All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
GitGuardian sells secrets detection and machine-identity governance to security engineering and identity teams. It has watched public GitHub for leaked credentials since 2018, and an academic benchmark of nine secret-detection tools opens by citing GitGuardian's count of those leaks. The same detection now runs inside customer repositories, build pipelines and chat tools, and reaches the service accounts and AI agents holding the credentials. Its command-line scanner is open source without giving away the engine, because the tool calls GitGuardian's own hosted service to do the detection. It is strongest where credentials are scattered across tools no single platform owns, and least differentiated on the repository, where GitHub's own scanner was measured as the most precise of the nine.
| Description | GitGuardian discovers an organization's secrets, prioritizes and remediates the leaks at scale, and protects the non-human identities those credentials belong to, reducing exposure to breaches that start with a stolen credential. | [f1] |
|---|---|---|
| Founded | 2017 | [f2] |
| Funding | $106M total | [f2] |
| Latest funding | $50M Series C (February 2026), led by Insight Partners | [f2] |
| Product | What it does |
|---|---|
| GitGuardian Platform | Platform for finding leaked credentials across repositories, pipelines, chat tools and developer machines, governing the machine identities that hold them, and planting decoy credentials. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
GitGuardian finds every secret used by machine identities across a customer's systems, including secrets outside vaults, which places the data row. Those machine identities are the users row. The scanning reaches the repositories and pipelines where code is built, which places the applications row. [f3]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | GitGuardian names its buyers plainly, selling to developers, security operations analysts and the identity teams that own machine accounts, and the leaked-credential problem it sells against is real and widely worked on. What the reviewed record does not carry is independent quantification of the pain itself. The one outside study here measures how well nine detection tools perform rather than how much damage the leaks cause, and it takes its figure for the scale of the problem from GitGuardian's own monitoring. [s16, s1, s2] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Product pages document mechanism rather than slogans. The ggscout collector reads metadata out of vaults, hashes it inside the customer's environment, and sends only fingerprints, the command-line scanner covers more than 550 credential types at the pre-commit stage, and the honeytoken engine separates tripped decoys from real exposures. An outside technical evaluation exists as well, since the North Carolina State University benchmark ran the scanner against an 818-repository corpus and rated its precision and recall relatively low against eight rivals. [s7, s6, s3, s16] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is credible and dated. By the ratios GitGuardian cites, machine accounts and AI agents now outnumber human users by a wide margin, and GitGuardian shipped its non-human identity governance line in 2025 and a developer endpoint line in 2026 against that shift. What the reviewed record does not carry is a second, independently documented buyer-side signal from the past year. Investor conviction is not buyer demand, the customer counts come from the company, and no independently documented regulatory driver or analyst category note appears in the reviewed sources. [s4, s1, s9, s19] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Eric Fourrier and Jérémy Thomas founded GitGuardian in 2017 while working as data scientists and software engineers, and built it from a side project that collected public GitHub commits into a company that has raised 106 million dollars. Fourrier is now chief executive, a role Thomas held at the Series B in 2021. The reviewed record shows no prior exit and no earlier named product either founder built, which is what separates this from the rung above. [s4, s10, s9] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Named enterprise references appear on both sides of the record. SiliconANGLE lists DigitalOcean, Snowflake, Datadog, ING Groep, Euronext and BASF as customers, the company separately names Deutsche Telekom and BASF, and its own site carries named practitioners at Vermeer, Qlik and Orange Business speaking about the product. A free tier for up to 25 developers and the GitHub Marketplace listing give the motion a second, self-serve path that does not depend on a sales conversation. [s18, s19, s1, s5, s4] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | GitGuardian has raised 106 million dollars over nine years, most recently 50 million dollars in February 2026, and the raise is proportional to a company selling four core capabilities into enterprises across North America and Europe. Shipping is visible across those lines. What is missing is any confirmation of output per dollar, since no revenue or margin figure appears anywhere in the reviewed sources and the growth ratios the company