Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    Vendor Insights
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.
    4.8

    Overview

    Play video

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    Business Plan, per 25 contributing developers (annual contract)
    $5,500.00

    AI Insights

     Info

    Dimensions summary

    This listing offers one pricing dimension: the Business Plan, sold as an annual contract. You buy in blocks of 25 contributing developers. Pricing scales with your developer count, so you add units as your team grows. A developer counts as any active contributor who has made at least one commit in the last 90 days to a project you secure. To cover more than the base block, you add additional 25-developer units. Large organizations needing several hundred licenses can request a private offer instead.

    Top-of-mind questions for buyers

    A developer is any active contributor to a project you secure who made at least one commit in the last 90 days. Contributors to your open-source projects count only if they are actual employees. Repositories hosted under your organization stay free for scanning purposes.
    You add units in blocks of 25 contributing developers. Cost scales with the number of units you buy under the annual contract. If your active contributor count crosses a block boundary, you purchase another 25-developer unit to cover the additional developers.
    Developer count reflects active contributors who made at least one commit in the last 90 days to a project you secure. Because this can shift as teams change, you can contact the vendor to get a count based on your repository activity before sizing your units.
    www.gitguardian.com
    Helpful?

    Vendor refund policy

    Please contact sales@gitguardian.com  to learn more about GitGuardian's refund policy.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform https://docs.gitguardian.com  or submit a support request at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    100
    In Application Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    18 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secrets Detection and Classification
    Supports detection of over 450 types of secrets including API keys, private keys, and database credentials across source code and productivity tools
    Multi-Platform Integration
    Integrates with major Version Control Systems (GitHub, GitLab, BitBucket, Azure DevOps), CI/CD tools (Jenkins, Travis CI), and productivity platforms (Slack, Jira, container registries)
    Public Repository Monitoring
    Scans public GitHub repositories to detect sensitive information in both organizational and personal developer accounts
    Policy Engine and Enforcement
    Includes a robust policy engine that enables security teams to enforce rules and manage secrets lifecycle across integrated platforms
    Honeytokens and Incident Detection
    Deploys honeytokens for defense and monitors for incidents, policy violations, and illegitimate use of secrets in both public and internal environments
    Centralized Secrets Management
    Centrally secures, rotates, and manages secrets across multi-cloud and hybrid environments with a unified view across multiple AWS accounts and AWS Secrets Manager instances.
    Multi-Platform Integration
    Offers REST APIs and integrates with a wide range of DevOps tools, container platforms, vulnerability scanners, RPA, and automation tools for credential delivery.
    Secrets Rotation and Lifecycle Management
    Automatically rotates secrets in AWS Secrets Manager and across enterprise environments without requiring changes to developer workflows or applications.
    Audit and Access Control
    Provides centralized control and comprehensive auditing of how applications, DevOps tools, and automation platforms authenticate and access sensitive resources including databases and cloud environments.
    Enterprise-Scale Architecture
    Designed to support massive scalability with data sovereignty requirements for large global enterprises and eliminates vault sprawl across distributed environments.
    Secrets Management and Centralization
    Centralized platform for managing secrets across projects, teams, and environments to eliminate secrets sprawl
    Automated Credential Rotation
    Automatic rotation of credentials without downtime to safeguard against data breaches
    Multi-Environment Integration
    Automatic synchronization and deployment of secrets across environments and infrastructure through expanding suite of integrations
    Access Control and Audit Logging
    Scalable and flexible access controls with detailed activity logs for real-time access management and compliance
    Developer-Centric Tools
    VS Code extension for editing secrets alongside code with bidirectional synchronization and Doppler CLI for consuming secrets as environment variables

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    300 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    89%
    10%
    1%
    0%
    0%
    5 AWS reviews
    |
    295 external reviews
    External reviews are from G2  and PeerSpot .
    Mithu P.

    Useful Security Tool That Catches What’s Easy to Miss

    Reviewed on Aug 18, 2026
    Review provided by G2
    What do you like best about the product?
    I like that GitGuardian catches things I might easily miss, especially exposed API keys or credentials. The alerts are pretty straightforward and make it clear what needs to be fixed. It feels like an extra safety net for the development process without getting in the way too much.
    What do you dislike about the product?
    The main thing I dislike is that some alerts can feel a bit noisy, especially when something is detected that isn’t really a serious risk. It sometimes takes extra time to figure out whether an alert actually needs action. I also feel the UI could make it easier to quickly understand the priority of an issue and what exactly I should do next. Overall it’s useful, but reducing unnecessary alerts and making the workflow a little simpler would make it better.
    What problems is the product solving and how is that benefiting you?
    GitGuardian helps us catch exposed secrets and credentials early, which saves a lot of manual checking and reduces the risk of security issues. Performance has been good overall, and it doesn’t slow down the development workflow too much. The integrations are also useful because we can connect it with the tools we already use. From a cost or ROI point of view, it is helpful because preventing one serious credential leak can save a lot of time and trouble later.The onboarding was fairly straightforward, although some areas could be explained better for new users. I also like the intelligence behind the alerts, but it could do a better job of reducing false positives and making it immediately clear which issues need the most attention.
    Antonio Q.

    Integrated and Effective in Leak Detection

    Reviewed on Aug 16, 2026
    Review provided by G2
    What do you like best about the product?
    I use GitGuardian as an automatic security 'checkpoint', which helps me prevent secrets from being accidentally shared. I like the fact that it integrates into the development flow without the need for new learning or additional steps. The tool detects secrets that should not have been committed, giving me time and peace of mind to regenerate secrets without worrying that someone might have accessed them. The initial setup was simple and easy, even though I know I can configure it better, I don't feel the need to do so at the moment.
    What do you dislike about the product?
    n/a
    What problems is the product solving and how is that benefiting you?
    GitGuardian acts as an automatic security checkpoint, detecting compromised secrets in real-time and providing peace of mind to regenerate them. It integrates easily into the development flow and helps monitor leaks, even with some false alarms.
    Mir Shahzad Mubeen

    Continuous secret monitoring has improved our code security and protected critical workflows

    Reviewed on Aug 07, 2026
    Review from a verified AWS customer

    What is our primary use case?

    GitGuardian Platform provides security through secret detection and broader code security. The main benefit is ensuring that secrets are properly managed across our organization.

    Honeycomb has many repositories, multiple agents, multiple backends, numerous React frontends, AWS Lambda integrations, automations, third-party APIs, and multiple developers. To manage all of this, we maintain hundreds of secrets to ensure that developers do not commit environment files and that everything is properly secured. GitGuardian Platform scans every commit, branch, pull request, and the entire repository history, which informs us about security gaps and code issues. Because it continuously monitors our system rather than performing just one scan, when a developer pushes code, we receive alerts that are generated immediately. This continuous monitoring capability has made GitGuardian Platform our main solution.

    What is most valuable?

    GitGuardian Platform offers numerous integrations, including GitHub, GitLab, AWS, email, Jira, and Slack. The continuous monitoring system that watches for pushes as soon as developers commit code is also a valuable feature.

    Integration with Slack and Jira allows developers to be notified immediately when a secret is detected, so they can revoke or rotate credentials before they are abused. Jira integration helps us track issues effectively through resolution by automatically creating tickets and assigning ownership.

    GitGuardian Platform has provided accurate and reliable output for detecting common secrets and credentials. Most alerts provide sufficient context to investigate and remediate issues properly. From a security perspective, no exposed credentials are shared between branches. When credentials are shared, they are detected easily, and developer awareness around secret management has improved.

    What needs improvement?

    The automated checks encourage developers to remove or rotate exposed credentials before code is merged. GitGuardian Platform is working well for our organization, and I currently see no needs for improvements. However, deeper integrations with AI development workflows and services would be useful because security is a main concern with the use of AI agents.

    I rate GitGuardian Platform a nine out of ten because there is a slight learning curve in integration, and I would have preferred integration with AI-native development workflows. With the increase of AI-focused workflows and incident prioritizations, AI agents need a security system that can flag security leaks. Apart from AI workflow considerations, the platform performs well.

    For how long have I used the solution?

    I have been using GitGuardian Platform for approximately two years.

    What do I think about the stability of the solution?

    GitGuardian Platform is stable.

    What do I think about the scalability of the solution?

    GitGuardian Platform demonstrates good scalability and is well suited for organizations managing multiple repositories and multiple developers with centralized monitoring.

    Which solution did I use previously and why did I switch?

    We have not used any solution before GitGuardian Platform.

    How was the initial setup?

    I was not directly involved in evaluating pricing, but the setup from a technical perspective was straightforward.

    What was our ROI?

    I do not have quantified ROI figures because our team has not tracked them separately. For us, the return is more about reducing security risks and avoiding costs than achieving a direct, measurable financial benefit.

    What other advice do I have?

    For others considering GitGuardian Platform, I recommend starting by connecting your most critical repositories and running a historical scan to identify any existing exposures. I also recommend integrating it with your pull request workflow and notification tools such as Slack or Jira, so any detected issues are addressed early. Establishing a clear process is crucial, and GitGuardian Platform delivers the most value when it is incorporated into the development workflow rather than used only for occasional scans. I rate this product a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Shemanti P.

    Proactive Secrets Detection That Fits Developers’ Workflow

    Reviewed on Aug 03, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about GitGuardian is its proactive approach to developer security. Instead of treating security as a final checkpoint, GitGuardian helps developers detect and remediate exposed secrets early in the development lifecycle. I also appreciate the company's strong focus on developer experience, practical security solutions, and commitment to open-source contributions, which makes security easier to adopt without slowing down development.
    What do you dislike about the product?
    One limitation is that GitGuardian is primarily focused on secrets detection and remediation. While it integrates well into broader security workflows, organizations still need additional tools for areas like vulnerability management, code quality, or broader application security. That's not necessarily a flaw, but it does mean GitGuardian is one part of a larger security stack rather than a complete security platform.
    What problems is the product solving and how is that benefiting you?
    GitGuardian solves the problem of exposed secrets—such as API keys, passwords, and tokens—that can accidentally be committed to source code or shared in repositories. These leaks are a common cause of security incidents and can be difficult to detect manually. By continuously scanning repositories and providing remediation guidance, GitGuardian helps teams identify and fix exposed secrets before they can be exploited. As a developer, I benefit from faster feedback, greater confidence when collaborating on code, and a smoother way to incorporate security into the development workflow without relying solely on manual reviews.
    Rohit P.

    Seamless Workflow Integration with Fast, Reliable Secret Detection

    Reviewed on Jul 31, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about GitGuardian is how seamlessly it fits into our development workflow while making secret detection simple and reliable. The interface is clean and easy to navigate, the integrations with our repositories were straightforward to set up, and scans run quickly without affecting our development process. The alerts provide enough context to understand the issue and fix it efficiently, which has helped us prevent accidental credential leaks before they become security incidents. The documentation and onboarding made it easy to get started, and overall the value it provides in reducing security risks and saving developer time makes it well worth the investment.
    What do you dislike about the product?
    One area that could be improved is reducing occasional false positives, as some alerts still require manual verification before taking action. I would also like to see more customization options for notification rules and reporting, especially for larger teams managing multiple repositories. While the platform is easy to use overall, some advanced settings can take a bit of time to discover, and more in-app guidance for those features would make the experience even better.
    What problems is the product solving and how is that benefiting you?
    GitGuardian helps solve the problem of accidentally exposing sensitive credentials like API keys, tokens, and passwords in source code. Instead of relying on manual code reviews to catch these issues, it automatically detects and alerts us early in the development process. This has reduced the risk of security incidents, saved time during reviews, and given our team greater confidence that we're protecting sensitive information before code is merged or deployed.
    View all reviews