GitGuardian

B
B tier on Secrets Scanning SoftwareScore 7.3 · #2 of 23
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, Mac, self-hosted, Web, Windows
gitguardian.com
The GitGuardian homepage

Summary

GitGuardian helps organizations detect exposed secrets and manage non-human identities and AI-agent security. Internal Secrets Monitoring scans code, CI/CD, and collaboration tools, while Public Secrets Monitoring looks for secrets exposed on public GitHub. Repository scans can run in real time or historically, and the ggshield command-line tool supports scanning during development and pre-commit hooks. The listed capabilities also cover CI/CD, pull-request, and push-protection scanning, along with custom detection rules. Growth adds remediation playbooks, Slack, Jira, and ServiceNow integrations, AI risk scoring, and false-positive filtering. Enterprise adds non-human identity governance and self-hosted deployment through GitGuardian Bridge, with Helm or KOTS deployment support. The free Starter plan supports up to 25 developers, unlimited real-time scanning, up to 500 historical scan detections, and 10,000 API calls per month. Growth and Enterprise pricing is available by contacting sales, and a 30-day trial is listed.

Who it is for

It suits application-security teams monitoring internal repositories and threat-response teams watching public GitHub. Developers can use ggshield for command-line scanning during coding.

What is good

  • Scans repositories in real time and historically.
  • ggshield supports pre-commit scanning.
  • Supports GitHub, GitLab, Bitbucket, and Azure DevOps.
  • Starter is free for up to 25 developers.
  • Enterprise offers self-hosted deployment.

What to know first

  • Growth pricing requires contacting sales.
  • Enterprise pricing is custom and requires contacting sales.
  • Starter repository scan capacity is 1 GB.

Everything Xiaomi review

GitGuardian: the full review

GitGuardian covers secret detection across internal development workflows and public GitHub, with governance and self-hosting options at the Enterprise tier. Starter is a free entry point, while Growth and Enterprise require a sales inquiry.

Overview

GitGuardian is a secrets-security platform for organizations that need to catch leaked credentials across development workflows and public GitHub. It suits security teams that need coverage beyond a developer’s local scan, especially when they also need governance or self-hosting. Its strongest case is broad monitoring with a free starting tier; the trade-off is that the wider capabilities require a sales-led plan.

Key features

  • Repository and workflow scanning: GitGuardian scans repositories in real time and historically, and supports GitHub, GitLab, Bitbucket, and Azure DevOps. CI/CD, pull-request, pre-commit, and push-protection scanning, plus custom detection rules, give teams several points to catch exposed secrets. Starter’s historical detection allowance is capped at 500, so it is a useful entry point rather than an unlimited historical audit.
  • Internal and public monitoring: Internal Secrets Monitoring searches code, CI/CD, and collaboration tools; Growth expands internal coverage to containers and custom sources. Public Secrets Monitoring focuses on exposed secrets on public GitHub. Growth limits that monitoring, while Enterprise makes it unlimited, a meaningful distinction for teams responsible for broad external exposure.
  • Developer CLI: The ggshield command-line tool scans for secrets during coding and supports pre-commit hooks. That places detection closer to developers, though the product’s broader value is in centralized monitoring rather than CLI use alone.
  • Remediation and administration: Growth includes remediation playbooks, AI risk scoring, false-positive filtering, and notifications through Slack, Teams, email, Jira, or ServiceNow. SAML 2.0 SSO, SCIM, IP allowlisting, and privacy mode support administration. These capabilities make Growth more suited to coordinated security operations than Starter.
  • Identity governance and deployment: Enterprise adds non-human identity governance, including vaults, identity mapping, and OWASP policies, along with self-hosted deployment through GitGuardian Bridge. Helm or KOTS deployment support gives organizations deployment options, but these features sit behind custom pricing.

Pricing

GitGuardian uses a freemium model and offers a 30-day trial. Starter costs 0.00 USD per free, billed Always, and supports up to 25 developers, unlimited real-time scanning, up to 500 historical scan detection, 10K API calls/month, and repository scan capacity of 1 GB. It is the practical choice for smaller teams beginning secret monitoring, but its developer, historical-scan, API, and repository limits constrain broader use.

Growth has custom pricing through sales contact. It includes everything in Starter, internal monitoring for code, CI/CD, containers, and custom sources, limited public monitoring, up to 10 teams, US and EU data hosting regions, and 12 GB repository scan capacity. The team cap and limited public coverage make it a better fit for organizations expanding internal controls than those needing unrestricted external monitoring.

Enterprise also has custom pricing and includes everything in Growth, unlimited public monitoring, NHI governance, self-hosted deployment, unlimited teams, 12-month audit log retention, and 60 GB repository scan capacity. It is the relevant tier for organizations with governance or deployment requirements that Starter and Growth do not cover. Enterprise includes a dedicated support channel; Premium Care is an add-on.

Platforms

GitGuardian supports API, Linux, macOS, self-hosted, web, and Windows environments. Its CLI and repository integrations suit development teams working across supported VCS providers; Enterprise self-hosting is the option for organizations that need the platform deployed in their own environment.

Who it's for

Application Security teams are the typical users of Internal Secrets Monitoring, while Threat Response teams commonly use Public Secrets Monitoring. GitGuardian is a strong fit when those functions need shared visibility across code and development workflows, or when an organization needs to govern non-human identities. A team looking only for a standalone local scanning tool may not need the wider platform or its sales-led tiers.

