

JFrog Xray and GitGuardian Platform are competing products in the security domain. GitGuardian seems to have the upper hand due to its advanced monitoring capabilities and superior data exposure detection features.
Features: JFrog Xray integrates deeply with CI/CD pipelines, offers comprehensive binary scanning, and robust reporting options. It provides strong support for multiple package management systems and tight integration with Artifactory. GitGuardian excels in secret detection, real-time updates, and provides a wide coverage of different secret types across multiple environments, making it efficient in alerting and remediation.
Room for Improvement: JFrog Xray could enhance its vulnerability prioritization and expand its scanning depth into non-supported file types. Its dependency tree visualization might benefit from more clarity and user-friendliness. Additionally, the learning curve could be reduced to facilitate easier use. GitGuardian could improve by further reducing false positives and providing more granular control over alert types. Enhanced customization options for alert management and better historical review capabilities would be advantageous.
Ease of Deployment and Customer Service: JFrog Xray offers a flexible deployment model with smooth integration into various environments supported by a responsive support network. GitGuardian provides a straightforward deployment process and is noted for exceptional responsiveness and expertise in customer service. The advantage lies slightly with GitGuardian due to its ease of integration and superior customer service.
Pricing and ROI: JFrog Xray offers competitive pricing with flexible plans that deliver significant ROI through efficiency improvements and reduced manual work. GitGuardian, while perceived as more expensive, provides substantial ROI by preventing costly security breaches. GitGuardian's value proposition justifies its higher initial costs, making it a valuable investment.
I can certainly say that we have saved significant time and resources in terms of people and automation.
The majority of our incidents for critical detectors and important secret types are remediated automatically or proactively by developers through GitGuardian's notification system, without security team involvement.
It has reduced manual effort, allowed for faster detection within seconds, and decreased the risk of credential leaks, which directly improves security and saves time for both SOC and developer teams.
It effectively helps us with credentials security and has been performing satisfactorily.
I would rate their technical support a nine out of ten.
I would rate the technical support as excellent.
When we need clarifications, we contact our account manager, and they arrange demos.
On a scale of 1 to 10, I would rate the technical support of JFrog Xray an eight because they are very knowledgeable.
In terms of scalability, I would rate it around a ten out of ten, as it handles all the repositories and commit activity we have.
I would rate it a ten out of ten for scalability.
GitGuardian Platform is highly scalable and can be deployed and integrated according to our requirements and pricing budget.
According to my use case, it is highly scalable.
We set up a lot of the repository, so GitGuardian is a required check.
The SaaS platform has experienced two significant moments of downtime or instability in the last six months, requiring notices and retrospectives.
I would rate the stability of the GitGuardian Platform as excellent with no downtimes.
I use JFrog Xray primarily for security purposes, and I find it reliable.
We did experience crashes, downtimes, and performance issues with JFrog Xray.
Another thing that would be good to see is some more metrics on the usage of the GitGuardian pre-push hooks.
The self-healing activity by developers isn't reflected in the analytics, requiring us to collect this data ourselves.
We are looking for better metrics and audit data, wanting more features such as knowing which users are creating the most secrets or committing the most secrets, what repository, what directory, and who is not checking in secrets.
When we have given a very long tag, it doesn't work as expected and requires excessive scrolling.
somehow you need to adapt your GitLab pipeline and turn them into JFrog pipeline, and this is something they don't really advertise at first—you're obliged to use the JFrog CLI.
X-ray needs improvement in supporting more than one database, as it currently only supports PostgreSQL.
Overall, the secret detection sector is expensive, but we are happy with the value we get.
It's fairly priced, as it performs a lot of analysis and is a valuable tool.
My personal feeling about the pricing of GitGuardian Platform is that it is higher compared to free tools such as GitLeaks.
JFrog Xray provides a free trial of 14 days.
The basic scanning capabilities come with Artifactory, however, curation requires additional licenses.
One of the best features of the solution is the ability to use pre-push hooks.
A high number of our exposures are remediated by developers before security needs to step in, as the self-healing playbook process engages them automatically.
GitGuardian Platform performs the capability to detect secrets in real time exceptionally, as it activates from the commit and can detect it immediately.
The most valuable features of JFrog Xray are its curation capabilities, its native integration with Artifactory, scanning for vulnerabilities, and license compliance features.
The policy-driven approach of JFrog Xray helped me maintain security standards by integrating it in the development pipeline.
With other registries such as ECR, we can use the images only in the AWS cloud. With JFrog, we can use this registry from any cloud or work locally as well.
| Product | Mindshare (%) |
|---|---|
| GitGuardian Platform | 3.3% |
| Astrix | 13.2% |
| Oasis | 11.0% |
| Other | 72.5% |
| Product | Mindshare (%) |
|---|---|
| JFrog Xray | 1.3% |
| Wiz | 5.5% |
| Qualys VMDR | 4.4% |
| Other | 88.8% |


| Company Size | Count |
|---|---|
| Small Business | 11 |
| Midsize Enterprise | 9 |
| Large Enterprise | 16 |
| Company Size | Count |
|---|---|
| Small Business | 1 |
| Midsize Enterprise | 3 |
| Large Enterprise | 6 |
GitGuardian is a comprehensive platform focused on enhancing Non-Human Identity security by integrating Secrets Security and Secrets Observability to detect and manage secrets across development environments.
As cybersecurity threats increasingly target NHIs like service accounts and applications, GitGuardian offers a robust solution by supporting over 450 types of secrets and deploying honeytokens for additional defense. Trusted by leading organizations and developers, its monitoring and quick alert system enable effective detection and management of sensitive data, strengthening operational security across platforms.
What are the key features of GitGuardian?
What benefits and ROI should companies consider?
In the tech industry, GitGuardian is employed to safeguard APIs and sensitive credentials across code repositories like GitHub. Companies benefit from instant alerts and integrations with tools like Slack, effectively managing risks and enhancing security policies. While popular in sectors dependent on development agility, there is room for further improvement in customization and integration to meet specific industry needs.
JFrog is on a mission to enable continuous updates through Liquid Software, empowering developers to code high-quality applications that securely flow to end-users with zero downtime. The world’s top brands such as Amazon, Facebook, Google, Netflix, Uber, VMware, and Spotify are among the 4500 companies that already depend on JFrog to manage binaries for their mission-critical applications. JFrog is a privately-held, global company, and is a proud sponsor of the Cloud Native Computing Foundation [CNCF].
If you are a team player and you care and you play to WIN, we have just the job you're looking for.
As we say at JFrog: "Once You Leap Forward You Won't Go Back!"
We monitor all Non-Human Identity Management (NHIM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.