Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI CD pipelines, and productivity tools with GitGuardian code security platform.
    4.4

    Overview

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    GitGuardian Business Secret detection for 25 Developers
    $5,500.00

    AI Insights

     Info

    Dimensions summary

    This listing offers one pricing dimension: GitGuardian Business secret detection for 25 developers. You buy access under a single contract based on developer seats, with this option covering up to 25 developers. A developer is counted as any active contributor who has made at least one commit in the last 90 days to a project you secure. Pricing scales with the number of developer seats, so this fixed 25-developer package sets both your seat count and your billing. Larger developer counts are handled through separate arrangements, not this dimension.

    Top-of-mind questions for buyers

    This plan covers Internal Secrets Monitoring. It scans your source code, CI/CD pipelines, and container registries for hardcoded secrets. You also get remediation playbooks and support for up to 20 teams. It scans Git repositories up to a set capacity. Public Secrets Monitoring and NHI Governance sit outside this plan.
    For Internal Secrets Monitoring, a developer is any active contributor who made at least one commit in the last 90 days to a project you secure. Only active contributors count, not every account. If your active contributor total stays at or below 25, this package fits your team.
    Developer Endpoint Protection is a separate add-on, not part of this seat-based plan. It is priced per endpoint per year. Developer endpoints map one-to-one to your platform seats. Standard endpoints cover non-developer machines. Each endpoint includes at least one Honeytoken. Contact GitGuardian for an endpoint count and quote.
    www.gitguardian.com
    Helpful?

    Vendor refund policy

    Full refund within 90 days of purchase. Contact support via email.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform or submit a support ticket in the platform. You can reahc out to our support team for any issue you encounter at support@gitguardian.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.4
    22 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    64%
    36%
    0%
    0%
    0%
    6 AWS reviews
    |
    16 external reviews
    External reviews are from PeerSpot .
    Mir Shahzad Mubeen

    Continuous secret monitoring has improved our code security and protected critical workflows

    Reviewed on Aug 07, 2026
    Review from a verified AWS customer

    What is our primary use case?

    GitGuardian Platform provides security through secret detection and broader code security. The main benefit is ensuring that secrets are properly managed across our organization.

    Honeycomb has many repositories, multiple agents, multiple backends, numerous React frontends, AWS Lambda integrations, automations, third-party APIs, and multiple developers. To manage all of this, we maintain hundreds of secrets to ensure that developers do not commit environment files and that everything is properly secured. GitGuardian Platform scans every commit, branch, pull request, and the entire repository history, which informs us about security gaps and code issues. Because it continuously monitors our system rather than performing just one scan, when a developer pushes code, we receive alerts that are generated immediately. This continuous monitoring capability has made GitGuardian Platform our main solution.

    What is most valuable?

    GitGuardian Platform offers numerous integrations, including GitHub, GitLab, AWS, email, Jira, and Slack. The continuous monitoring system that watches for pushes as soon as developers commit code is also a valuable feature.

    Integration with Slack and Jira allows developers to be notified immediately when a secret is detected, so they can revoke or rotate credentials before they are abused. Jira integration helps us track issues effectively through resolution by automatically creating tickets and assigning ownership.

    GitGuardian Platform has provided accurate and reliable output for detecting common secrets and credentials. Most alerts provide sufficient context to investigate and remediate issues properly. From a security perspective, no exposed credentials are shared between branches. When credentials are shared, they are detected easily, and developer awareness around secret management has improved.

    What needs improvement?

    The automated checks encourage developers to remove or rotate exposed credentials before code is merged. GitGuardian Platform is working well for our organization, and I currently see no needs for improvements. However, deeper integrations with AI development workflows and services would be useful because security is a main concern with the use of AI agents.

    I rate GitGuardian Platform a nine out of ten because there is a slight learning curve in integration, and I would have preferred integration with AI-native development workflows. With the increase of AI-focused workflows and incident prioritizations, AI agents need a security system that can flag security leaks. Apart from AI workflow considerations, the platform performs well.

    For how long have I used the solution?

    I have been using GitGuardian Platform for approximately two years.

    What do I think about the stability of the solution?

    GitGuardian Platform is stable.

    What do I think about the scalability of the solution?

