GitGuardian

Find every credential. Stop the next breach.

Also known as
gitguardian

What is GitGuardian?

Secrets Security and Non-Human Identity Governance platform that finds, fixes, and prevents hardcoded secrets across development environments and protects against credential-based attacks.

Independently observed

GitGuardian pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
SubscriptionFree tier

Free tier available. Growth and Enterprise plans require contact/demo.

Starter

Free
Free

For individuals and teams up to 25 developers

devs
25
historical_scans
500
api_calls_monthly
10K
  • Internal Secrets Monitoring
  • Unlimited real-time scanning
  • GitHub, Azure Repos, GitLab, Bitbucket support
  • 550+ specific detectors
  • Automated severity scoring

Growth

Custom pricing – free trial available

For teams up to 500 developers

devs
500
  • Internal secrets monitoring: code, CI/CD, containers, custom
  • Public secrets monitoring (limited)
  • Endpoint protection for developer machines
  • Remediation playbooks
  • Slack, Jira, ServiceNow integrations
  • AI risk scoring and false-positive filtering
  • SSO (SAML 2.0) + SCIM
  • Up to 10 teams
  • US and EU data hosting regions

Enterprise

Contact sales
Contact sales
min 500 seats

For 500+ developer organizations

  • Public secrets monitoring (unlimited)
  • NHI governance: vaults, identity mapping, OWASP policies
  • Endpoint protection: developer + standard endpoints
  • Corporate and enterprise data sources integration
  • Self-hosted deployment + GitGuardian Bridge
  • Unlimited teams and custom RBAC
  • Custom detectors
  • 12-month audit log retention
  • Premium Care support (add-on)

Add-ons

  • Endpoint Protection
  • Extra endpoints
  • Premium Care

What GitGuardian does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
DAST (dynamic analysis)
SCA / dependency scanning
Secret scanning
Container / image scanning
IaC misconfiguration scanning
Governance
OSS licence compliance
SBOM generation (SPDX/CycloneDX)
Remediation
Automated fix / upgrade PRs
Prioritisation
Reachability / exploitability prioritisation
Deployment
Hosting
Cloud + self-hosted
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
Licensing
OSS engine available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (8)

Independently observed
  • Slack
  • Jira
  • ServiceNow
  • GitHub
  • Azure Repos
  • GitLab
  • Bitbucket
  • Docker

GitGuardian alternatives

Other devsecops tools we track, ranked by the same independent score.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for GitGuardian, not the verdict.

Balanced composite 65 / 100
medium · 60%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security Posture9040.003600.0
Reliability5018.00900.0
Capabilities6712.00805.4
Price Level808.00640.0
Integrations2712.00329.3
Pricing Transparency2510.00250.0

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Features

AttributeValueEvidence
Capabilities{"sca":false,"dast":false,"sast":false,"sbom":false,"hosting":"both","ci_native":true,"ide_plugin":false,"auto_fix_pr":false,"open_source":false,"iac_scanning":false,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":false}mediumsource · 2026-08-01 · 60%

Integrations

AttributeValueEvidence
Count8mediumsource · 2026-08-01 · 60%

Pricing

AttributeValueEvidence
Free tierYeslowsource · 2026-08-01 · 48%
Modelfreemiumhighsource · 2026-08-01 · 80%
Price levellowmediumsource · 2026-08-01 · 60%
TransparentNomediumsource · 2026-08-01 · 60%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-01 · 60%

Security

AttributeValueEvidence
GdprYeshighsource · 2026-08-01 · 75%
Iso27001Yeslowsource · 2026-08-01 · 48%
PciYeshighsource · 2026-08-01 · 75%
Soc2Yeslowsource · 2026-08-01 · 48%
Disclosure policyYesmediumsource · 2026-08-01 · 60%