GitGuardian Platform and Trellix DLP compete in security and data loss prevention. GitGuardian appears to have the upper hand due to its specialized secret detection and developer-focused integrations.
Features: GitGuardian Platform offers secret detection and remediation with integrations into developer tools, high detection accuracy, and the "Dev in the loop" feature for quick remediation. Its pre-commit hooks also provide real-time feedback, enhancing development processes. Trellix DLP focuses on comprehensive data protection with endpoint security, emission control, and network blocking, but lacks specialized integrations for secret detection.
Room for Improvement: GitGuardian could benefit from more customization options, improved integration support, and better management of false positives, especially for specific identifiers and logs. Users also desire automation in feedback and historical scanning. Trellix DLP struggles with a complex user interface, lack of MacOS and Linux support, and limited browser compatibility, requiring significant training for virtualization and improved customer support responsiveness.
Ease of Deployment and Customer Service: GitGuardian offers flexible deployment options for on-premises and cloud environments, with highly regarded customer service and direct communication channels. Trellix DLP supports primarily on-premises deployment and some hybrid cloud but is criticized for its complicated setup process and less responsive customer service.
Pricing and ROI: GitGuardian's pricing is seen as reasonable due to its comprehensive secret detection capabilities, with demonstrated ROI from faster remediation and reduced exposure risk. It offers a free tier for smaller teams. Trellix DLP provides per-node pricing but is considered expensive by some users, with ROI less direct, focusing on general data protection benefits.
I can certainly say that we have saved significant time and resources in terms of people and automation.
The majority of our incidents for critical detectors and important secret types are remediated automatically or proactively by developers through GitGuardian's notification system, without security team involvement.
The benefits our customers see from using Trellix DLP include cost reduction, given its competitive pricing in India.
I would rate their technical support a nine out of ten.
I would rate the technical support as excellent.
We received prompt technical support and remote sessions when necessary.
Trellix's technical support deserves a perfect rating, and I would rate it ten out of ten compared to other solutions.
The support from both the vendor and Trellix is excellent.
In terms of scalability, I would rate it around a ten out of ten, as it handles all the repositories and commit activity we have.
I would rate it a ten out of ten for scalability.
Currently, what GitGuardian Platform is doing works effectively.
Trellix DLP is very scalable, especially with the cloud version as everything is managed in the cloud.
It's a bit of a fallback, and I know they are working on improving scalability.
I would rate the scalability of Trellix DLP between eight to nine out of ten.
We set up a lot of the repository, so GitGuardian is a required check.
The SaaS platform has experienced two significant moments of downtime or instability in the last six months, requiring notices and retrospectives.
I would rate the stability of the GitGuardian Platform as excellent with no downtimes.
With the move to cloud provisioning, that is not a big problem anymore due to scalability on Trellix's side.
The agents are the main issue as they can behave inconsistently across different versions of operating systems.
Product stability is not a major concern; I would rate it 99% stable.
Another thing that would be good to see is some more metrics on the usage of the GitGuardian pre-push hooks.
The self-healing activity by developers isn't reflected in the analytics, requiring us to collect this data ourselves.
We are looking for better metrics and audit data, wanting more features such as knowing which users are creating the most secrets or committing the most secrets, what repository, what directory, and who is not checking in secrets.
Having someone within a region who understands the countries and how they approach data and information security is sometimes where the problem lies.
Improved compatibility with Mac OS is needed due to ineffective policy applications.
The product also faces challenges with high CPU and memory utilization, impacting endpoint performance.
Overall, the secret detection sector is expensive, but we are happy with the value we get.
It's fairly priced, as it performs a lot of analysis and is a valuable tool.
It used to be in the middle, tending towards the high end, especially in South Africa, where we need to convert from dollars to rands, making things very expensive quickly.
The solution is currently affordable and not considered expensive.
One of the best features of the solution is the ability to use pre-push hooks.
A high number of our exposures are remediated by developers before security needs to step in, as the self-healing playbook process engages them automatically.
GitGuardian Platform performs the capability to detect secrets in real time exceptionally, as it activates from the commit and can detect it immediately.
Trellix products are manageable through a centralized control center, meeting requirements from frameworks like PCI DSS.
Additionally, it supports integration with third-party solutions and agents, providing a versatile and user-friendly management experience.
These features are very useful for protecting company confidential data from being copied to another remote location or other sites.
GitGuardian helps organizations detect and fix vulnerabilities in source code at every step of the software development lifecycle. With GitGuardian’s policy engine, security teams can monitor and enforce rules across their VCS, DevOps tools, and infrastructure-as-code configurations.
Widely adopted by developer communities, GitGuardian is used by more than 500,000 developers and is the #1 app in the security category on the GitHub Marketplace. GitGuardian is also trusted by leading companies, including Instacart, Genesys, Orange, Iress, Beyond Identity, NOW: Pensions, and Stedi.
GitGuardian Platform includes automated secrets detection and remediation. By reducing the risks of secrets exposure across the SDLC, GitGuardian helps software-driven organizations strengthen their security posture and comply with frameworks and standards.
Its detection engine is trained against more than a billion public GitHub commits every year, and it covers 350+ types of secrets such as API keys, database connection strings, private keys, certificates, and more.
GitGuardian brings security and development teams together with automated remediation playbooks and collaboration features to resolve incidents fast and in full. By pulling developers closer to the remediation process, organizations can achieve higher incident closing rates and shorter fix times.
The platform integrates across the DevOps toolchain, including native support for continuously scanning VCS platforms like GitHub, Gitlab, Azure DevOps and Bitbucket or CI/CD tools like Jenkins, CircleCI, Travis CI, GitLab pipelines, and many more. It also integrates with ticketing and messaging systems like Splunk, PagerDuty, Jira and Slack to support teams with their incident remediation workflows. GitGuardian is offered as a SaaS platform but can also be hosted on-premise for organizations operating in highly regulated industries or with strict data privacy requirements.
Trellix DLP is the ultimate data loss prevention (DLP) solution, safeguarding organizations' sensitive data from unauthorized access, disclosure, or alteration. This robust system monitors and regulates data flows across networks, emails, and the web, identifying and shielding various data types such as financial, personal, intellectual property, and regulated data. Employing encryption, access control, DLP policies, and monitoring, it secures data both at rest and in transit, ensuring compliance with data security regulations and industry standards. With customizable deployment options, including on-premises, cloud-based, and hybrid, Trellix DLP offers comprehensive protection and rapid response to data loss incidents.
We monitor all Data Loss Prevention (DLP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.