Listing Thumbnail

    GitGuardian Platform

     Info
    Sold by: GitGuardian 
    Deployed on AWS
    The end-to-end secrets security platform for enterprises. Scan and fix hardcoded secrets in source code, CI/CD pipelines, and productivity tools with GitGuardian code security platform.
    4.8

    Overview

    Play video

    GitGuardian is an end-to-end secrets security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards.

    With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and Secrets Observability. This dual approach enables the detection of compromised secrets across your dev environments while also managing legitimate secrets and their lifecycle.

    The platform supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense

    Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

    Highlights

    • With Secrets Security, GitGuardian aims to eliminate leaks and sprawl, detecting compromised or misused secrets across both public and internal environments. This foundation of NHI security is strengthened by monitoring for incidents, policy violations, and illegitimate use of secrets.
    • GitGuardian's Secrets Detection tackles internal secrets sprawl by identifying sensitive data in source code and productivity tools. The platform supports over 450 types of secrets, including API keys, private keys, and database credentials. With a robust policy engine, security teams can enforce rules across major Version Control Systems ( like GitHub, GitLab, BitBucket, and Azure DevOps, CI/CD tools such as Jenkins, Travis CI as well as tools like Slack, Jira, container registries, and more.
    • To expand visibility beyond internal systems, GitGuardian Public Monitoring scans public GitHub repositories, detecting sensitive information in both organizational and developers' personal repos. This is crucial, as 80% of corporate secrets leaked on public GitHub stem from personal accounts.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    GitGuardian Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    25 developers
    Business Plan, per 25 contributing developers (annual contract)
    $5,500.00

    AI Insights

     Info

    Dimensions summary

    This listing offers one pricing dimension: the Business Plan, sold as an annual contract. You buy in blocks of 25 contributing developers. Pricing scales with your developer count, so you add units as your team grows. A developer counts as any active contributor who has made at least one commit in the last 90 days to a project you secure. To cover more than the base block, you add additional 25-developer units. Large organizations needing several hundred licenses can request a private offer instead.

    Top-of-mind questions for buyers

    A developer is any active contributor to a project you secure who made at least one commit in the last 90 days. Contributors to your open-source projects count only if they are actual employees. Repositories hosted under your organization stay free for scanning purposes.
    You add units in blocks of 25 contributing developers. Cost scales with the number of units you buy under the annual contract. If your active contributor count crosses a block boundary, you purchase another 25-developer unit to cover the additional developers.
    Developer count reflects active contributors who made at least one commit in the last 90 days to a project you secure. Because this can shift as teams change, you can contact the vendor to get a count based on your repository activity before sizing your units.
    www.gitguardian.com
    Helpful?

    Vendor refund policy

    Please contact sales@gitguardian.com  to learn more about GitGuardian's refund policy.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Explore our guides to use the GitGuardian Platform https://docs.gitguardian.com  or submit a support request at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    100
    In Application Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    18 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secrets Detection and Classification
    Supports detection of over 450 types of secrets including API keys, private keys, and database credentials across source code and productivity tools
    Multi-Platform Integration
    Integrates with major Version Control Systems (GitHub, GitLab, BitBucket, Azure DevOps), CI/CD tools (Jenkins, Travis CI), and productivity platforms (Slack, Jira, container registries)
    Public Repository Monitoring
    Scans public GitHub repositories to detect sensitive information in both organizational and personal developer accounts
    Policy Enforcement Engine
    Provides robust policy engine enabling security teams to enforce rules and detect policy violations across integrated platforms
    Honeytokens Deployment
    Deploys honeytokens as a defense mechanism to detect unauthorized access and misuse of secrets
    Centralized Secrets Management
    Centrally secures, rotates, and manages secrets across multi-cloud and hybrid environments with a unified view across multiple AWS accounts and AWS Secrets Manager instances.
    Multi-Platform Integration
    Offers REST APIs and integrates with a wide range of DevOps tools, container platforms, vulnerability scanners, RPA, and automation tools for credential delivery.
    Secrets Rotation and Lifecycle Management
    Automatically rotates secrets in AWS Secrets Manager and across cloud environments without requiring changes to developer workflows or applications.
    Audit and Access Control
    Provides centralized control and comprehensive auditing of how applications, DevOps tools, and automation platforms use secrets and privileged credentials to access sensitive resources.
    Enterprise-Scale Architecture
    Designed to support massive scalability with data sovereignty requirements for large global enterprises across multi-cloud and hybrid infrastructure.
    Secrets Management and Orchestration
    Centralized platform for syncing, managing, orchestrating, and rotating secrets automatically across projects, teams, and environments
    Credential Rotation
    Automated credential rotation capabilities without downtime to actively safeguard secrets from data breaches
    Multi-Environment Integration
    Automatic synchronization and deployment of secrets across all environments and infrastructure through expanding suite of integrations
    Developer Tools and IDE Integration
    VS Code extension for editing secrets alongside code with bidirectional sync, and Doppler CLI for consuming secrets as environment variables
    Access Control and Compliance
    Scalable and flexible access controls with detailed activity logs for real-time access management, compliance tracking, and configurable alerts through Slack, Teams, Splunk, or Discord

