By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. At a glance
  2. What they do
  3. Research contribution
  4. Differentiators
  5. Where the category context matters
  6. Practical notes
  7. When GitGuardian makes sense
  8. What we don't know

At a glance

Founded2017
FoundersJérémy Thomas (CEO), Eric Fourrier (CTO)
HeadquartersParis, France
CategorySecrets detection + NHI governance (expanding)
Reported funding~$56M Series B (Eurazeo-led, December 2021); private since
Key productsSecrets Detection, Honeytoken, NHI Governance module, Public Monitoring (public GitHub scanning)
Position in categoryDetection-first; NHI-adjacent and extending further into the category

What they do

GitGuardian's original problem was simple and unsolved: developers leak secrets into source control constantly, and attackers scrape public GitHub for them. GitGuardian built a scanner and then kept going, into enterprise private repositories, into CI logs, into collaboration tools, and more recently into the adjacent NHI-governance space.

The product surface in 2026 includes:

  • Secrets detection. Pre-commit, CI, and post-commit scanning of source control with high-precision detectors tuned per credential type.
  • Public monitoring. Continuous scanning of public GitHub for leaks of an organisation's secrets, the original product.
  • Honeytoken. Planted-credential tripwires that alert on use, giving defenders an early warning when repositories or CI systems are accessed by unauthorised actors.
  • NHI Governance. An NHI-layer product overlapping with the startup NHI platforms: discovery, posture, ownership, lifecycle.

Research contribution

GitGuardian's research output has shaped the industry's understanding of the secrets problem more than any other vendor's. The Shai-Hulud npm supply-chain worm response in November 2025 is a case in point, GitGuardian was among the first to publish detailed technical analysis of the dead-man's-switch logic and TruffleHog-embedded secret-exfiltration mechanism. The Codecov Bash Uploader incident is another instance where its telemetry was instrumental in scoping blast radius.

The annual "State of Secrets Sprawl" report is widely cited and has become a useful benchmark for board-level conversations about the scale of the problem.

Differentiators

  • Detector quality. Years of investment in per-credential-type detectors with high precision, the difference between "300 flagged secrets, mostly false positives" and "40 flagged secrets, almost all real."
  • Public monitoring. Few vendors have the infrastructure and the relationships with GitHub to do continuous public-scope monitoring well.
  • Research voice. The vendor with the most serious, most consistent NHI-relevant research output.
  • European ownership. Paris-headquartered, independent, not part of a US platform consolidation story.

Where the category context matters

GitGuardian is approaching NHI governance from "we already see the credentials, we should govern them." The startup NHI platforms are approaching it from "we see the identities, we should understand their credentials." The two directions are converging; whether GitGuardian builds out the full NHI-platform feature set at the depth of Astrix / Oasis / Entro is the open question, but the baseline of strong detector quality and research credibility is a real asset.

Practical notes

  • Deployment for the detection product is fast (GitHub App, CI integration, API). Enterprise rollouts at scale still take planning but the barrier to first value is low.
  • Pricing has both SaaS and self-hosted tiers; enterprise deployments negotiated.
  • Honeytoken deserves separate attention, it's one of the few detection primitives with a clear low-false-positive signal for NHI-adjacent compromise.
  • For organisations new to NHI governance, GitGuardian is often the fastest path to meaningful early wins on the secrets-sprawl dimension while a broader NHI programme is being scoped.

When GitGuardian makes sense

GitGuardian is a reasonable shortlist candidate when the driver is:

  • "We have secrets leaking into GitHub and we need to stop that this quarter."
  • "We need public-scope monitoring for our organisation's exposure."
  • "We want honeytoken tripwires in our environment."
  • "We're building out NHI governance and want to start with the credential surface."

Less obvious fit when the driver is:

  • "We need deep SaaS OAuth-token discovery as our first problem", Astrix is more oriented there.
  • "We need enterprise lifecycle workflow as our primary organising principle", Oasis foregrounds that.
  • "We need a secrets manager", GitGuardian detects, it doesn't vault.

What we don't know

  • Current ARR and precise customer count are not publicly disclosed at recent granularity.
  • The depth of the NHI Governance module relative to startup platforms at point deployment, best validated during POC.

Assess your own NHI programme.

Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.