GitGuardian

Detect and prevent credential exposure across your code and infrastructure

Also known as
gitguardian

Available worldwide · Popular in: US, EU

What is GitGuardian?

A platform that scans code repositories, CI/CD pipelines, containers, and infrastructure for exposed credentials and machine identities, providing real-time detection with automated remediation and incident management workflows.

Independently observed

GitGuardian pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
SubscriptionFree tier

Free tier available. Paid tiers (Growth, Enterprise) pricing available upon request.

Free

Free
Free

Community plan with core scanning capabilities

api_calls
10k/month
repository_size
12 GB
historical_scans
500
  • Unlimited real-time scanning
  • Internal secrets monitoring
  • Public secrets monitoring (limited)
  • Slack, Jira, ServiceNow integrations
  • SSO (SAML 2.0) + SCIM
  • US and EU data hosting regions

Growth

Contact sales
Contact sales

Starter plan for teams scaling secrets governance with dedicated support

  • Internal secrets monitoring across code, CI/CD, container registries
  • Public secrets monitoring (limited)
  • Remediation playbooks and notifiers
  • SSO (SAML 2.0) + SCIM, IP allowlisting, privacy mode
  • Dedicated Customer Success Manager

Enterprise

Contact sales
Contact sales

Advanced plan for complex environments with NHI governance and self-hosted options

  • NHI Governance with vault coverage and identity inventory
  • AI-powered remediation with Smart Routing
  • Enterprise data sources including file storage and CI logs
  • Self-hosted deployment (Helm or KOTS)
  • 12-month audit log retention
  • Honeytoken for preemptive threat detection

Add-ons

  • Developer Endpoint Protection

What GitGuardian does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
DAST (dynamic analysis)
-
SCA / dependency scanning
Secret scanning
Container / image scanning
IaC misconfiguration scanning
-
Governance
OSS licence compliance
-
SBOM generation (SPDX/CycloneDX)
-
Remediation
Automated fix / upgrade PRs
Prioritisation
Reachability / exploitability prioritisation
Deployment
Hosting
Cloud + self-hosted
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
Licensing
OSS engine available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (22)

Independently observed
iam
  • AWS IAM
  • Azure Entra ID
ide
  • Cursor
  • Claude Code
  • GitHub Copilot
  • Windsurf
  • Google Gemini CLI
  • GitHub
  • GitHub Enterprise Server
  • GitLab
  • Bitbucket
  • Azure Repos
  • Azure DevOps
  • Jira
  • Slack
  • ServiceNow
  • Confluence
  • Docker
  • Container registries
  • HashiCorp Vault
  • CyberArk
  • AWS Secrets Manager

GitGuardian FAQ

Common questions about GitGuardian, answered from independent, dated evidence.

What is GitGuardian?

A platform that scans code repositories, CI/CD pipelines, containers, and infrastructure for exposed credentials and machine identities, providing real-time detection with automated remediation and incident management workflows. It is indexed under DevSecOps Tools.

Source: https://www.gitguardian.com/pricing

How much does GitGuardian cost?

GitGuardian does not publish its prices. Pricing is quoted on request, across 3 plans (Free, Growth and Enterprise), so the figure depends on your seat count and requirements. We record this as a pricing-transparency signal rather than guessing a number. Pricing changes often, so verify at source before relying on it.

Source: https://www.gitguardian.com/pricing

What platforms does GitGuardian support?

GitGuardian supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://www.gitguardian.com/pricing

Can GitGuardian be self-hosted?

Yes. GitGuardian can be deployed cloud / SaaS and self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://www.gitguardian.com/pricing

What does GitGuardian integrate with?

We have confirmed 20 integrations for GitGuardian, including GitHub, GitLab, Bitbucket, Azure Repos, Azure DevOps, Jira, Slack and ServiceNow, plus 12 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://www.gitguardian.com/pricing

What security certifications does GitGuardian have?

We have independently confirmed SOC 2, ISO 27001 and GDPR for GitGuardian. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as GitGuardian not holding them. Always confirm compliance directly before you rely on it.

Source: https://www.gitguardian.com/security-engineers

Where is GitGuardian available?

GitGuardian is available worldwide. Its primary markets are the United States and the EU.

Source: https://www.gitguardian.com/pricing

GitGuardian alternatives

Other devsecops tools we track, ranked by the same independent score.

All GitGuardian alternatives, ranked →

Compare GitGuardian

Side by side against other devsecops tools, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for GitGuardian, not the verdict.

Balanced composite 70 / 100
medium · 72%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security posture900.2118.8
Capabilities960.054.9
Reliability500.094.7
Price level800.043.4
Integrations370.051.9
Pricing transparency250.051.3

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Content

AttributeValueEvidence
Faq7 itemsmediumsource · 2026-09-10 · 60%

Features

AttributeValueEvidence
CapabilitiesSca: Yes · Sast: Yes · Hosting: both · Ci native: Yes · Ide plugin: Yes · Auto fix pr: Yesmediumsource · 2026-09-04 · 60%

Integrations

AttributeValueEvidence
Count18mediumsource · 2026-09-04 · 60%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-09-04 · 75%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-09-04 · 60%
Modelfreemiummediumsource · 2026-09-04 · 60%
Price levellowmediumsource · 2026-09-04 · 60%
TransparentNomediumsource · 2026-09-04 · 60%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-01 · 60%

Security

AttributeValueEvidence
GdprYeshighsource · 2026-08-01 · 75%
Iso27001Yeslowsource · 2026-08-01 · 48%
PciYeshighsource · 2026-08-01 · 75%
Soc2Yeshighsource · 2026-08-14 · 75%
Disclosure policyYesmediumsource · 2026-08-01 · 60%
Trust centerhttps://www.gitguardian.com/videos/security-automation-and-leveraging-ai-to-deal-with-security-at-scale-huxley-barbeemediumsource · 2026-09-04 · 60%
Still deciding?

Is GitGuardian the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank GitGuardian against the rest of the devsecops tools we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of GitGuardian

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves GitGuardian up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows GitGuardian's independent score and links back to this profile.

GitGuardian, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/gitguardian" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/gitguardian.svg" alt="GitGuardian, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![GitGuardian, verified on vioscaleAI](https://www.vioscale.ai/badge/software/gitguardian.svg)](https://www.vioscale.ai/software/gitguardian)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing GitGuardian. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim GitGuardian

Not the owner? How vendor profiles work