GitGuardian

Paris secrets-detection platform that scans git history and CI logs for leaked credentials

Quick Overview

Company GitGuardian SAS
Category Developer Tools
Headquarters Paris, France
Founded 2017
EU Presence EU (France)
Open Source No
Pricing Free plan for small teams / Business priced per active developer seat / Enterprise pricing on request
Free Option Free plan available; paid tiers on request
Replaces GitHub secret scanning, manual credential audits

Detailed Review

Pros and Cons

Pros

  • Scans git history, CI logs and chat tools for secrets
  • Free plan genuinely usable for small teams
  • Seat pricing counts only active contributors, not every account
  • Non-Human Identity governance covers long-lived API keys and tokens
  • Works alongside any forge, not tied to one

Cons

  • Detects leaked secrets; doesn't manage or store them itself
  • Business tier price isn't published, only "per seat"
  • US affiliate is joint controller for US customers
  • Another subscription layered on top of the forge itself

Alternatives to GitGuardian

See all developer tools →

Frequently Asked Questions

What is GitGuardian?

GitGuardian scans git history, CI/CD logs and chat tools for secrets that should never have been committed — API keys, database passwords, private certificates — and flags them before or immediately after they leak into a repository.

It works alongside any forge in this category rather than replacing one, watching GitLab, Gitea, GitHub or Codeberg repositories for the mistake every development team eventually makes. Its newer Non-Human Identity governance extends the same idea to API keys and service-account tokens that outlive the person who created them, a gap most forges don't cover on their own.

Where is GitGuardian based?

GitGuardian operates from Paris, France, which places it under EU (France).

What does GitGuardian cost?

Free plan for small teams / Business priced per active developer seat / Enterprise pricing on request. Free plan available; paid tiers on request.

Who is GitGuardian best for?

Teams that need leaked secrets caught early. The only tool here that watches for the mistake everyone eventually makes: a real secret committed straight into git history.

What are the drawbacks of GitGuardian?

Detects leaked secrets; doesn't manage or store them itself. Business tier price isn't published, only "per seat". US affiliate is joint controller for US customers. Another subscription layered on top of the forge itself.

Who worked on this review

Three people touch every tool page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Daniel Brandt
Written by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Sebastiaan Smits
Edited by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Marta Kowalczyk
Fact-checked by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Go to GitGuardian