as teams change, you can contact the vendor to get a count based on your repository activity before sizing your units.
    www.gitguardian.com
    Helpful?

    Vendor refund policy

    Please contact sales@gitguardian.com  to learn more about GitGuardian's refund policy.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform https://docs.gitguardian.com  or submit a support request at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    100
    In Application Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    18 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secrets Detection and Classification
    Supports detection of over 450 types of secrets including API keys, private keys, and database credentials across source code and productivity tools
    Multi-Platform Integration
    Integrates with major Version Control Systems (GitHub, GitLab, BitBucket, Azure DevOps), CI/CD tools (Jenkins, Travis CI), and productivity platforms (Slack, Jira, container registries)
    Public Repository Monitoring
    Scans public GitHub repositories to detect sensitive information in both organizational and personal developer accounts
    Policy Enforcement Engine
    Provides robust policy engine enabling security teams to enforce rules and detect policy violations across integrated platforms
    Honeytokens Deployment
    Deploys honeytokens as a defense mechanism to detect unauthorized access and misuse of secrets
    Centralized Secrets Management
    Centrally secures, rotates, and manages secrets across multi-cloud and hybrid environments with a unified view across multiple AWS accounts and AWS Secrets Manager instances.
    Multi-Platform Integration
    Offers REST APIs and integrates with a wide range of DevOps tools, container platforms, vulnerability scanners, RPA, and automation tools for credential delivery.
    Secrets Rotation and Lifecycle Management
    Automatically rotates secrets in AWS Secrets Manager and across cloud environments without requiring changes to developer workflows or applications.
    Audit and Access Control
    Provides centralized control and comprehensive auditing of how applications, DevOps tools, and automation platforms use secrets and privileged credentials to access sensitive resources.
    Enterprise-Scale Architecture
    Designed to support massive scalability with data sovereignty requirements for large global enterprises across multi-cloud and hybrid infrastructure.
    Secrets Management and Orchestration
    Centralized platform for syncing, managing, orchestrating, and rotating secrets automatically across projects, teams, and environments
    Credential Rotation
    Automated credential rotation capabilities without downtime to actively safeguard secrets from data breaches
    Multi-Environment Integration
    Automatic synchronization and deployment of secrets across all environments and infrastructure through expanding suite of integrations
    Developer Tools and IDE Integration
    VS Code extension for editing secrets alongside code with bidirectional sync, and Doppler CLI for consuming secrets as environment variables
    Access Control and Compliance
    Scalable and flexible access controls with detailed activity logs for real-time access management, compliance tracking, and configurable alerts through Slack, Teams, Splunk, or Discord

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    304 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    89%
    10%
    1%
    0%
    0%
    6 AWS reviews
    |
    298 external reviews
    External reviews are from G2  and PeerSpot .
    Akriti Chawla

    Continuous secret scanning has protected our code and improves collaboration in daily workflows

    Reviewed on Sep 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for GitGuardian Platform is to detect and prevent exposed secrets as well as credentials in our source code such as API keys, passwords, tokens, and private keys. It also helps us identify leaked secrets in Git repositories and continuous integration and continuous development pipelines and take action before they can be misused.

    A specific example of how I have used GitGuardian Platform in my workflow is during a code review when a developer accidentally committed API credentials into the Git repository. GitGuardian detected the exposed secret and flagged it before the change could move forward through our deployment workflow. We were able to identify the affected repository, revoke and replace the credentials, and remove the secret from the code. It was useful because the issue was caught early rather than being discovered after a potential security incident. We have used GitGuardian Platform as an additional security check across all our repositories development.

    Day-to-day, we use GitGuardian Platform as part of our deployment, development, and code review process to continuously check our repository for exposed secrets. It helps us catch API keys, tokens, passwords, and credentials early because when an alert appears, we review the findings to identify whether it is an actual secret, take necessary actions such as removing or rotating the credential, and it gives the development team an extra layer of security without adding manual effort to our workflow.

    What is most valuable?

    The best features GitGuardian Platform offers include continuous secret scanning, real-time alerts, clear identification of exposed credentials, and easy access to find the repository, which is useful because it helps us quickly understand where a secret was exposed and what needs to be addressed. The integration with Git workflows makes it easy to include security checks without significantly slowing down development, helping the team to identify and respond to leaked API keys, tokens, passwords, and other sensitive information.