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    311 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    89%
    10%
    1%
    0%
    0%
    6 AWS reviews
    |
    305 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2879661

    Automated secret detection has transformed our security scans and accelerates deployments

    Reviewed on Sep 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for GitGuardian Platform is for security purposes when scanning our source repository, deployment, and all configurations where we can have credentials that cannot be shared with end users or any third party. This is why we are using GitGuardian Platform for security purposes to store all credentials securely.

    In addition to the main use case, there are credentials we want to store for environment-related purposes. For production-related properties, we want to connect with Azure, Git, or some external APIs where we have secret API keys. We keep those in this secret management on Git so that we can secure our systems.

    What is most valuable?

    GitGuardian Platform's best features include automatically detecting issues in API keys, tokens, and passwords.

    The automatic detection feature helps my team and workflow tremendously by saving a lot of time because everything is automatic now and we don't need to scan manually. This has saved considerable time and makes it easy to scan the whole project and find whatever issues exist.

    Regarding additional features, the main focus was the ability to scan our project, CICD workflow, and other tools we are using to identify issues in the initial phases so that we can fix them easily and ensure our system has more comprehensive vulnerability scanning.

    GitGuardian Platform has positively impacted our organization by helping to scan issues in early stages so that we can make decisions and fix them easily. It aids in automatic deployment whenever there is no vulnerability, allowing us to deploy our services without any impact or additional checks, thus saving a lot of time.

    Earlier, when we had a security repository or CICD process, we were taking about four to five days to scan all those things and maintain documentation to reduce vulnerabilities and keys. However, with GitGuardian Platform, we have reduced that time to within a single day to perform all activities.

    What needs improvement?

    GitGuardian Platform is a better solution already, but we could enhance it further by incorporating more features using AI for better security scans instead of just offering guidelines.

    For needed improvements, we could integrate with our source repository, whether it is GitHub, Bitbucket, or Git bucket, and we can do so easily using AI. We would just need to provide proper prompts to scan the whole repository, which could allow for fixing vulnerabilities during development before pushing to deployment.

    For how long have I used the solution?

    I have been using GitGuardian Platform for the last two years.

    What do I think about the stability of the solution?

    GitGuardian Platform is reliable for us and has proven to be stable.

    What do I think about the scalability of the solution?

    For scalability, GitGuardian Platform handles our requests very easily. We are a couple of developers working as a team, and we are using it at a high level without any issues related to scalability.

    How are customer service and support?

    I have not connected with customer support yet because everything has been working fine.

    Which solution did I use previously and why did I switch?

    Earlier, we were using some Git-related cloud tools for scanning, such as SonarQube for finding issues and fixing vulnerabilities. However, now we are using GitGuardian Platform, which is quite helpful.

    How was the initial setup?

    My experience with GitGuardian Platform's pricing, setup cost, and licensing was straightforward. Everything mentioned in the document format was clear, and there were no issues.

