GitGuardian is a comprehensive platform focused on enhancing Non-Human Identity security by integrating Secrets Security and Secrets Observability to detect and manage secrets across development environments.


| Product | Market Share (%) |
|---|---|
| GitGuardian Platform | 0.3% |
| Astrix | 27.1% |
| Oasis | 24.7% |
| Other | 47.9% |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| SonarQube Server (formerly SonarQube) | 4.0 | N/A | 81% | 117 interviewsAdd to research |
| Snyk | 4.0 | N/A | 100% | 49 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 8 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 160 |
| Midsize Enterprise | 40 |
| Large Enterprise | 182 |
As cybersecurity threats increasingly target NHIs like service accounts and applications, GitGuardian offers a robust solution by supporting over 450 types of secrets and deploying honeytokens for additional defense. Trusted by leading organizations and developers, its monitoring and quick alert system enable effective detection and management of sensitive data, strengthening operational security across platforms.
What are the key features of GitGuardian?In the tech industry, GitGuardian is employed to safeguard APIs and sensitive credentials across code repositories like GitHub. Companies benefit from instant alerts and integrations with tools like Slack, effectively managing risks and enhancing security policies. While popular in sectors dependent on development agility, there is room for further improvement in customization and integration to meet specific industry needs.
GitGuardian Platform was previously known as GitGuardian Internal Monitoring, GitGuardian Public Monitoring.
Widely adopted by developer communities, GitGuardian is used by over 600 thousand developers and leading companies, including Snowflake, Orange, Iress, Mirantis, Maven Wave, ING, BASF, and Bouygues Telecom.
| Author info | Rating | Review Summary |
|---|---|---|
| DevOps Engineer at Deuna App | 5.0 | I use the GitGuardian Platform for application security to detect secrets in real time, significantly enhancing data security. Although documentation visibility needs improvement, the platform saves time and resources, outperforming alternatives like GitHub Advanced Security and Cycode. |
| Senior Manager, Product Security at DigitalOcean | 4.0 | We use GitGuardian Platform to prevent secret exposures effectively. Its self-healing playbook automatically engages developers, resolving issues swiftly. However, analytics could improve to better reflect these developer activities. The platform saves us significant time weekly compared to competitors. |
| Head of Engineering Services at IRESS | 4.5 | We use GitGuardian with GitHub to detect code secrets, appreciating its detail, instant Slack notifications, and pre-push hooks. While its alerts and metrics need improvement, its detection surpasses alternatives like TruffleHog, providing reassurance about our code's security. |
| Director, Corporate Security Operations at a tech vendor with 5,001-10,000 employees | 4.0 | I use GitGuardian Platform to monitor code repositories for secrets, appreciating its real-time detection and custom detectors. However, it generates false positives and lacks certain features. I haven't found alternatives integrating across multiple repositories as effectively. |
| DevOps Engineer at a manufacturing company with 10,001+ employees | 4.5 | I've used GitGuardian for securing our enterprise repositories, and it's improved our workflow with strong detection, seamless integration, and helpful audit tools. While we wish for custom detectors, overall it's stable, scalable, and easy to deploy. |
| Senior DevOps Engineer | 3.5 | I've used GitGuardian Public Monitoring for nearly two years to detect exposed secrets in our GitHub repos; it's easy to deploy, works well, but could improve by adding code analysis and distinguishing real from mock credentials. |
| Head of Development at Inhabit | 5.0 | We use GitGuardian for internal security monitoring, identifying and removing secrets from our repositories, and enhancing codebase security. Its valuable features, like team filtering and incident management, exceed competitors. However, improved reporting and smoother Single Sign-On are needed. |
| Application Security Engineer at a energy/utilities company with 10,001+ employees | 4.5 | I use GitGuardian Public Monitoring to detect exposed code publicly. The Explore function is valuable, and I appreciate critical issue alerts via email. I'm interested in potential Postman scanning integration and honeytokens to enhance security measures. |