    GitGuardian Platform demonstrates good scalability and is well suited for organizations managing multiple repositories and multiple developers with centralized monitoring.

    Which solution did I use previously and why did I switch?

    We have not used any solution before GitGuardian Platform.

    How was the initial setup?

    I was not directly involved in evaluating pricing, but the setup from a technical perspective was straightforward.

    What was our ROI?

    I do not have quantified ROI figures because our team has not tracked them separately. For us, the return is more about reducing security risks and avoiding costs than achieving a direct, measurable financial benefit.

    What other advice do I have?

    For others considering GitGuardian Platform, I recommend starting by connecting your most critical repositories and running a historical scan to identify any existing exposures. I also recommend integrating it with your pull request workflow and notification tools such as Slack or Jira, so any detected issues are addressed early. Establishing a clear process is crucial, and GitGuardian Platform delivers the most value when it is incorporated into the development workflow rather than used only for occasional scans. I rate this product a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Antonio Tirado Peña

    Automated secret detection has eliminated code leaks and enforces secure commits in pipelines

    Reviewed on Jul 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use GitGuardian Platform mainly to prevent and detect exposed credentials, API keys, database connection strings, cloud credentials, and SSH keys within our repository and within the CI/CD pipelines. It works as a safety net that automates everything to ensure the code is clean and can reach production properly and that there are no credential leaks.

    When we have made a commit with some secret hardcoded in the code, it has automatically notified us by email saying that the Git commit cannot be done because it has exposed secrets.

    We trust it and we see that it is really working. It detects if there is any code leakage, and it is very useful when you have public repositories.

    What is most valuable?

    The best features offered by GitGuardian Platform are historical scanning, since it incorporates all existing repositories and all legacy repositories. The ability to analyze histories is amazing. It brings to light exposed credentials in old commits, forgotten branches, and it is a pretty good, quite complete standard scanner. It has real-time detection and CI/CD integration. It intercepts secrets in the pipeline itself or through a pre-commit hook. This is useful because you do not even get to make the commit; instead, you detect the leak beforehand. It directly notifies the specific developer so they can fix the problem, which is great.

    Regarding CI/CD integration and real-time detection, it has impacted the number of incidents or security leaks we have in the company. In the company we have ISO 27000 and the National Security Scheme, and one of the KPIs we have specifically is security leaks or security breaches. Since we have GitGuardian Platform, secrets in code are better monitored.

    The reduction of security leaks since we implemented GitGuardian Platform has been drastic and we have brought the indicator down to zero percent of secrets revealed within the code.

    What needs improvement?

    GitGuardian Platform has the occasional false positive in testing. Sometimes it detects simulated or dummy keys that are put into unit tests. The management of custom patterns could be a bit more streamlined or a bit more automated, as it detects certain formats with internal tokens.

    For how long have I used the solution?

    I have been using this tool for two or three years.

    What do I think about the stability of the solution?

    GitGuardian Platform is super stable, a ten out of ten. It works without any latency, everything working in real time, without penalizing compilation time.

    What do I think about the scalability of the solution?

    It scales without problems across multiple repositories and developer accounts without loss of performance at peak working hours.

    How are customer service and support?

    I have not needed to use GitGuardian Platform support.

    Which solution did I use previously and why did I switch?

    We did not use any similar solution previously.

    How was the initial setup?

    For costs, we are on the free version for up to twenty-five developers, so we are totally covered. As for the implementation, it is super simple. You open GitHub, open the GitGuardian Platform connector, configure the repositories you want it to monitor, and it is running. The learning curve and monitoring are almost zero. We use GitGuardian Platform's SaaS. What we did was configure it with the GitHub connector, which took just a few clicks, and you just set it to work and notifications and responses start arriving about all your repositories that you share.

    What about the implementation team?

    We did not evaluate other options initially. We discovered GitGuardian Platform and since the implementation was very fast, the license we use for the number of developers we have in the company is the free one, and everything worked the first time and everything is working perfectly, we have not evaluated other options.

    What was our ROI?

    I have seen a return on investment by the reduction of security incidents. We have reduced security incidents related to secret leaks.

    What's my experience with pricing, setup cost, and licensing?

