GitGuardian
GitGuardian is a Paris-based cybersecurity company providing a secrets detection and non-human identity (NHI) governance platform, serving developers and security teams at enterprises including 1 in 4 Fortune 500 companies.
- Company typePrivate
- Founded2017
- HeadquartersParis, France
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What GitGuardian does
GitGuardian is a Paris-headquartered cybersecurity company that provides a platform for detecting and managing sensitive digital credentials and machine identities (non-human identities, or NHIs). Founded in 2017 and operating through GitGuardian SAS (France) and GitGuardian Inc. (Cambridge, MA), the company serves developers, security engineers, and AppSec/SecOps teams at enterprises including 1 in 4 Fortune 500 companies. As of 2025, GitGuardian protects more than 600,000 developers and monitors 610,000+ repositories, with its platform scanning over 1 billion commits daily and detecting 550+ secret types at a sub-5% false positive rate.
The core platform spans the full secret lifecycle — detect, attribute, rotate, and remediate — through products including Internal Secrets Monitoring, Public Secrets Monitoring, NHI Governance, the Developer Endpoint Protection module (launched June 2026), the ggshield CLI (#1 most-installed security app on GitHub Marketplace), honeytokens, and a public REST API with a Python SDK. The technical stack incorporates an XGBoost ML model for agentic alert prioritization (5x critical detection precision vs. rule-based systems), NHI governance with ownership attribution, dependency mapping, and one-click revocation, plus hook-based scanning at AI coding tool entry points (Cursor, Claude Code, GitHub Copilot). GitGuardian monetizes primarily through SaaS subscriptions (60% of new enterprise customers signing multi-year agreements), complemented by a freemium self-serve tier, usage-based API quotas, and a channel partner program for VARs, MSPs, and MSSPs launched in December 2025.
The company has raised approximately $106.2 million across disclosed funding rounds, including a $50 million Series C in February 2026 led by Insight Partners with co-lead Quadrille Capital, following a $44 million Series B in December 2021 led by Eurazeo and Sapphire Ventures. GitGuardian reports 5x year-over-year growth in remediation volume and 7x growth in connected collaboration sources in 2025, with 80%+ of new ARR originating in North America and active expansion into EMEA, APAC, South America, and the Middle East.
GitGuardian firmographics
Firmographics- Name
- GitGuardian
- Legal name
- GitGuardian SAS / GitGuardian inc.
- Website
- https://gitguardian.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- GitGuardian is a Paris-based cybersecurity company providing a secrets detection and non-human identity (NHI) governance platform, serving developers and security teams at enterprises including 1 in 4 Fortune 500 companies.
- Ownership category
- akta.pro rank
GitGuardian industry classification
Industry- Product category
- Secrets Security and Non-Human Identity Governance
- NAICS
- Software Publishers (51321), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
- akta.pro secondary industries
- Data Security & Privacy Managed Services (DLP/Encryption) (BPAEADAL), GitOps & Continuous Delivery Operations (BPAEAKAN)
Keywords
Where GitGuardian is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices6 records
Markets served
GitGuardian business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- SaaS Subscriptions: Recurring SaaS subscriptions across Internal Secrets Monitoring, Public Secrets Monitoring, NHI Governance, and Developer Endpoint Protection; 60% of new enterprise customers sign multi-year agreements, indicating land-and-expand with multi-year lock-in.
- Freemium / Self-Serve Tier: Free signup with first-repo scan in 5 minutes drives bottom-up developer adoption that converts to paid enterprise tiers.
- API Usage / Quota Consumption: API-based quota (scanning calls) shared across tokens of a workspace on a rolling month basis; enables usage-based billing for embedded integrations.
- Channel / Managed Services Revenue: VAR, MSP, and MSSP channel partners deliver secrets security as a managed service, generating partner-sourced recurring revenue.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free tier / self-serve signup |
| Subscription | Multi-year contract | Enterprise subscription with multi-year agreements |
| Hybrid | Multi-year contract | Enterprise contract with prevention-first deployment (Orange Business case study) |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels10 records
GitGuardian product offering
Product offeringCore offering
GitGuardian sells a SaaS platform for detecting, attributing, rotating, and remediating hardcoded secrets and machine (non-human) identities across developer endpoints, source code repositories, CI/CD pipelines, container registries, and collaboration tools. Its core products are Internal Secrets Monitoring, Public Secrets Monitoring, NHI Governance, and Developer Endpoint Protection, all delivered through multi-region SaaS (US/EU) and accessible via the ggshield CLI and a public REST API.
Product overview
GitGuardian offers a unified platform for secrets security and Non-Human Identity (NHI) governance built around the full secret lifecycle—Detect, Attribute, Rotate, and Remediate. The core platform comprises Internal Secrets Monitoring (scanning internal repositories, CI/CD, and collaboration tools), Public Secrets Monitoring (scanning external GitHub attack surface), and NHI Governance (discovering, attributing, and managing machine identities). These are extended by the Developer Endpoint Protection module (scanning developer laptops via ggshield for plaintext credentials in .env files, shell history, and AI coding agent caches) and the ggshield CLI itself, which is the #1 most-installed security app on GitHub. Supporting tools include GitGuardian Scout, the GitGuardian API, HasMySecretLeaked (a free public exposure-check service), and SaaS Sentinel. Honeytokens serve as a detection layer deployed across developer endpoints and cloud infrastructure. The platform is sold as a prevention-first, full-lifecycle solution rather than a single-purpose scanner.
Differentiator
Problem solved
Functional benefit
Brands
- ggshield: GitGuardian's CLI application for secrets detection, deployed as pre-commit, pre-push, IDE, and AI coding tool integrations.
- ggscout
- HasMySecretLeaked
Products and services
- Internal Secrets Monitoring Monitors internal code repositories, CI/CD pipelines, container registries, Jira, Slack, and other collaboration sources for leaked secrets, using agentic prioritization to triage incidents like a SecOps engineer, auto-route to the right developer, and close incidents.
- Public Secrets Monitoring Continuously scans public GitHub repositories for leaked credentials, protecting the external attack surface by detecting and helping remediate secrets before attackers can exploit them.
- NHI Governance Provides comprehensive visibility and control over non-human identities (service accounts, API keys, OAuth tokens, AI agents) across secrets managers, cloud platforms, and SaaS applications, flagging orphaned accounts, attributing ownership, and identifying over-privileged and rotation-overdue credentials.
- Developer Endpoint Protection Extends GitGuardian's secrets and NHI security platform to developer workstations, scanning laptops for credentials in plaintext .env files, shell history, CLI caches, IDE/MCP configs, and AI coding agent caches, with honeytoken detection and MDM-based fleet deployment (Intune, Jamf, Kandji).
- ggshield (GitGuardian CLI) GitGuardian's command-line interface providing maximum visibility wherever code is written, including pre-commit, pre-push, IDE, AI coding tools, agent skills, plugins, and MCP servers; detects 550+ secret types with a low false-positive rate and is the #1 most-installed security app on GitHub.
- Honeytokens Decoy credentials deployed to detect malicious secret harvesting in real time, including AWS-type honeytokens distributed via ggshield and managed via the API (create, reconcile, revoke, reset).
- GitGuardian API Public REST API (v1.1.0) enabling programmatic secret scanning, incident management, honeytoken deployment, source/perimeter management, SCIM v2 provisioning, OAuth2/OIDC integrations, audit logs, and health check monitoring, with Python SDK (py-gitguardian).
- GitGuardian Scout Developer-facing monitoring tool listed alongside ggshield in the GitGuardian developer tools ecosystem, providing secret detection and monitoring capabilities.
- HasMySecretLeaked Free public service that allows users to check whether their secrets have been exposed in public GitHub repositories, accessible via API and monitored as part of GitGuardian's services status.
- SaaS Sentinel Free tool offered by GitGuardian for monitoring SaaS applications and collaboration platforms for leaked secrets, part of the company's free tools suite.
Companies that use GitGuardian
Customer profileNamed customers7 records
Segments9 records
Ideal customer profiles3 records
GitGuardian technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration28 records
AI capability8 records
Feature8 records
GitGuardian partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered flagship and core.
- ONE-ISACflagshipStrategic partnership to enhance cybersecurity in the oil and natural energy sector. The collaboration focuses on operational technology environments and addresses sector-specific challenges through secrets detection, non-human identity security, and promotion of industry standards. Announced May 2025.
- GitHubflagshipTechnology integration partner; GitGuardian is the #1 Security App on GitHub Marketplace and provides ggshield integration with GitHub Actions, GitHub Advanced Security, and GitHub Copilot for secrets scanning at commit, push, and AI-tool stages.
- GitLabcoreTechnology integration partner for source monitoring and pre-receive hooks; Orange Business case study achieved 80% reduction in new secret leaks via pre-receive hooks on GitLab.
- Jira (Atlassian)coreIntegration partner for incident routing into the destination ticketing system; supports Jira Cloud and Jira Data Center installations.
- SlackcoreIntegration partner for monitoring secrets in Slack workspaces as a source type, with health-check support.
- Amazon Web Services (AWS)coreIntegration partner covering AWS ECR, AWS S3, AWS Secrets Manager, and AWS IAM Outbound Identity Federation; NHI Governance tracks vault integrations for migration to short-lived JWTs.
- Microsoft AzurecoreIntegration partner supporting Azure Repos, Azure Pipelines, Azure Container Registry, and Microsoft Teams as monitored source types.
- Bitbucket (Atlassian)coreIntegration partner for Bitbucket Cloud and Bitbucket Data Center installations as monitored source types.
- CircleCIcoreCI/CD integration partner for secret scanning within CircleCI pipelines.
- Docker HubcoreIntegration partner for monitoring container registries as a monitored source type.
- Google Cloud
Scale indicators15 records
Recent moves13 records
Expansion highlights6 records
GitGuardian competitors and assessment
Company assessmentEmerging players
- Aqua Security: Cloud-native security platform covering containers, IaC, and secrets. Overlaps with GitGuardian on infrastructure-as-code secrets scanning and competes for DevSecOps budget in cloud-native enterprises.
- Entro Security: NHI and secrets security startup focused on discovering, monitoring, and managing machine identities across cloud and SaaS environments. Competes with GitGuardian in the NHI Governance category with a more focused initial scope.
- 1Password: Secrets and credential management provider that has expanded from consumer/team password management into developer secrets and machine identity. Competes for a portion of the secrets-management buyer base, particularly in mid-market and SMB segments.
- Truffle Security (TruffleHog): Open-source-driven secrets detection company built around the widely adopted TruffleHog scanner. Competes most directly with GitGuardian in source-code secrets detection, particularly with developer-led adoption motions.
Direct peers
- Snyk: Developer-security platform offering SAST, SCA, IaC scanning, and increasingly code-secrets detection. Targets the same developer and AppSec buyer personas as GitGuardian and is a direct competitor for AppSec budget in mid-market and enterprise accounts.
- HashiCorp Vault: Industry-standard secrets management platform for storing and rotating credentials. Complementary rather than purely competitive with GitGuardian, but Vault's expansion into broader secrets lifecycle management overlaps with GitGuardian's rotation and NHI capabilities.
- Akeyless: SaaS-based secrets management and machine identity platform. Directly competes with GitGuardian's NHI Governance and secrets rotation capabilities, particularly for cloud-native and DevOps-centric enterprises.
Broad incumbents
- GitHub Advanced Security: Bundled code-scanning, secret-scanning, and dependency-review capabilities offered with GitHub Enterprise. Directly competes with GitGuardian in source-control-integrated secrets detection and benefits from native distribution to every GitHub Enterprise customer.
- CyberArk: Privileged access management leader that has expanded into machine identity and secrets management through organic development and acquisitions. Competes with GitGuardian's NHI Governance module and benefits from an established enterprise security footprint.
- Wiz: Cloud security platform with broad enterprise traction that has expanded into code-to-cloud security including secrets detection. Competes for the same CISO budget and has demonstrated a similar land-and-expand growth pattern.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
GitGuardian social profiles
Digital presenceGitGuardian compliance and trust
Trust signalCompliance5 records
GitGuardian financial estimates
Financial estimateRevenue estimate
Valuation estimate
GitGuardian leadership team
Management profileNumber of profiles
Profiles4 records
GitGuardian subsidiaries and ownership
Company hierarchySubsidiaries1 record
GitGuardian funding detail
Funding detailFunding overview
Funding rounds5 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GitGuardian M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GitGuardian
What does GitGuardian do?
GitGuardian sells a SaaS platform for detecting, attributing, rotating, and remediating hardcoded secrets and machine (non-human) identities across developer endpoints, source code repositories, CI/CD pipelines, container registries, and collaboration tools. Its core products are Internal Secrets Monitoring, Public Secrets Monitoring, NHI Governance, and Developer Endpoint Protection, all delivered through multi-region SaaS (US/EU) and accessible via the ggshield CLI and a public REST API.
Is GitGuardian a public or private company?
GitGuardian is a private company. It is classified as venture growth investor backed and is currently operating.
When was GitGuardian founded?
GitGuardian was founded in 2017. It employs 101 to 250 people.
Where is GitGuardian based?
GitGuardian is headquartered in Paris, France, in the Europe region.
How does GitGuardian make money?
Four revenue lines are on record. SaaS Subscriptions are the primary driver. The others are freemium / Self-Serve Tier, API Usage / Quota Consumption and channel / Managed Services Revenue.
Who are GitGuardian's main competitors?
Emerging players on record are Aqua Security, Entro Security, 1Password and Truffle Security (TruffleHog). Direct peers are Snyk, HashiCorp Vault and Akeyless. Broad incumbents are GitHub Advanced Security, CyberArk and Wiz.
Does GitGuardian have an API?
Yes. GitGuardian offers a public REST API (v1.1.0) at https://api.gitguardian.com/v1 (US) or https://api.eu1.gitguardian.com/v1 (EU), authenticated via API keys. Endpoints cover secret scanning (content scan, multiscan, scan and create incidents), secret incidents (internal and public) management, honeytokens management, source/perimeter management, team and member management, SCIM v2 for user/group provisioning, OAuth2/OIDC for third-party integrations, audit logs, IP allowlist management, custom tags, severity rules, and health checks. It supports both public-facing endpoints and an internal API. A Python SDK (py-gitguardian) is available, along with the GitGuardian Shield CLI (ggshield) which uses the API for scanning files and detecting secrets in code via py-gitguardian. The API uses cursor-based pagination and ISO-8601 timestamps. OAuth 2.0 endpoints are available to integrate third-party clients (such as MCP clients) via Authorization Code + PKCE flow with Dynamic Client Registration support. Developer documentation is at api.gitguardian.com/docs.
What industry is GitGuardian in?
GitGuardian's product category is Secrets Security and Non-Human Identity Governance. Its primary akta.pro industry code is HDADACAG, Code & Repository Security (Git Security, Code Integrity), with a secondary code of BPAEADAL, Data Security & Privacy Managed Services (DLP/Encryption). Its NAICS code is 51321 and its SIC code is 7372.