GitGuardian Platform vs Microsoft Purview Data Loss Prevention comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

GitGuardian Platform
Ranking in Data Loss Prevention (DLP)
6th
Average Rating
9.0
Number of Reviews
24
Ranking in other categories
Application Security Tools (7th), Static Application Security Testing (SAST) (6th), Software Supply Chain Security (4th), DevSecOps (4th)
Microsoft Purview Data Loss...
Ranking in Data Loss Prevention (DLP)
1st
Average Rating
8.0
Number of Reviews
13
Ranking in other categories
Microsoft Security Suite (12th)
 

Mindshare comparison

As of June 2024, in the Data Loss Prevention (DLP) category, the mindshare of GitGuardian Platform is 0.2%, down from 0.5% compared to the previous year. The mindshare of Microsoft Purview Data Loss Prevention is 27.8%, up from 23.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Data Loss Prevention (DLP)
Unique Categories:
Application Security Tools
0.3%
Static Application Security Testing (SAST)
0.3%
Microsoft Security Suite
1.9%
 

Featured Reviews

EE
Feb 29, 2024
They offer a free tier that provides full functionality for smaller teams
When we first deployed GitGuardian, we went back through all of the commits that we did over the course of the last five or six years that the company existed. It immediately found more than a hundred. We detected all sorts of secrets in those repositories. It had a pretty substantial impact from the first day. That was during our trial run, but now it's incorporated into our deployment pipelines. The impact is still there, and it's still tremendous. It's probably not as instantaneous or the same avalanche of detections that we saw on day one. That was impressive, but we don't get that anymore. It has been a constant trickle of tickets. GitGuardian helps us prioritize remediation. You need to incorporate it into your existing processes, but GitGuardian provides you with the flexibility and the tools. For example, in our environment, we implement ticket creation through webhooks. We have some logic rules stating that our production repositories are a higher priority than our dev or sandbox repositories. Our developers commit all sorts of weird things to those. GitGuardian gives you the tools to do that, but it may not necessarily do that right out of the box when you first deploy it. To have collaboration between our security and dev teams, you need to have a detection. Previously, we did not have a functional equivalent to GitGuardian in our environment, and it introduced that process, so we could begin having that conversation. The security team is more focused on remediating to ensure that API token or password is invalidated as soon as possible after it was committed. Developers are more focused on why the secret was committed and environment variables to store that particular secret. The collaboration exists in our company largely thanks to GitGuardian. A webhook creates a ticket in our internal ticketing system, and the ticket goes to the security guys. They look through it. They make sure the secret is invalidated and start that conversation with the developer to say that they committed this, so please don't do that again. That's the end of the story. We don't use 100 percent of GitGuardian's functionality. We are a fairly small company, so we probably don't need all of that. This simple approach works pretty well for a company of our size. GitGuardian has improved our security team's productivity if we measure it in security incidents per week, hour, etc. Now, we have a separate stream of secret detection tickets going into our system. It's much better to have those during the deployment phase instead of discovering them after a breach or down the road. It's hard to quantify the time saved. Finding a secret that was accidentally committed to a repo is like searching for a needle in a haystack. And you don't even know if the needle is in that haystack. Now you have something like X-ray vision that lets you see through that haystack and find right where the needle is. It unlocked a new angle on our application security process that did not exist. When a secret was accidentally committed to a repo, it could have been noticed by a security guy or another developer, or maybe not.
Bryan Sprowls - PeerSpot reviewer
Nov 28, 2023
An affordable and easily scalable tool that decreases the risk of data leakage in an organization
It is important to me that Purview delivers data protection across multi-cloud and multi-platform environments. Otherwise, we would have to have multiple DLP solutions. It is very important to me that the solution was built taking into account critical regulations from around the world. It makes it easier to templatize deployments for data loss prevention. I use the tool for data loss protection. The tool works fairly well in remediating policy violations. There could be a little bit of improvement in policy tips. Policy tips aren't consistent across different experiences. The tool has greatly impacted the visibility of most of our customers. Some of our customers didn't realize they had a lot of PII data being sent externally until after the tool was implemented. Later, they become more aware. The solution enables us to show our compliance as close to real-time as possible. It has affected our meetings with compliance regulators. We don't save time and money directly. The tool saves us time and money by saving on fines for regulatory compliance violations. Without the solution, one of our customers would have been fined about $2,500,000. It is important to me that the product can connect to iOS, Mac, and Android devices, as well as data in other SaaS apps. It's not a complete solution unless it can be used everywhere. We are implementers. People evaluating the product must understand the types of data and the compliance models they must adhere to. Overall, I rate the product an eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's also worth mentioning that GitGuardian is unique because they have a free tier that we've been using for the first twelve months. It provides full functionality for smaller teams. We're a smaller company and have never changed in size, but we got to the point where we felt the service brought us value, and we want to pay for it. We also wanted an SLA for technical support and whatnot, so we switched to a paid plan. Without that, they had a super-generous, free tier, and I was immensely impressed with it."