    What was our ROI?

    We have seen a return on investment with GitGuardian Platform. The amount we spend yields full results whenever required, so it has been good.

    Which other solutions did I evaluate?

    Before choosing GitGuardian Platform, I did not evaluate other options. I was searching and found this platform to provide a better solution, which led me to utilize it.

    What other advice do I have?

    I advise others considering GitGuardian Platform to proceed with it for integrating CICD tools, workflows, or source repositories, as it can help them in early development, ease their processes, and accelerate their workflow. I rate my overall experience with GitGuardian Platform as nine out of ten.

    Lenin Jose M.

    Essential for Secure Code Management, Needs Improved Alert Handling

    Reviewed on Sep 25, 2026
    Review provided by G2
    What do you like best about the product?
    I like GitGuardian for its ability to send notifications when I commit and push my code to GitHub, highlighting any issues. I also appreciate the Secret Scanning Engine because it finds a lot of secrets that would otherwise be exposed.
    What do you dislike about the product?
    I find GitGuardian's alert fatigue and notification overload to be challenging, especially when dealing with large projects. The management of false positives could also be improved. I believe implementing smarter aggregation, multi-layered notification routing, and automated triage workflows would enhance the experience.
    What problems is the product solving and how is that benefiting you?
    I use GitGuardian to identify security issues on GitHub repositories, especially scanning for secrets in code. It notifies me about any issues right after I commit and push code, which I find really useful.
    Shrikant Patil

    Automated secret detection has improved security reviews and now streamlines credential remediation

    Reviewed on Sep 24, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I mainly use GitGuardian Platform to monitor source code and repositories for exposed secrets and credentials. I identify leaked API keys or tokens and help prioritize and remediate those findings before they can be misused.

    Recently, I used GitGuardian Platform to scan a repository, and it flagged an exposed API credential in the code. I reviewed the finding, verified where the credential was being used, removed it from the repository, rotated the affected credentials, and updated the code to use a secure secret management approach instead.

    What is most valuable?

    The best features for me are automated secret detection, repository monitoring, and clear alerts for exposed credentials. I also find the ability to prioritize findings and track remediation useful because it makes it easier to quickly identify high-risk secrets and ensure they are properly addressed.

    The feature I rely on most day-to-day is automated secret detection and repository monitoring. It continuously helps identify exposed API keys, tokens, passwords, and other credentials across repositories, so I do not have to manually review every change for potential leaks. It is especially important in my workflow because I work with security testing and code review, and catching a credential early allows me to investigate and remediate it before it becomes a larger security issue.

    GitGuardian Platform has improved our security posture by giving us better visibility into exposed secrets across repositories. It has also made my daily workflow more efficient because I can quickly identify, investigate, and remediate leaked credentials instead of relying entirely on manual code reviews. Overall, it has helped make secret detection a more consistent part of our deployment and security process.

    What needs improvement?

    One area that could be improved is reducing false positives and making it easier to quickly understand the context and severity of a detected secret. More detailed remediation guidance and additional customization for alerts and scanning rules would also make GitGuardian Platform even more useful for security teams managing a larger number of repositories.

    For how long have I used the solution?

    I have been using GitGuardian Platform for the last nine months.

    What do I think about the stability of the solution?

    GitGuardian Platform is very stable.

    What do I think about the scalability of the solution?

    GitGuardian Platform has been scalable for our use case. It works well with the number of repositories and code changes growing while continuing to provide visibility into potential secret exposures. This makes it suitable for teams that need consistent secret detection across a growing deployment environment.

    How are customer service and support?

    Customer support is good.

    How was the initial setup?

    My experience with the pricing and licensing was generally positive. The setup was straightforward, and I found the licensing model relatively easy to understand. The overall cost felt reasonable for the visibility and security value provided, although pricing can vary depending on the organization's requirement and scale.

    What was our ROI?

    I have seen a positive return on investment, mainly through time saved in identifying and investigating exposed credentials. GitGuardian Platform reduces the amount of manual effort required for secret detection and helps the security team respond to findings faster. I do not have a specific dollar amount or percentage to share, but the improved efficiency and earlier detection provide clear value in our security workflow.