    GitGuardian Platform has positively impacted our organization by improving our overall security awareness and helping us identify exposed credentials early in the development life cycle. It reduces the need for manual checks and gives the team better visibility into potential secrets across all the repositories. When an issue is detected, developers can easily investigate and resolve it quickly before it becomes a larger security concern. It has also encouraged better practices around handling all the API keys, tokens, and sensitive credentials, adding an extra layer of security to our development CI/CD workflow without creating any significant issues for the team.

    What needs improvement?

    GitGuardian Platform could be improved by providing an explanation of the potential risks. Better visualization would help our team quickly focus on the most critical findings. It would also be useful to have a more customizable reporting dashboard for tracking team and repositories. The platform is easy to use, but these improvements could make investigation and remediation even faster.

    The integrations are generally straightforward, but having more guided setup options and clear documentation for advanced integration would make the onboarding process even easier and faster. From a user experience perspective, more customization for the notification dashboard and alert workflow would be useful, especially for our last team. It would also be helpful to have more detailed remediation guidance within alerts. The platform is easy to work with, and the improvements in these areas would make it even more efficient for development as well as our security team.

    For how long have I used the solution?

    I have been using GitGuardian Platform for approximately six to eight months.

    What do I think about the stability of the solution?

    GitGuardian Platform is stable.

    What do I think about the scalability of the solution?

    GitGuardian Platform is very scalable.

    How are customer service and support?

    Customer support for GitGuardian Platform is very good.

    Which solution did I use previously and why did I switch?

    I have not previously used a different solution.

    How was the initial setup?

    The integration process for our team with GitGuardian Platform has been fairly straightforward. The initial setup and connecting our Git repository do not take much time. The documentation made it easy to understand the required steps. Once everything integrated, GitGuardian Platform started providing visibility into potential secrets without requiring any major changes to our existing development workflow. The alerts are very easy to understand and help our team quickly identify what needs attention. The setup was smooth, and the platform fits well in our existing Git and CI/CD processes.

    What about the implementation team?

    We are simply a customer of GitGuardian Platform, having no other business relationship with this vendor.

    What was our ROI?

    I see a good return on investment with GitGuardian Platform in terms of money as well as the time saved.

    What's my experience with pricing, setup cost, and licensing?

    Pricing for GitGuardian Platform is moderate, not very cheap or very costly. I do not find anything discouraging regarding the pricing, setup cost, or licensing. Pricing is very moderate and friendly for all budgets, making it accessible for both large and small enterprises.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing GitGuardian Platform.

    What other advice do I have?

    GitGuardian Platform provides strong visibility into exposed secrets and helps our development security team identify issues early. Its integration with our development workflow makes it practical to use without adding too much overhead.

    We check the alerts or findings generated by GitGuardian Platform daily, using the alerts and fixing them on priority.

    GitGuardian Platform helps improve collaboration between our security and development teams by giving both teams visibility into exposed secrets and the security findings. Developers can quickly understand and remediate issues, while security teams can monitor the situation, creating a more consistent and efficient security workflow across all teams.

    Onboarding new users to GitGuardian Platform is very easy. The platform is intuitive, and new users can quickly understand the dashboards, alerts, and basic workflow with minimal training.

    I always recommend GitGuardian Platform, as it is a very good solution for privacy, adding an extra layer of protection in our pipelines against the exposure of API keys. I would rate this product a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Rostyslav M.