"GitGuardian Internal Monitoring has helped increase our secrets detection rate by several orders of magnitude. This is a hard metric to get. For example, if we knew what our secrets were and where they were, we wouldn't need GitGuardian or these types of solutions. There could be a million more secrets that GitGuardian doesn't detect, but it is basically impossible to find them by searching for them."
"GitGuardian has also helped us develop a security-minded culture. We're serious about shift left and getting better about code security. I think a lot of people are getting more mindful about what a secret is."
"What is particularly helpful is that having GitGuardian show that the code failed a check enables us to automatically pass the resolution to the author. We don't have to rely on the reviewer to assign it back to him or her. Letting the authors solve their own problems before they get to the reviewer has significantly improved visibility and reduced the remediation time from multiple days to minutes or hours. Given how time-consuming code reviews can be, it saves some of our more scarce resources."
"The secrets detection and alerting is the most important feature. We get alerted almost immediately after someone commits a secret. It has been very accurate, allowing us to jump on it right away, then figure out if we have something substantial that has been leaked or whether it is something that we don't have to worry about. This general main feature of the app is great."
"The entire GitGuardian solution is valuable. The product is doing its job and showing us many things. We get many false positives, but the ability to automatically display potential leaks when developers commit is valuable. The dashboards show you recent and historical commits, and we have a full scan that shows historical leaked secrets."
"Some of our teams have hundreds of repositories, so filtering by team saves a lot of time and effort."
"There is quite a lot to like. Its user interface is fantastic, and being able to sort the incidents by whether they are valid or for a certain repository or a certain user has been very beneficial in helping investigate what has been found."
"There's a good amount of documentation in case you run into any problems."
"I rate Microsoft Purview Data Loss Prevention's stability a ten out of ten."
"The auto-labeling feature is definitely the most valuable feature. It goes in and labels the documents for you in different repositories. It covers the Outlook and Exchange repositories along with SharePoint and OneDrive. It is really helpful in those areas."
"Microsoft Purview Data Loss Prevention's responses are faster. Its installation is also reliable. The security score helps with the security part."
"For Purview's natively integrated compliance across Azure, Dynamics 365, and Office 365, I would give it a 10 out of 10. It provides all the insights and information."
"The most valuable features are identifying sensitive data and issuing alerts."
"One of the valuable features of Purview is the ability to create a legal hold on a user's account within the compliance portal. That's pretty useful when it comes to any litigation or if you want to redeem the content within a mailbox, OneDrive, or a generic public SharePoint site."
"We can use Microsoft Purview Data Loss Prevention to manage devices and site policies."
 

Cons

"Other solutions have a live chat feature that provides instant results. Waiting for an agent to reply to an email is less ideal than an instant conversation with a support employee. That's a complaint so minor I almost hesitate to mention it."
"We have encountered occasional difficulties with the Single Sign-On process."
"An area for improvement is the front end for incidents. The user experience in this area could be much better."
"There is room for improvement in GitGuardian on Azure DevOps. The implementation is a bit hard there. This is one of the things we requested help with. I would not say their support is not good, but they need them to improve in helping customers on that side."
"There are some features that are lacking in GitGuardian. The more we grow and the more engineers we have, the more it will become difficult to assign an incident because the assignment is not automatic. I know they are working on that and we are waiting for it."
"There is room for improvement in its integration for bug-tracking. It should be more direct. They have invested a lot in user management, but they need to invest in integrations. That is a real lack."
"We'd like to request a new GitGuardian feature that automates user onboarding and access control for code repositories."
"It took us a while to get new patterns introduced into the pattern reporting process."
"Microsoft Purview Data Loss Prevention's licensing is expensive."
"The scalability, in terms of the portal, could be more user-friendly. Sometimes I have faced difficulties in identifying the options."
"The platform can be challenging to navigate and has the potential for improvement."
"The AI advancements can improve the false positives."
"There is a need for improvements, particularly in ensuring that file-based recognition is more reliable and comprehensive."
"Technical support is awful."
"There is no AIP for Linux systems. That's a setback. Another thing it's lacking is libraries to work with Python. It has libraries for C# and C++, for example, but not for Python and, these days, Python is very useful."
"They do not provide language options beyond the ones already available, so our language option is missing."
 