Pros and cons

  • Pros: Monitoring spans internal development workflows and public GitHub, with real-time and historical scanning across four supported VCS providers.
  • Pros: Starter is free and includes unlimited real-time scanning for up to 25 developers, giving a team a substantial starting allowance.
  • Pros: Enterprise combines NHI governance, self-hosting, unlimited teams, and unlimited public monitoring for organizations with broader security requirements.
  • Cons: Growth and Enterprise require sales contact for pricing, making budget comparison less direct.
  • Cons: Starter’s 500 historical detections, 10K API calls/month, and 1 GB repository scan capacity can restrict larger audits.
  • Cons: Public monitoring is limited on Growth; unlimited coverage requires Enterprise.

Alternatives

For a wider category comparison, browse Secrets Scanning Software. Choose ggshield when the priority is GitGuardian’s open-source CLI rather than the full platform. Consider Semgrep Code if a free code and supply-chain plan capped at 10 repositories and 10 contributors better matches the scope. Endor Labs offers a free Developer plan for individual developers using local scans via its AURI MCP server, without an account. Talisman is a free option for teams seeking MIT-licensed pre-commit and pre-push hooks with repository scanning. Kingfisher is a free and open-source alternative. TruffleHog has a free open-source plan with scanning for GitHub, S3, directories, GCS, and Docker, plus 800+ secret detectors. Augustus is a free Apache 2.0-licensed alternative. Vooda AI has a free self-hosted plan for production use at any company size with no seat limits.

Verdict

Choose GitGuardian if your organization needs secret detection spanning internal development workflows and public GitHub, with a route to NHI governance or self-hosting as requirements grow. The free Starter tier makes it possible to begin without a subscription, but its caps and the sales-led pricing for Growth and Enterprise are reasons to look elsewhere if you need predictable costs or only a focused local scanner.

GitGuardian plans and pricing

All plans
Starter Free Always Up to 25 devs · Unlimited real-time scanning · Up to 500 historical scan detection · 10K API calls/month gitguardian.com · 29 Sept 2026
Growth Not published Contact sales Everything in Starter · Internal monitoring for code, CI/CD, containers and custom sources · Limited public monitoring · Up to 10 teams · US and EU data hosting regions gitguardian.com · 29 Sept 2026
Enterprise Not published Custom; contact sales Everything in Growth · Unlimited public monitoring · NHI governance · Self-hosted deployment · Unlimited teams · 12-month audit log retention gitguardian.com · 29 Sept 2026

Compared on secrets scanning software

Free plan
Yesgitguardian.com
Supported VCS
GitHub, GitLab, Bitbucket, Azure DevOpsgitguardian.com
CI/CD scanning
Yesgitguardian.com
Pre-commit scanning
Yesgitguardian.com
Pull-request scanning
Yesgitguardian.com
Push protection
Yesgitguardian.com
Custom detection rules
Yesgitguardian.com

Facts

Purpose
GitGuardian protects enterprises against leaked secrets and mismanaged identities with secrets security, NHI governance, and AI agent security.gitguardian.com · 29 Sept 2026
Monitoring
Internal Secrets Monitoring finds leaks across code, CI/CD, and collaboration tools, while Public Secrets Monitoring catches secrets exposed on public GitHub.gitguardian.com · 29 Sept 2026
Detection
The product scans code repositories in real time and historically, and its CLI supports pre-commit hooks.gitguardian.com · 29 Sept 2026
Remediation
Pricing describes remediation playbooks, Slack, Jira, and ServiceNow integrations, AI risk scoring, and false-positive filtering in the Growth plan.gitguardian.com · 29 Sept 2026
NHI governance
Enterprise includes vaults, identity mapping, and OWASP policies for non-human identity governance.gitguardian.com · 29 Sept 2026
Integrations
The platform pricing page lists Slack, Teams, email, Jira, and ServiceNow as remediation notifiers.gitguardian.com · 29 Sept 2026
Access controls
The pricing comparison lists SSO using SAML 2.0 and SCIM, IP allowlisting, and privacy mode as platform administration capabilities.gitguardian.com · 29 Sept 2026
Self-hosting
Enterprise offers self-hosted deployment with GitGuardian Bridge, and the company describes Helm or KOTS deployment support.gitguardian.com · 29 Sept 2026
Support
Enterprise includes a dedicated support channel, while Premium Care is listed as an add-on.gitguardian.com · 29 Sept 2026
Limits
The pricing comparison lists repository scan capacities of 1 GB for Starter, 12 GB for Growth, and 60 GB for Enterprise.gitguardian.com · 29 Sept 2026
Developer CLI
GitGuardian CLI, called ggshield, provides secret scanning from the command line and supports developers during coding.gitguardian.com · 29 Sept 2026
Audience
The pricing FAQ says Public Secrets Monitoring is typically used by Threat Response and Internal Secrets Monitoring by Application Security.gitguardian.com · 29 Sept 2026

Company

Founded
2017gitguardian.com · 23 Sept 2026
Headquarters
Paris, Francegitguardian.com · 23 Sept 2026

Best GitGuardian alternatives

See all 20

Where it ranks on Everything Xiaomi

Is GitGuardian yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources