GitGuardian

Detect and prevent exposed secrets (API keys, tokens, credentials) across repositories, CI/CD, and collaboration tools

Cybersecurity

Overview

GitGuardian is a European platform (founded in Paris in 2017) specializing in automated detection of exposed secrets: API keys, authentication tokens, database credentials, certificates, and other sensitive identifiers scattered across Git repositories, CI/CD pipelines (Jenkins, CircleCI, GitHub Actions), containers, Slack, Jira, and other team collaboration tools. It scans in real-time, blocking exposure before push or PR merge. The Starter plan is free up to 25 developers with unlimited internal scanning (500 historical detections), 10K API calls/month and 1 GB repository capacity; Growth and Enterprise are not publicly priced (quote required) but add public secrets monitoring, automated remediation, AI risk scoring, and playbooks for Slack/Jira/ServiceNow integration.

GitGuardian's platform interface is currently available in English only, though public documentation will be translated to French by Q2 2026. Being a European company based in France, GDPR compliance and EU data residency are highlighted across all plans. A documented REST API enables automated detection and retrieval of findings; the platform integrates with Slack, Jira, and collaboration tools for notifications and automatic ticket creation. The Starter free plan offers strong value for SMEs up to 25 developers, but progression to Growth is required for public secrets detection (internet-wide scanning) and advanced features: actual costs remain opaque pending quote.

Our verdict

Best for SMEs and development teams wanting secrets exposure protection at no upfront cost, with a free tier up to 25 developers and a European company. Avoid if developer count exceeds 25 without budget for Growth quote: the absence of public pricing makes budget planning difficult, and the actual scope (public vs. internal) must be validated before commitment.

← Back to all tools
GitGuardian: pricing, review and alternatives — librairy.io