    Catching exposed secrets before they turn into pull request cleanup

    Reviewed on Sep 08, 2026
    Review provided by G2
    What do you like best about the product?
    Installing ggshield as a pre-commit hook has been one of the simplest changes we’ve made with the biggest payoff. When a secret-like value shows up, the commit gets blocked before anything is pushed, and the CLI clearly shows what triggered the detection. We also run it in CI, and the same tooling can be used with pre-receive hooks, which makes it easier to keep checks consistent across local development and the repository. Historical Scanning is just as important, because removing a key from the current version of a file doesn’t remove it from older commits. We use the repository integrations and dashboard to trace the incident, pinpoint where the secret first appeared, and organize remediation. In larger setups, Remediation Playbooks and integrations with Slack, Jira, and ServiceNow help turn an alert into an actual process, instead of just another notification people acknowledge and forget. Honeytokens are a different kind of signal that I also find useful. We can create decoy AWS credentials through ggshield and place them in controlled locations; if someone uses them, there’s very little ambiguity about whether that access was expected. I wouldn’t replace normal monitoring with honeytokens, but they’re helpful when you want to detect real interaction with information that should never be touched.
    What do you dislike about the product?
    The first few weeks can be a bit noisy. Fixtures, test tokens, examples, and random strings sometimes look enough like real credentials to trigger detections. It’s tempting to throw together a giant ignore file and move on, but that usually defeats the purpose of the tool. Instead, we start by reviewing the finding, confirm it’s actually harmless, and then document the exception. The tuning takes some effort—especially in older repositories—but I’d rather deal with that friction than train the team to automatically dismiss every secret alert.
    What problems is the product solving and how is that benefiting you?
    We really saw the value during a hotfix, when a developer temporarily dropped a full database connection string into a .json file for local testing and then forgot to remove it before committing. ggshield blocked the commit immediately and flagged the exact value. Because the credential had already been shared through our local branch workflow, we rotated it right away, removed the value before anything reached the remote repository, and updated the project so configuration always comes from our secret manager. After that, we ran a historical scan and found an older API key buried in a commit from months earlier. Our first assumption was that it didn’t matter anymore because it was no longer on main, but the key was still valid, so we rotated that one too. Overall, GitGuardian prevented a new exposure from reaching the remote, helped us uncover an older one that would otherwise have stayed invisible, and pushed us to fix the workflow itself rather than treating the incident as a one-time cleanup.
    Anonymous

    Effortless Security for GitHub Projects

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    I like GitGuardian because it's autonomous and easy to use. I don't have to log in to my GitGuardian account often since I receive notifications via email, which is comfortable for me. I appreciate that I can let it work in the background, and if something goes wrong, I get notified, with alerts even on my phone. The initial setup was quite straightforward as I connected directly with my GitHub account, making the process simple. Overall, it's comfortably good for my personal projects.
    What do you dislike about the product?
    Nothing, really
    What problems is the product solving and how is that benefiting you?
    I use GitGuardian to keep my secret keys or passwords safe when I push code. It's autonomous and easy to use, notifying me via email so I can address issues without logging into the account.
    Mithu P.

    Useful Security Tool That Catches What’s Easy to Miss

    Reviewed on Aug 18, 2026
    Review provided by G2
    What do you like best about the product?
    I like that GitGuardian catches things I might easily miss, especially exposed API keys or credentials. The alerts are pretty straightforward and make it clear what needs to be fixed. It feels like an extra safety net for the development process without getting in the way too much.
    What do you dislike about the product?
    The main thing I dislike is that some alerts can feel a bit noisy, especially when something is detected that isn’t really a serious risk. It sometimes takes extra time to figure out whether an alert actually needs action. I also feel the UI could make it easier to quickly understand the priority of an issue and what exactly I should do next. Overall it’s useful, but reducing unnecessary alerts and making the workflow a little simpler would make it better.
    What problems is the product solving and how is that benefiting you?
    GitGuardian helps us catch exposed secrets and credentials early, which saves a lot of manual checking and reduces the risk of security issues. Performance has been good overall, and it doesn’t slow down the development workflow too much. The integrations are also useful because we can connect it with the tools we already use. From a cost or ROI point of view, it is helpful because preventing one serious credential leak can save a lot of time and trouble later.The onboarding was fairly straightforward, although some areas could be explained better for new users. I also like the intelligence behind the alerts, but it could do a better job of reducing false positives and making it immediately clear which issues need the most attention.
    Antonio Q.

    Integrated and Effective in Leak Detection

    Reviewed on Aug 16, 2026
    Review provided by G2
    What do you like best about the product?
    I use GitGuardian as an automatic security 'checkpoint', which helps me prevent secrets from being accidentally shared. I like the fact that it integrates into the development flow without the need for new learning or additional steps. The tool detects secrets that should not have been committed, giving me time and peace of mind to regenerate secrets without worrying that someone might have accessed them. The initial setup was simple and easy, even though I know I can configure it better, I don't feel the need to do so at the moment.
    What do you dislike about the product?
    n/a
    What problems is the product solving and how is that benefiting you?
    GitGuardian acts as an automatic security checkpoint, detecting compromised secrets in real-time and providing peace of mind to regenerate them. It integrates easily into the development flow and helps monitor leaks, even with some false alarms.
    View all reviews