    What other advice do I have?

    I would recommend evaluating GitGuardian Platform if secret detection and credential exposure are important concerns for your organization. It provides useful visibility into repositories, helps identify exposed credentials early, and makes investigation and remediation more efficient. I would suggest starting with the areas most relevant to your deployment workflow and then expanding coverage as needed. I gave this review a rating of 10.

    PrinceKumar7

    Automated secret detection has transformed our workflows and now prevents leaks in real time

    Reviewed on Sep 23, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Our primary use case for GitGuardian Platform is preventing credentials and other sensitive secrets from being accidentally committed to source code or exposed through our development and CI/CD workflows. We experienced one or two incidents where our secrets were leaked through Git when developers accidentally committed them or they were exposed through the pipeline. This is crucial from an infrastructure perspective because our application interacts with many cloud services. For example, development and deployment environments can contain AWS access keys, API keys, database credentials, and JWT tokens. The problem is not always intentional credential exposure, as a developer can accidentally include credentials in a .env file, Terraform variable, Docker file, or CI/CD configuration and commit it to Git.

    GitGuardian Platform is designed to detect hardcoded secrets in both repositories and CI/CD workflows, including historical repositories and new contributions. It supports integrations with GitHub, GitLab, Bitbucket, and Azure DevOps, all of which we use in our organization. Our precise use case is to detect secrets before they become a production security issue.

    GitGuardian Platform fits into our workflow in many steps. The first step is repository secret scanning, the second is CI/CD pipeline production, the third is pull request scanning, and the fourth is historical scanning.

    How has it helped my organization?

    Since adopting GitGuardian Platform, the most significant improvement in our organization is moving secret security earlier in the development process. Previously, the workflow involved developers committing secrets, which remained in repositories, leading to manual discoveries by the security team, credential rotations, and further investigations. This process was burdensome and time-consuming. Now, we have automated detection where developers commit secrets, the scanner detects them, the security team receives findings, and the secrets are either removed or rotated, significantly shortening the time between exposure and detection. This reduces our reliance on developers to remember every possible security rule.

    I recall scanning twenty repositories for any secrets manually when our first AWS account was hacked, which took me around four days. However, GitGuardian Platform saves all those four days of my manual work by automating this process.

    What is most valuable?

    In my experience, the best features of GitGuardian Platform include real-time secret detection, which is invaluable for catching credentials close to when they are introduced rather than finding them weeks later. The second feature is historical repository scanning. Additionally, it has CI/CD integration, can integrate with multiple Git platforms, offers custom detectors, provides context-aware detection, and allows for severity and prioritization of issues.

    The first three features have saved us considerably, particularly the real-time secret detection, while we initially also depended on historical repository scanning. As a DevOps professional, CI/CD integration is critically important to me.

    What needs improvement?

    I would improve GitGuardian Platform by reducing false positives and streamlining remediation. I also desire stronger integration around issue management workflows. For instance, once a critical secret is detected, the ideal workflow should involve detection, ticket creation, owner assignment, credential rotation, verification, and closure. The more automated this process becomes, the fewer manual security work is required.

    For how long have I used the solution?

    I have been using GitGuardian Platform for around one year.

    What other advice do I have?

    My advice for others considering GitGuardian Platform is that for DevOps and cloud infrastructure teams, integrating secret detection into normal development and CI/CD workflows makes much more sense than relying entirely on manual security reviews. This tool is incredibly useful. I would rate this product a ten out of ten.

    Tej K.

    Fast Incident Notifications That Help Resolve Issues Quickly

    Reviewed on Sep 23, 2026
    Review provided by G2
    What do you like best about the product?
    I liked that the incident notification came quickly, which helped me address the issue and fix it.
    What do you dislike about the product?
    Some of the notifications were late, which was the downside.
    What problems is the product solving and how is that benefiting you?
    The main problem Git GuardiauN solved for me was that errors were displayed with priority and with the exact line-by-line location.
    View all reviews