🔒🤖 NEW PRODUCT! Get full control of your Non-Human Identities

DISCOVER

🔒🤖 NEW PRODUCT! Get full control of your Non-Human Identities

DISCOVER

GitGuardian Pricing

free

Starter

For individuals or up to 25 devs

$0

Always
No credit card required
Get Started
Secrets Detection Logo

free Plan also includes:

5 honeytokens

Up to 25 devs

Unlimited real-time scanning

Up to 500 historical scan detection

Business

Teams

Recommended for teams up to 200 devs

$220

/year
per developer
Start Trial
Secrets Detection Logo
ADD-ONS

everything in free Plan, plus:

Up to 20 teams

Remediation playbooks

Scan developers collaboration tools

Enterprise

Custom

Recommended for 200+ dev teams

Let’s Talk

Contact Sales
Products available
Secrets Detection Logo

everything in business Plan, plus:

Self-hosted deployment

Unlimited teams

Unlimited API quota calls

Scan Git repository up to 60Gb

Unlimited custom detectors

Dedicated support channel

#1 app on the GitHub marketplace

Trusted by security leaders at the world’s largest companies

All GitGuardian Products

Non-Human Identity Security
SECRETS SECURITY

Secrets Detection

Scan and fix hardcoded secrets.

Learn more

Public Monitoring

We catch the leaks, you stop the intrusions.

Learn more

Honeytoken

Detect intruders before it's too late with fake secrets.

Learn more
nhi Governance

NHI Governance

Get full control and visibility of your Non-Human Identities.

Learn more
Hide platform plan details
Dropdown Arrow
Secrets detection logo

Secrets Detection

Dropdown Arrow

Sources

Business

Start trial

Enterprise

Book a demo

Application source code, Docker images

++

++

++

Git repositories max scanning size

1 Gb

12 Gb

60 Gb

Scan developers collaboration tools

--

Ticketing, Documentation, Messaging, Container Registries

Ticketing, Documentation, Messaging, Container Registries

Historical scan

500

Unlimited

Unlimited

SDLC stages

Business

Start trial

Enterprise

Book a demo

Multi-VCS support
GitHub, Azure Repos, GitLab, Bitbucket

++

++

++

GitHub Enterprise server

--

++

++

Developer workstations scan - Git hooks

++

++

++

Pull requests - GitHub only

++

++

++

Detection

Business

Start trial

Enterprise

Book a demo

Specific detectors (%ndet%+)

++

++

++

Generic detectors (%ngdet%+)

++

++

++

Custom detectors - REGEX based

--

++

1 detector included

++

Unlimited detectors

Validity and presence checks (periodicity)

Low frequency

High frequency

High frequency

Remediation

Business

Start trial

Enterprise

Book a demo

Automated severity scoring
(context-based)

--

++

Built-in rules only

++

Built-in and custom

End-to-end mapping (Sources, scope, leaks)

--

--

++

Developer-in-the-loop
(feedback and resolution)

++

++

++

Remediation tracking

++

++

++

Remediation playbooks

++

Only some playbooks

++

++

Remediation guidelines
for developers

++

Default and custom

++

Default and custom

++

Default and custom

Secrets managers integrations

--

++

++

Push-to-vault

--

--

++

Prevention

Business

Start trial

Enterprise

Book a demo

GitGuardian CLI ggshield
(in pre-commit hooks)

++

++

++

VScode extension

++

++

++

Public Monitoring

Dropdown Arrow

Support

Business

Start trial

Enterprise

Book a demo

Official open-source repositories

--

--

++

Public personal repos of developers and subcontractors

--

--

++

Regular update of this perimeter

--

--

++

Detection

Business

Start trial

Enterprise

Book a demo

Real-time monitoring of GitHub repos

--

--

++

Scan 6 years of past contributions 

(Even if deleted or made private)

--

--

++

Specific and generic secrets detection

--

--

++

Keyword detection specific to your organization

--

--

++

Built-in validity and presence checks

--

--

++

Advanced contextual analysis that enhances precision & recall

--

--

++

Post-detection insights

--

--

++

Audit logs

--

--

++

Real-time alerting

Business

Start trial

Enterprise

Book a demo

Notifications via configured channels (Jira, Slack, etc.)

--

--

++

Alerts on events
(severity updates, notes, etc.)

--

--

++

Emails for new incidents, public events etc

--

--

++

Threat hunting

Business

Start trial

Enterprise

Book a demo

Search Public GitHub with regex and full-text queries and scan results for secrets

--

--

++

Deployment

Business

Start trial

Enterprise

Book a demo

SaaS

--

--

++

Authn/Authz

Business

Start trial

Enterprise

Book a demo

SSO login with SAML 2.0 or SCIM

--

--

++

Roles & permissions

--

--

++

API

Business

Start trial

Enterprise

Book a demo

REST API for programmatic and at-scale incident lifecycle management, custom webhooks

--

--

++

Support

Business

Start trial

Enterprise

Book a demo

Onboarding program with dynamic attack surface mapping

--

--

++

Account management and customer success support

--

--

++

Ticket portal and live support

--

--

++

Honeytoken addon logo

Honeytoken

Dropdown Arrow

Honeytokens

Business

Start trial

Enterprise

Book a demo

Included for Free

5 Honeytokens

5 Honeytokens

5 Honeytokens

Type

AWS IAM Secrets

AWS IAM Secrets

AWS IAM Secrets

ADD-ON Quota

--

10 / dev

Custom

Deployment

Business

Start trial

Enterprise

Book a demo

Automated detection in source code

++

++

++

Perimeter coverage tracking

++

++

++

Deployment jobs

--

++

++

Monitoring

Business

Start trial

Enterprise

Book a demo

Leakage detection
on public sources (GitHub)

++

++

++

IP labeling

++

++

++

Incident response

Business

Start trial

Enterprise

Book a demo

Enriched events stream (e.g., user agent, action, IP address, tags, etc.)

++

++

++

NHI Governance

Dropdown Arrow

Sources

Business

Start trial

Enterprise

Book a demo

Secrets managers

--

++

++

Cloud identity and access management (IAM)

--

--

++

Cloud infrastructure configuration

--

--

++

Infrastructure as Code (IaC)

--

--

++

NHI discovery & inventory

Business

Start trial

Enterprise

Book a demo

Real-time inventory

--

--

++

Unified View

--

--

++

Context & visibility

Business

Start trial

Enterprise

Book a demo

Ownership

--

--

Coming soon!

Permissions & access

--

--

++

End-to-end mapping (Sources, consumers, scope, leaks)

--

--

++

Policy breach context in an exploration graph

--

--

++

Lifecycle management

Business

Start trial

Enterprise

Book a demo

Push-to-vault

--

--

++

Safe revocation/rotation

--

--

++

Security posture & hygiene

Business

Start trial

Enterprise

Book a demo

Duplicated and reused secrets detection

--

--

++

Internal and public Incidents overview

--

--

++

Meeting the OWASP Top 10 policies

--

--

++

Vaulted secrets metrics

--

--

++

Platform logo

Platform

Dropdown Arrow

Deployment

Business

Start trial

Enterprise

Book a demo

SaaS

++

++

++

Data center regions

US

US / Europe

US / Europe

Self-hosted
(Helm or KOTS)

--

--

++

Starting at 200 devs

Administration

Business

Start trial

Enterprise

Book a demo

SSO login with
SAML 2.0 support or SCIM

--

++

++

Teams

--

Up to 20 teams

Unlimited

Custom roles

--

++

Up to 3 roles

++

Unlimited

Inventory management
(with key/value custom tags & saved views)

++

Up to 100

++

Unlimited

++

Unlimited

IP allowlisting

++

++

++

Common Access Card (CAC)

--

--

++

only for self-hosted

Alerting & ticketing

Business

Start trial

Enterprise

Book a demo

Native integrations for %third parties with gg notifications integration%

++

Workspace-level

++

Team-level

++

Team-level

Event-driven webhooks

++

++

++

Analytics & reporting

Business

Start trial

Enterprise

Book a demo

Analytics insights

++

++

++

Analytics charts

--

++

++

Export (.csv format)

--

++

++

API & developer tools

Business

Start trial

Enterprise

Book a demo

REST API for workspace and
incident management

++

++

++

GitGuardian CLI for
developers (ggshield)

++

++

++

Quota

10,000
calls/month

100,000
calls/month

Unlimited

Other

Business

Start trial

Enterprise

Book a demo

Audit logs (UI)

++

++

++

Audit logs (API)

++

++

12-month retention

++

unlimited retention

Support

Business

Start trial

Enterprise

Book a demo

Onboarding program

Self-service resources
(docs, guides)

++

++

Customer support

Ticket portal

Ticket portal

Ticket portal and live support

Support availability

N/A

Next business day

During
business hours

Premium support

--

--

Add-on

Enterprise AppSec and IAM are challenging

You have more than 500 developers?

Let’s get you on our enterprise onboarding program.

only available for gitguardian platform

Premium support icon

Premium Support

Build and rollout the most comprehensive secrets detection and remediation program.

Get support from a dedicated team of SREs for on-premise deployments

Design a phased rollout program with the help of our Solutions Engineering team

Train security and dev teams on vulnerability management and remediation

Talk to an expert

Schedule a 30-minute demo and get a complimentary report with your organization’s live incidents on GitHub.

I’m not sure which product I need.

Secrets Detection tightly integrates with repositories that are owned by your company, either public (under your GitHub Organization, if you have any) or private repositories. These repositories are part of your Software Development Life Cycle.

Public Monitoring is more of a Data Loss Prevention or Threat Intelligence solution. It monitors the whole GitHub public activity, using many different rules to pinpoint activity that is linked with your company and that might be a threat. This activity mostly occurs on repositories that you don’t control and you don’t even know exist, such as your developers’ personal repositories.

NHI Governance gives you one place to see all your secrets across vaults and other sources, understand who uses them, and automate their lifecycle management. It helps you find security gaps and improve your overall NHI security.

Can I purchase licenses for the GitGuardian Platform on AWS Marketplace?

GitGuardian Platform licenses can be acquired via the AWS Marketplace. As an AWS ISV Accelerate partner, we offer seamless integration and streamlined procurement. Please visit https://aws.amazon.com/marketplace to learn more.

If you are a large organization looking to acquire several hundred licenses, you can also request a private offer from the GitGuardian team. Please contact sales@gitguardian.com.

How do GitGuardian Public Monitoring and GitGuardian Secrets Detection work together?

These two products are complementary and available in the platform. They come in the form of two different dashboards. GitGuardian for Public Monitoring is typically used by Threat Response, while Secrets Detection is typically used by Application Security.

This greatly depends however, on the way responsibilities are split between your teams. In any case, the look and feel of both GitGuardian dashboards are very similar, so that your team members aren’t lost when they use both products!

How do GitGuardian NHI Governance and GitGuardian Secrets Detection work together?

GitGuardian NHI Governance and Secrets Detection gives you a complete NHI security picture. Governance finds all your secrets, and Detection pinpoints leaks. This combo boosts accuracy, speeds up incident response by showing you exactly where secrets live, and helps prevent future leaks by guiding developers. Together, they make secrets management faster, safer, and more efficient.

Who counts as a developer?

For Public Monitoring: any publicly active developer who has made at least one public commit somewhere on GitHub.

For Secrets Detection and NHI Governance: any active contributor to a project you are securing with GitGuardian who has made at least one commit in the last 90 days.

How can I get a count of my developers?

For Public Monitoring, the best option that you have is to reach out to us. We use many different rules to identify public activity that is linked with your company. It just takes one email to our support to get your company’s public activity metrics based on our historical data.

For Secrets Detection and NHI Governance, a developer is an active contributor to a project you are securing with GitGuardian who has made at least one commit in the last 90 days. This applies to both Secrets Detection and NHI Governance, as NHI Governance is part of the unified GitGuardian Platform and is priced per developer seat.

Are contributors to my Open Source projects counted?

Our GitGuardian platform is free for repositories hosted under your GitHub Organization.

Our Public Monitoring product is charged based on your numbers of publicly active developers. Contributors to your Open Source projects aren’t always members of your development teams. We count these contributors only if they are actual employees. In such a case, we monitor these contributors wherever they commit on public GitHub, especially on personal and third party repositories.

How do you count API calls?

Quota usage is based on requests and not on content amount or size. As an example, the scan of a single file, via single scan endpoint, and the scan of a commit involving multiple files, via multiple scan endpoint, both use 1 API call per request.

The quota is set on a rolling month basis (and not on calendar month). By default, we grant 10,000 calls/month on our free plans and 1M calls/month for our customers on the business plan. Those quotas can be fine tuned upon request.

Do you have discounts for nonprofit institutions or educational institutions?

We do! Please contact us.