publishes reach the record only through the company. [s9, s4, s19, s5] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Three independent outlets describe GitGuardian in overlapping terms drawn from the same two categories. SecurityWeek calls it a secrets security firm, SiliconANGLE calls it a non-human identity security platform company, and DevOps.com calls it a non-human identity security and automated secrets detection and remediation company. Secrets detection is an established line item and machine-identity governance is an emerging one, so a buyer knows which budget this comes out of. [s9, s18, s12] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Real friction exists, because GitGuardian looks across repositories, build pipelines, chat and ticketing tools, vaults and developer laptops rather than one platform, and reconciles what it finds against what is stored in a vault. The friction is not structural. GitHub ships its own secret scanner, which the North Carolina State University benchmark measured as the most precise of the nine tools it tested, so the code host GitGuardian also distributes through sells a competing capability. [s1, s7, s16] |
GitGuardian sells to three groups at once. Developers get a scanner that runs before a commit leaves a laptop, security operations analysts get the queue of exposures to close, and the identity team gets an inventory of the machine accounts those credentials belong to. The company frames the problem as credentials sitting where nobody put them deliberately, in a personal repository, a chat message or a build pipeline.
How badly the field currently solves this has independent measurement behind it. North Carolina State University researchers evaluated nine secret-detection tools against a shared corpus of repositories and found top precision of 75 percent, 46 percent for the runner-up, and five of the nine below 7 percent. That paper also opens by citing GitGuardian's own count of leaks across public GitHub, which is how the company's monitoring became the figure that benchmark cites for the scale of the problem, rather than a reference other researchers use.
The newer half of the problem is who holds the credential rather than where it leaked. Service accounts, API keys, OAuth tokens and AI agents outnumber human users by a wide margin, and GitGuardian shipped a non-human identity governance line in 2025 to inventory them, attribute owners and flag the ones that are stale or over-privileged. [s16, s1, s2, s4]
GitGuardian describes four core capabilities. Internal Secrets Monitoring watches a customer's own repositories, pipelines, registries and collaboration tools, Public Secrets Monitoring watches public GitHub, NHI Governance inventories machine identities, and Developer Endpoint Protection extends coverage to the developer's own machine. Honeytoken ships inside NHI Governance, planting decoy credentials that alert when an intruder uses one.
Two named tools carry the work into the places secrets live. The ggshield command-line scanner detects more than 550 credential types at the pre-commit stage and inside build pipelines, and it needs an API key because the detection itself runs as GitGuardian's hosted service. The ggscout collector reads secrets metadata out of HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, Google Secret Manager, CyberArk Conjur Cloud, Akeyless and Delinea, hashes it inside the customer's environment, and sends fingerprints and metadata rather than plaintext.
The reconciliation between those two halves is the product's argument. Finding a credential in a chat message means little on its own, and matching it to a vault entry, an owner and a set of permissions is what turns it into a ticket somebody can close. The company describes agentic prioritization triaging incidents and auto-routing them to the right developer.
An outside evaluation of the free scanner exists and is not flattering. The North Carolina State University benchmark ran version 1.14.3 against 818 repositories. On the 15-repository sample the researchers timed, it was the slowest of the eight tools they could time, at 4.8 hours, with precision and recall the researchers described as relatively low, and only 18 percent of the true secrets it found were also found by Gitleaks. That test dates from 2023 and covers the free command-line tool rather than the platform sold today, which leaves the current engine's accuracy measured only by the company. [s1, s6, s7, s16, s3, s5, s9]
GitGuardian competes against the code host itself as well as against the identity vendors. GitHub ships its own secret scanner, and the North Carolina State University benchmark measured that scanner as the most precise of the nine it tested, at 75 percent, so the platform GitGuardian also distributes through sells a competing capability.
The company's stated answer is breadth rather than depth on any one surface. It covers repositories it does not host, chat and ticketing tools, container registries, developer laptops and the vaults themselves, and its pitch is finding what never made it into a vault rather than protecting what did. Its own site states the case as vaults protecting what is inside them while GitGuardian finds the API key in Slack and the credential in a personal repository.
At the Series B in December 2021 the company said it would use the money to build a code security platform able to compete with companies such as Snyk. The direction since has bent toward identity rather than application security, which puts it beside the machine-identity governance vendors rather than the code scanners it once named. [s16, s1, s10, s7]
Two motions run in parallel. A free Starter plan covers up to 25 developers with no credit card and a GitHub Marketplace listing puts the product where developers already shop for security apps, alongside a claimed reach of more than 600,000 developers. The paid motion is a quoted deal through Growth and Enterprise. Growth carries internal monitoring, limited public monitoring, remediation playbooks and single sign-on, and Enterprise adds machine-identity governance, wider public monitoring, collaboration-tool sources and self-hosted deployment. Licenses can also be bought through the AWS Marketplace.
The named-customer record is genuine and mostly reaches the public through the company. SiliconANGLE lists DigitalOcean, Snowflake, Datadog, ING Groep, Euronext and BASF, and GitGuardian separately names Deutsche Telekom and BASF and publishes named practitioners at Vermeer, Qlik and Orange Business speaking about their deployments.
Scale figures are the company's own measurement. GitGuardian reports more than 115,000 developers inside enterprise customers, more than 610,000 enterprise repositories monitored, more than 210,000 connected collaboration sources and more than 16 million free users' repositories, with 70 percent of revenue from the United States. SiliconANGLE repeats three of those figures. No revenue amount appears anywhere in the reviewed sources. [s5, s1, s18, s19, s4]
Eric Fourrier and Jérémy Thomas started GitGuardian in 2017 as a side project while working full-time as data scientists and software engineers, collecting public GitHub commits in real time until the scale of the leakage became clear. Fourrier is chief executive and co-founder today. Thomas held the chief executive role at the Series B in December 2021, when SecurityWeek reported he would move from France to the United States to open an American office, so coverage from that period names a different person in the job.
The company's research output is what carries its public standing. Its measurement of leaked credentials across public GitHub is cited by that benchmark as the reference figure for the problem, which is an unusual position for a vendor to hold in a market it also sells into.
The reviewed record shows no prior exit and no earlier named product either founder built before this one. Investor support is broad, with Insight Partners leading the 2026 round alongside Eurazeo, Balderton, Sapphire Ventures, Quadrille Capital, Fly Ventures and BPI. A filing on the United States Securities and Exchange Commission's EDGAR system covering the year ended December 31, 2025 lists GitGuardian SAS of Paris among equity investments held at five percent or more, which is where the French legal entity behind the product is on record. [s4, s10, s16, s9, s15]
Two things carry the trust story. One is architecture: the ggscout collector hashes secrets metadata inside the customer's own environment and exports only hashed fingerprints and metadata, so the plaintext credential stays where it already sits. An enterprise buyer can also take a self-hosted deployment instead of the hosted service.
The other is a published trust record with real content behind it. GitGuardian's trust center states annual SOC 2 Type II audits by Prescient Assurance, maintained since 2022, alongside GDPR, encryption in transit and at rest, independent penetration tests and a 48-hour incident notification commitment. It also records monthly vulnerability scans and a private bug bounty.
Separately from what it holds, GitGuardian sells compliance as a reason to buy. Its site lists PCI DSS, NIS2, DORA, SOC 2, ISO 27001, SOX and GDPR as frameworks that now expect demonstrable control over secrets and machine identities, which describes the buyer's own obligations rather than GitGuardian's attestations. [s7, s5, s8, s1]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Snyk | competes with | GitGuardian said at its Series B that it would build a code security platform able to compete with companies such as Snyk. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Semgrep | competes with | Competes for the same application security budget inside engineering organizations. | |
| Cycode | competes with | Competes for the same software supply chain security buyer inside engineering organizations. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Astrix Security | competes with | