💻 Developer Endpoint Protection is here: find every credential on every developer machine, before attackers do.

Learn more →

💻 Developer Endpoint Protection is here: find every credential on every developer machine, before attackers do.

Learn more →

GitGuardian Pricing

Find every credential. Stop the next breach.

free

Starter

For individuals or up to 25 devs

$0

Always
No credit card required
Get Started

free Plan also includes:

Up to 25 devs

Unlimited real-time scanning

Up to 500 historical scan detection

Business

Teams

For teams up to 200 devs

Let’s Talk

Start Trial
Add on

Up to 20 teams

Remediation playbooks

Scan Git repository up to 12 Gb

Enterprise

Custom

Recommended for 200+ dev teams

Let’s Talk

Contact Sales
Add on
Add on

Self-hosted deployment available

Unlimited teams, API calls & custom detectors

Dedicated support channel

Starter

For individuals and teams up to 25 devs

Free Plan also includes:

Internal secrets monitoring

Up to 25 devs

Unlimited real-time scanning

Up to 500 historical scan detection

10K API calls/month

Start for free

Growth

For teams up to 500 developers

Everything in Starter, plus:

Internal secrets monitoring: code, CI/CD, containers, custom

Public secrets monitoring (limited)

Endpoint protection for developer machines (extra endpoints as add-on)

Remediation playbooks + Slack, Jira, ServiceNow integrations

AI risk scoring and false-positive filtering

SSO (SAML 2.0) + SCIM

Up to 10 teams

US and EU data hosting regions

Start free trial

Enterprise

For 500+ developer organizations

Everything in Growth, plus:

Public secrets monitoring (unlimited)

NHI governance: vaults, identity mapping, OWASP policies

Endpoint protection: developer + standard endpoints (extra as add-on)

Corporate data sources: ticketing, messaging, documentation

Enterprise data sources: file storage, CI logs

Self-hosted deployment + GitGuardian Bridge

Unlimited teams + custom RBAC

Custom detectors

12-month audit log retention

Premium Care (add-on)

Contact sales

Non-Human Identity & Secrets Security Platform

GitGuardian Platform

Internal Secrets Monitoring

Scan and fix
hardcoded secrets.

Learn more

Public Secrets Monitoring

We catch the leaks, you stop the intrusions.

Learn more

Endpoint Protection

Detect credentials on developer and employee machines

Learn more

NHI Governance

Get full control and visibility of your Non-Human Identities.

Learn more
View Hide platform plan details
Dropdown Arrow

Internal Secrets Monitoring

Dropdown Arrow

Business

Start trial

Enterprise

Book a demo

Sources

Business

Start trial

Enterprise

Book a demo

Application source code, Docker images with ggshield

++

++

++

Git repositories max scanning size

1 Gb

12 Gb

60 Gb

Scan developers collaboration tools

--

--

Add-on (Ticketing, Documentation, Messaging, Container Registries)

Historical scan

500

Unlimited

Unlimited

SDLC stages

Business

Start trial

Enterprise

Book a demo

Multi-VCS support
GitHub, Azure Repos, GitLab, Bitbucket

++

++

++

GitHub Enterprise server

--

++

++

Developer workstations scan - Git hooks

++

++

++

Pull requests - GitHub only

++

++

++

Detection

Business

Start trial

Enterprise

Book a demo

Specific detectors (%ndet%+)

++

++

++

Generic detectors (%ngdet%+)

++

++

++

Custom detectors - REGEX based

--

++

++

Validity and presence checks (periodicity)

Low frequency

High frequency

High frequency

Remediation

Business

Start trial

Enterprise

Book a demo

Automated severity scoring
(context-based)

--

++

++

End-to-end mapping (Sources, scope, leaks)

--

--

++

Developer-in-the-loop
(feedback and resolution)

++

++

++

Remediation tracking

++

++

++

Remediation playbooks

++

Only some playbooks

++

++

Remediation guidelines
for developers

++

Default and custom

++

++

Secrets managers integrations

--

++

++

Push-to-vault

--

--

++

Prevention

Business

Start trial

Enterprise

Book a demo

GitGuardian CLI ggshield
(in pre-commit hooks)

++

++

++

VScode extension

++

++

++

Public Secrets Monitoring

Dropdown Arrow

Business

Start trial

Enterprise

Book a demo

Support

Business

Start trial

Enterprise

Book a demo

Official open-source repositories

--

--

++

Public personal repos of developers and subcontractors

--

--

++

Regular update of this perimeter

--

--

++

Detection

Business

Start trial

Enterprise

Book a demo

Real-time monitoring of GitHub repos

--

--

++

Scan 6 years of past contributions 

(Even if deleted or made private)

--

--

++

Specific and generic secrets detection

--

--

++

Keyword detection specific to your organization

--

--

++

Built-in validity and presence checks

--

--

++

Advanced contextual analysis that enhances precision & recall

--

--

++

Post-detection insights

--

--

++

Audit logs

--

--

++

Real-time alerting

Business

Start trial

Enterprise

Book a demo

Notifications via configured channels (Jira, Slack, etc.)

--

--

++

Alerts on events
(severity updates, notes, etc.)

--

--

++

Emails for new incidents, public events etc

--

--

++

Threat hunting

Business

Start trial

Enterprise

Book a demo

Search Public GitHub with regex and full-text queries and scan results for secrets

--

--

++

Deployment

Business

Start trial

Enterprise

Book a demo

SaaS

--

--

++

Authn/Authz

Business

Start trial

Enterprise

Book a demo

SSO login with SAML 2.0 or SCIM

--

--

++

Roles & permissions

--

--

++

API

Business

Start trial

Enterprise

Book a demo

REST API for programmatic and at-scale incident lifecycle management, custom webhooks

--

--

++

Support

Business

Start trial

Enterprise

Book a demo

Onboarding program with dynamic attack surface mapping

--

--

++

Account management and customer success support

--

--

++

Ticket portal and live support

--

--

++

NHI Governance

Dropdown Arrow

Business

Start trial

Enterprise

Book a demo

Sources

Business

Start trial

Enterprise

Book a demo

Secrets managers

--

++

++

Cloud identity and access management (IAM)

--

--

++

Cloud infrastructure configuration

--

--

++

NHI discovery & inventory

Business

Start trial

Enterprise

Book a demo

Real-time inventory

--

--

++

Unified View

--

--

++

Context & visibility

Business

Start trial

Enterprise

Book a demo

Ownership

--

--

Coming soon!

Permissions & access

--

--

++

End-to-end mapping (Sources, consumers, scope, leaks)

--

--

++

Policy breach context in an exploration graph

--

--

++

Lifecycle management

Business

Start trial

Enterprise

Book a demo

Push-to-vault

--

--

++

Safe revocation/rotation

--

--

++

Security posture & hygiene

Business

Start trial

Enterprise

Book a demo

Duplicated and reused secrets detection

--

--

++

Internal and public Incidents overview

--

--

++

Meeting the OWASP Top 10 policies

--

--

++

Vaulted secrets metrics

--

--

++

Honeytokens

Business

Start trial

Enterprise

Book a demo

Amount included

--

--

Unlimited

Types supported

--

--

AWS IAM

Automated detection in code

--

--

++

Perimeter coverage tracking

--

--

++

Deployment jobs

--

--

++

Leakage detection on GitHub

--

--

++

IP enrichment & labeling

--

--

++

Enriched events stream

--

--

++

Incident response workflows

--

--

++

Developer Endpoint Protection

Dropdown Arrow

Business

Start trial

Enterprise

Book a demo

Billing metric

Add-on

Add-on

Developer endpoints (machines of devs with platform seats)

--

Contact Sales

Contact Sales

Standard endpoints (non-dev: marketing, ops, etc.)

--

Contact Sales

Contact Sales

Dev endpoints = platform seats (1:1 mapping)

--

++

++

Honeytoken per endpoint

--

1 per endpoint

1 per endpoint

Automated credential detection on machines

--

++

++

AI hooks on developer workstations

--

++

++

MCP inventory

--

++

++

Platform

Dropdown Arrow

Business

Start trial

Enterprise

Book a demo

Deployment

Business

Start trial

Enterprise

Book a demo

SaaS

++

++

++

Data center regions

US

US / Europe

US / Europe

Self-hosted
(Helm or KOTS)

--

--

++

GitGuardian Bridge

--

--

++

Administration

Business

Start trial

Enterprise

Book a demo

SSO login with
SAML 2.0 support and SCIM

--

++

++

Teams

--

Up to 20 teams

Unlimited

Roles

--

++

++

Inventory management
(with key/value custom tags & saved views)

++

Up to 100

++

++

IP allowlisting

++

++

++

Common Access Card (CAC)

--

--

++

Alerting & ticketing

Business

Start trial

Enterprise

Book a demo

Native integrations for %third parties with gg notifications integration%

++

Workspace-level

++

++

Event-driven webhooks

++

++

++

Analytics & reporting

Business

Start trial

Enterprise

Book a demo

Analytics insights

++

++

++

Analytics charts

--

++

++

Export (.csv format)

--

++

++

API & developer tools

Business

Start trial

Enterprise

Book a demo

REST API for workspace and
incident management

++

++

++

GitGuardian CLI for
developers (ggshield)

++

++

++

Quota

10,000
calls/month

100,000
calls/month

Unlimited

Other

Business

Start trial

Enterprise

Book a demo

Audit logs (UI)

++

++

++

Audit logs (API)

++

++

++

Support

Business

Start trial

Enterprise

Book a demo

Onboarding program

Self-service resources
(docs, guides)

++

++

Customer support

Ticket portal

Ticket portal

Ticket portal and live support

Support availability

N/A

Next business day

During
business hours

Premium support

--

--

Add-on

Enterprise AppSec and IAM is challenging

You have more than 500 developers? Let’s get you on our enterprise onboarding program.

Only available for GitGuardian Platform
Premium Support

Build and rollout the most comprehensive secrets detection and remediation program.

Check

Get support from a dedicated team of SREs for on-premise deployments

Check

Design a phased rollout program with the help of our Solutions Engineering team

Check

Train security and dev teams on vulnerability management and remediation

Talk to an expert

Schedule a 30-minute demo and get a complimentary report with your organization’s live incidents on GitHub.

Take an interactive Tour

In this self-guided tour, discover key features that security teams and IAM leaders love.

Interactive demo example

What capabilities does the GitGuardian Platform include?

The GitGuardian Platform provides unified secrets and NHI security through four core capabilities: Internal Secrets Monitoring (find leaks across code, CI/CD, and collaboration tools), Public Secrets Monitoring (catch what leaks on public GitHub), NHI Governance (protect every machine identity across your vaults and IAM systems), and Developer Endpoint Protection (extend coverage to the developer's own machine).

Can I purchase licenses for the GitGuardian Platform on AWS Marketplace?

GitGuardian Platform licenses can be acquired via the AWS Marketplace. As an AWS ISV Accelerate partner, we offer seamless integration and streamlined procurement. Please visit https://aws.amazon.com/marketplace to learn more.

If you are a large organization looking to acquire several hundred licenses, you can also request a private offer from the GitGuardian team. Please contact sales@gitguardian.com.

How do GitGuardian Public Secrets Monitoring and GitGuardian Internal Secrets Monitoring work together?

These two products are complementary and available in the platform. They come in the form of two different dashboards. GitGuardian for Public Secrets Monitoring is typically used by Threat Response, while Internal Secrets Monitoring is typically used by Application Security.

This greatly depends however, on the way responsibilities are split between your teams. In any case, the look and feel of both GitGuardian dashboards are very similar, so that your team members aren’t lost when they use both products!

How do GitGuardian NHI Governance and GitGuardian Internal Secrets Monitoring work together?

GitGuardian NHI Governance and Internal Secrets Monitoring gives you a complete NHI security picture. Governance finds all your secrets, and Internal Monitoring pinpoints leaks. This combo boosts accuracy, speeds up incident response by showing you exactly where secrets live, and helps prevent future leaks by guiding developers. Together, they make secrets management faster, safer, and more efficient.

Additionally, NHI Governance includes Honeytoken for preemptive threat detection.When Secrets Monitoring finds an exposed credential, you can deploy a honeytoken in its place. If an attacker attempts to use it, you get instant alerts—turning remediated incidents into tripwires for future intrusion detection.

Who counts as a developer?

For Public Secrets Monitoring: any publicly active developer who has made at least one public commit somewhere on GitHub.

For Interal Secrets Monitoring and NHI Governance: any active contributor to a project you are securing with GitGuardian who has made at least one commit in the last 90 days.

How does Developer Endpoint Protection pricing work?

Developer Endpoint Protection is priced per endpoint per year, with two tiers:

  • Developer endpoints — priced per endpoint/year, mapped 1:1 to the developer seats you already have on the GitGuardian Platform. If you have 1,000 platform seats, you have 1,000 developer endpoints.
  • Standard endpoints — priced per endpoint/year at a lower rate. These cover non-developer machines (marketing, operations, and other functions outside the engineering team).

Each endpoint includes at least one Honeytoken for passive threat detection. Contact us to get a count of your endpoints and a custom quote.

How can I get a count of my developers?

For Public Secrets Monitoring, the best option that you have is to reach out to us. We use many different rules to identify public activity that is linked with your company. It just takes one email to our support to get your company’s public activity metrics based on our historical data.

For Internal Secrets Monitoring and NHI Governance, a developer is an active contributor to a project you are securing with GitGuardian who has made at least one commit in the last 90 days. This applies to both Internal Secrets Monitoring and NHI Governance, as NHI Governance is part of the unified GitGuardian Platform and is priced per developer seat.

Are contributors to my Open Source projects counted?

Our GitGuardian platform is free for repositories hosted under your GitHub Organization.

Our Public Secrets Monitoring product is charged based on your numbers of publicly active developers. Contributors to your Open Source projects aren’t always members of your development teams. We count these contributors only if they are actual employees. In such a case, we monitor these contributors wherever they commit on public GitHub, especially on personal and third party repositories.

How do you count API calls?

Quota usage is based on requests and not on content amount or size. As an example, the scan of a single file, via single scan endpoint, and the scan of a commit involving multiple files, via multiple scan endpoint, both use 1 API call per request.

The quota is set on a rolling month basis (and not on calendar month). By default, we grant 10,000 calls/month on our free plans and 1M calls/month for our customers on the business plan. Those quotas can be fine tuned upon request.

Do you have discounts for nonprofit institutions or educational institutions?

We do! Please contact us.

GitGuardian Pricing

Find every credential. Stop the next breach.

free

Starter

For individuals or up to 25 devs

$0

Always
No credit card required
Get Started

free Plan also includes:

Up to 25 devs

Unlimited real-time scanning

Up to 500 historical scan detection

Business

Teams

For teams up to 200 devs

Let’s Talk

Start Trial
Add on

Up to 20 teams

Remediation playbooks

Scan Git repository up to 12 Gb

Enterprise

Custom

Recommended for 200+ dev teams

Let’s Talk

Contact Sales
Add on
Add on

Self-hosted deployment available

Unlimited teams, API calls & custom detectors

Dedicated support channel

Starter

For individuals and teams up to 25 devs

Free Plan also includes:

Internal secrets monitoring

Up to 25 devs

Unlimited real-time scanning

Up to 500 historical scan detection

10K API calls/month

Start for free

Growth

For teams up to 500 developers

Everything in Starter, plus:

Internal secrets monitoring: code, CI/CD, containers, custom

Public secrets monitoring (limited)

Endpoint protection for developer machines (extra endpoints as add-on)

Remediation playbooks + Slack, Jira, ServiceNow integrations

AI risk scoring and false-positive filtering

SSO (SAML 2.0) + SCIM

Up to 10 teams

US and EU data hosting regions

Start free trial

Enterprise

For 500+ developer organizations

Everything in Growth, plus:

Public secrets monitoring (unlimited)

NHI governance: vaults, identity mapping, OWASP policies

Endpoint protection: developer + standard endpoints (extra as add-on)

Corporate data sources: ticketing, messaging, documentation

Enterprise data sources: file storage, CI logs

Self-hosted deployment + GitGuardian Bridge

Unlimited teams + custom RBAC

Custom detectors

12-month audit log retention

Premium Care (add-on)

Contact sales

Capability

Starter

Growth

Enterprise

Monitor - sources we scan

Git repositories (GitHub, GitLab, Bitbucket, Azure DevOps)

Repo scanning capacity

1 GB

12 GB

60 GB

CI/CD, container registries, AI agent configs

Collaboration tools (ticketing, messaging, documentation)

Developer endpoints (machines)

Add-on

Add-on

Detect - secrets detection engine

Real-time and unlimited historical scanning

Custom regex detectors

Unlimited

Investigate - context and enrichment

Validity and presence checks

Low frequency

High frequency + custom

AI risk scoring, AI filters, severity rules

Remediate - workflows that close incidents

Remediation playbooks + notifiers (Slack, Teams, email, Jira, ServiceNow)

AI Copilot for remediation

Smart Routing

Prevent - guardrails at the source

ggshield CLI + pre-commit hooks

Limited

AI IDE hooks (Cursor, Claude Code, Codex, GitHub Copilot)

Secure - non-human identity governance

Secrets manager integration + push-to-vault

NHI inventory, ownership mapping, duplicated/reused secret detection, OWASP Top 10 policy coverage

Platform and administration

SSO (SAML 2.0) + SCIM, IP allowlisting, privacy mode

Teams

Up to 10

Unlimited

Self-hosted deployment + GitGuardian Bridge

API audit logs (12-month retention)

Dedicated CSM

+ Premium Care

Take an interactive Tour

In this self-guided tour, discover key features that security teams and IAM leaders love.

Interactive demo example

More than 500 developers? Talk to our enterprise team

We'll help you design a phased rollout, train your security and engineering teams, and deploy on-premises if needed.

Dedicated Solutions Engineering team for rollout planning

Phased deployment program tailored to your environment

Training for security and developer teams on remediation workflows

Self-hosted (Helm or KOTS) deployment support

What capabilities does the GitGuardian Platform include?

The GitGuardian Platform provides unified secrets and NHI security through four core capabilities: Internal Secrets Monitoring (find leaks across code, CI/CD, and collaboration tools), Public Secrets Monitoring (catch what leaks on public GitHub), NHI Governance (protect every machine identity across your vaults and IAM systems), and Developer Endpoint Protection (extend coverage to the developer's own machine).

Can I purchase licenses for the GitGuardian Platform on AWS Marketplace?

GitGuardian Platform licenses can be acquired via the AWS Marketplace. As an AWS ISV Accelerate partner, we offer seamless integration and streamlined procurement. Please visit https://aws.amazon.com/marketplace to learn more.

If you are a large organization looking to acquire several hundred licenses, you can also request a private offer from the GitGuardian team. Please contact sales@gitguardian.com.

How do GitGuardian Public Secrets Monitoring and GitGuardian Internal Secrets Monitoring work together?

These two products are complementary and available in the platform. They come in the form of two different dashboards. GitGuardian for Public Secrets Monitoring is typically used by Threat Response, while Internal Secrets Monitoring is typically used by Application Security.

This greatly depends however, on the way responsibilities are split between your teams. In any case, the look and feel of both GitGuardian dashboards are very similar, so that your team members aren’t lost when they use both products!

What's the difference between Growth and Enterprise?

Growth is built for security teams managing up to 500 developers. It bundles the core platform capabilities — Internal Secrets Monitoring across code, CI/CD, and container registries, Public Secrets Monitoring (limited), remediation playbooks, and SSO. It comes with a dedicated CSM and is the right starting point for most security teams scaling secrets governance.

Enterprise is built for 500+ developer organizations and adds the capabilities that mature security programs require: NHI Governance (vault coverage, identity inventory, OWASP policies), AI-powered remediation (AI Copilot, Smart Routing), enterprise data sources (file storage, CI logs, collaboration tools), self-hosted deployment, and 12-month audit log retention.

How do GitGuardian NHI Governance and GitGuardian Internal Secrets Monitoring work together?

GitGuardian NHI Governance and Internal Secrets Monitoring gives you a complete NHI security picture. Governance finds all your secrets, and Internal Monitoring pinpoints leaks. This combo boosts accuracy, speeds up incident response by showing you exactly where secrets live, and helps prevent future leaks by guiding developers. Together, they make secrets management faster, safer, and more efficient.

Additionally, NHI Governance includes Honeytoken for preemptive threat detection.When Secrets Monitoring finds an exposed credential, you can deploy a honeytoken in its place. If an attacker attempts to use it, you get instant alerts—turning remediated incidents into tripwires for future intrusion detection.

Who counts as a developer?

For Public Secrets Monitoring: any publicly active developer who has made at least one public commit somewhere on GitHub.

For Interal Secrets Monitoring and NHI Governance: any active contributor to a project you are securing with GitGuardian who has made at least one commit in the last 90 days.

How does Developer Endpoint Protection pricing work?

Developer Endpoint Protection is priced per endpoint per year, with two tiers:

  • Developer endpoints — priced per endpoint/year, mapped 1:1 to the developer seats you already have on the GitGuardian Platform. If you have 1,000 platform seats, you have 1,000 developer endpoints.
  • Standard endpoints — priced per endpoint/year at a lower rate. These cover non-developer machines (marketing, operations, and other functions outside the engineering team).

Each endpoint includes at least one Honeytoken for passive threat detection. Contact us to get a count of your endpoints and a custom quote.

How can I get a count of my developers?

For Public Secrets Monitoring, the best option that you have is to reach out to us. We use many different rules to identify public activity that is linked with your company. It just takes one email to our support to get your company’s public activity metrics based on our historical data.

For Internal Secrets Monitoring and NHI Governance, a developer is an active contributor to a project you are securing with GitGuardian who has made at least one commit in the last 90 days. This applies to both Internal Secrets Monitoring and NHI Governance, as NHI Governance is part of the unified GitGuardian Platform and is priced per developer seat.

Are contributors to my Open Source projects counted?

Our GitGuardian platform is free for repositories hosted under your GitHub Organization.

Our Public Secrets Monitoring product is charged based on your numbers of publicly active developers. Contributors to your Open Source projects aren’t always members of your development teams. We count these contributors only if they are actual employees. In such a case, we monitor these contributors wherever they commit on public GitHub, especially on personal and third party repositories.

How do you count API calls?

Quota usage is based on requests and not on content amount or size. As an example, the scan of a single file, via single scan endpoint, and the scan of a commit involving multiple files, via multiple scan endpoint, both use 1 API call per request.

The quota is set on a rolling month basis (and not on calendar month). By default, we grant 10,000 calls/month on our free plans and 1M calls/month for our customers on the business plan. Those quotas can be fine tuned upon request.

Do you have discounts for nonprofit institutions or educational institutions?

We do! Please contact us.