    For costs, we are on the free version for up to twenty-five developers, so we are totally covered.

    Which other solutions did I evaluate?

    We did not evaluate other options initially. We discovered GitGuardian Platform and since the implementation was very fast, the license we use for the number of developers we have in the company is the free one, and everything worked the first time and everything is working perfectly, we have not evaluated other options.

    What other advice do I have?

    GitGuardian Platform is a ten. I give GitGuardian Platform a ten because it is super stable, it has no service interruptions, the webhooks and real-time analysis respond with total consistency, without penalizing pull request compilation times. It is very scalable; it has grown as our team has grown. It protects us and we are quite happy with it.

    They should try it without any doubt. It is a marvel that fulfills everything it promises. If you are applying shift-left security policies within your company and you want to put a hard stop to credential leaks within your microservices architecture or your cloud infrastructure, GitGuardian Platform is one of the most effective tools I have found on the market. It covers the gap between DevSecOps and development very well. As long as you dedicate some initial time to adjusting exceptions in test environments, it works wonderfully.

    I give GitGuardian Platform an overall rating of ten out of ten.

    Udit Parekh

    Continuous secret detection has strengthened DevSecOps and improves real-time incident response

    Reviewed on Jul 24, 2026
    Review from a verified AWS customer

    What is our primary use case?

    GitGuardian Platform is used to detect exposed secrets such as API keys, AWS credentials, database passwords, SSH keys, and tokens across the Git repository before they become a security incident.

    What is most valuable?

    GitGuardian Platform offers secret detection across repositories, real-time alerts, broad account support for cloud credentials and API keys, easy integration with GitHub, and incident tracking.

    Real-time alerts and incident tracking features help significantly by enabling immediate alerts after credentials are committed rather than discovering leaked credentials during periodic audits. In real time, monitoring and remediating exposed credentials is very helpful.

    GitGuardian Platform positively impacts the organization by strengthening the DevSecOps process, reducing the risk of credential exposure, and increasing developer awareness around secure coding practices.

    Specific outcomes from using GitGuardian Platform include faster detection of exposed credentials, reduced manual repository reviews, improved developer awareness of secret management, and better compliance with internal security policies.

    Regarding GitGuardian Platform's AI capabilities, security is clearly the platform's main focus as it provides strong visibility into secret exposure and helps organizations establish better governance around credential management.

    GitGuardian Platform's AI detection engine is accurate, and relatively few false positives are experienced. The alerts are actionable and easy to investigate, and the accuracy and reliability are strong.

    What needs improvement?

    GitGuardian Platform can be improved with better integration with enterprise ticketing platforms, enhancing the dashboard for executive reporting, and providing more automation for remediation.

    Needed improvements for GitGuardian Platform should focus on enhancing the detection capabilities, reporting, workflow automation, and enterprise integration.

    What other advice do I have?

    GitGuardian Platform should be integrated early into the development lifecycle and secret detection should be made part of the pull request and CI/CD process. It works best as a preventive control rather than something that is only used during periodic security audits, making it valuable for teams currently dealing with security audits and frequently exposed secrets. I would rate this solution 9 out of 10.

    PeterHenggeler

    Automated alerts have prevented secret leaks and save us time cleaning repository history

    Reviewed on Jul 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for GitGuardian Platform is secret detection.

    Every time we open a pull request, it scans the pull request and ensures that we did not accidentally put a database password in a pull request. That process has worked very well for my team as it has caught several things, it is very helpful, and it is easy to use.

    What is most valuable?

    The best features GitGuardian Platform offers include notification directly to the engineer who created the pull request.

    The direct notification feature has helped my engineers and my workflow overall by being effective. It is nice to know that no matter what happens, day or night, if someone puts up a change, they will get an alert, and the security team will get an alert.

    GitGuardian Platform has positively impacted our organization as it helps us reduce the number of secrets that we would accidentally commit into source code. We have definitely saved time, as we do not have to go clean out Git history because we can just rotate the secret quickly.

    What needs improvement?

    I do not have real feedback on how GitGuardian Platform can be improved as I think the team does a good job.

    For how long have I used the solution?

    I have been using GitGuardian Platform for four years.

    What other advice do I have?

    My advice to others looking into using GitGuardian Platform is that it is a very quick win to set up and very easy to configure. I would rate this review a 10.

    Sanket-Shinde

    Secret scanning has protected sensitive data and now streamlines fixing vulnerabilities

    Reviewed on Apr 19, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I use GitGuardian Platform to ensure that there are no secrets committed, such as hardcoded values, database credentials, API keys, or any secrets that could be exposed to external users of our application. To maintain security and data accuracy, confidential data should not be shared with other platforms. GitGuardian Platform checks our local code first, then it passes through our CI/CD pipeline as well. When we push code to GitHub, it scans and sends a report via Gmail, so we have to fix those security vulnerabilities.

    What is most valuable?

    The best features of GitGuardian Platform are that it detects everything being pushed through the repository and scans everything comprehensively. It checks the possibility of exposure, so if there are API keys or database passwords being used, it warns us to either remove, rotate, or replace them, ensuring they should not be present in a GitGuardian Platform scan.

    Our company has seen many benefits from using GitGuardian Platform, especially since there have been numerous cyber attacks and security threats in the last two to three years. Our company has remained very safe in this regard because we need to secure our data effectively, being in the insurance reinsurance sector. GitGuardian Platform ensures our data is protected by regularly scanning the repositories and sending us reports on how to fix vulnerabilities, keeping us safe from cyber attacks.

    What needs improvement?

    GitGuardian Platform could improve by providing a more user-friendly UI with tips or solutions. With AI advancements, they could offer AI-specific solutions in scanning reports, suggesting fixes for GitGuardian Platform incidents, and even permit automated fixes, which would significantly reduce the developer's workload.

    For how long have I used the solution?

    I have been using GitGuardian Platform for the last one year.

    What do I think about the stability of the solution?

    Stability and availability of GitGuardian Platform are commendable; it is stable and available.

    It is stable because when I push changes, it scans immediately, confirming fixes. There is no downtime during scanning, maintaining stability and availability.

    How are customer service and support?

    I find support good since we have not needed much help from them. The guidelines provided are sufficient for guiding us on what to fix.

    Which other solutions did I evaluate?

    There are many tools in our organization for similar purposes, but GitGuardian Platform is specifically for exposing secrets. We also use Snyk for vulnerability scanning, among others, though I cannot recall all of them.

    The decision was made by my organization, not me, so I am not sure about the parameters they considered before choosing GitGuardian Platform.

    What other advice do I have?

    GitGuardian Platform prioritizes incidents in our workflow through automated validity checks. There are high risk, low risk, and medium risk incidents raised, and the infosec team prioritizes them and approaches us, the developers who pushed those changes, to fix them accordingly.

    GitGuardian Platform's public leakage detection influences our company's data security as a precaution. We are not sure if data might be exposed, but taking this precaution by scanning the repositories is crucial. A cyber attacker just needs one piece of data, so we ensure at least that one thing is secured. It is about cyber attack prevention, ensuring all our data remains safe.

    It rates the effectiveness of severity in incident management based on the severity of the change. This allows us to address the most important ones first. It checks what has been pushed from the code, raising a high-level vulnerability if database-related passwords are involved and reports it urgently. For low-level issues like hardcoded values for APIs, it is reported accordingly based on priority.

    I use GitGuardian Platform's automated playbooks for scanning. Productivity-wise, these playbooks help me know if I am going to push code with secrets. I am aware now, so I intentionally avoid that, ensuring I write good code. It increases my productivity by helping me fix issues proactively. If GitGuardian Platform were not here and vulnerabilities were discovered later, there could be severe consequences. Currently, that impact has been reduced, minimizing our efforts significantly through early precautions.

    Our organization is currently innovating on the AI side, which includes creating a custom agent to fix vulnerabilities, similar to GitHub Copilot. This agent automates changes required based on GitGuardian Platform scanning, closing incidents directly. This support reduces our efforts and timelines.

    Fixing vulnerabilities now takes approximately 60% less time. If fixing took ten days, I now do it in six. I am not sure about multi-vault integration because I am just a developer using it to fix my code changes. I am not sure if I am using GitGuardian Platform's Honey Tokens feature. I would rate this product an 8.5 overall.

    View all reviews