Pricing and Cost Advice

"It could be cheaper. When GitHub secrets monitoring solution goes to general access and general availability, GitGuardian might be in a little bit of trouble from the competition, and maybe then they might lower their prices. The GitGuardian solution is great. I'm just concerned that they're not GitHub."
"The internal side is cheap per user. It is annual pricing based on the number of users."
"It's a little bit expensive."
"I am only aware of the base price. I do not know what happened with our purchasing team in discussions with GitGuardian. I was not privy to the overall contract, but in terms of the base MSRP price, I found it reasonable."
"We have seen a return on investment. The amount of time that we would have spent manually doing this definitely outpaces the cost of GitGuardian. It is saving us about $35,000 a year, so I would say the ROI is about $20,000 a year."
"The pricing for GitGuardian is fair."
"With GitGuardian, we didn't need any middlemen."
"We don't have a huge number of users, but its yearly rate was quite reasonable when compared to other per-seat solutions that we looked at... Having a free plan for a small number of users was really great. If you're a small team, I don't see why you wouldn't want to get started with it."
"It's a little bit pricey compared to competitors, but it's not too high."
"It is a part of our Microsoft licensing. We pay for a yearly renewal. Its price is reasonable for the size of the organization we are. It is fairly competitive, and you get what you pay for. We have an E5 license, and a part of understanding the E5 license is to see what all you get with it. If you really look at it from that standpoint, you get a lot of value. You have Defender and all its security features in there as well. Their licensing is fairly flexible. They have different programs. We've seen ones where you could pay for up to three to five years in advance. There is also a monthly pay-as-you-go type of deal, but we're doing a yearly renewal and fixing the budget."
"I am satisfied with the tool's pricing."
"The pricing is reasonable."
"We are using the E3 license for Microsoft 365 with the E5 compliance license add-on."
"Microsoft Purview Data Loss Prevention is part of a bundle and is not sold as a standalone product."
"The product has the best price-to-performance ratio."
report
Use our free recommendation engine to learn which Data Loss Prevention (DLP) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
21%
Computer Software Company
15%
Media Company
8%
Financial Services Firm
8%
Financial Services Firm
17%
Computer Software Company
13%
Manufacturing Company
10%
Retailer
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about GitGuardian Internal Monitoring ?
It's also worth mentioning that GitGuardian is unique because they have a free tier that we've been using for the first twelve months. It provides full functionality for smaller teams. We're a smal...
What needs improvement with GitGuardian Internal Monitoring ?
We'd like to request a new GitGuardian feature that automates user onboarding and access control for code repositories. Ideally, when a user contributes to a repository, they would be automatically...
What do you like most about Microsoft Purview Data Loss Prevention?
The most valuable features are identifying sensitive data and issuing alerts.
What needs improvement with Microsoft Purview Data Loss Prevention?
The Endpoint DLP engine has a lot of delays. The just-in-time protection feature does not always work as expected, mainly when working with network files in a more classic environment.
 

Also Known As

GitGuardian Internal Monitoring
Microsoft Endpoint Data Loss Prevention, MS Endpoint DLP, Microsoft Endpoint DLP
 

Overview

 

Sample Customers

Automox, 66degrees (ex Cloudbakers), Iress, Now:Pensions, Payfit, Orange, BouyguesTelecom, Seequent, Stedi, Talend, Snowflake... 
Information Not Available
Find out what your peers are saying about GitGuardian Platform vs. Microsoft Purview Data Loss Prevention and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.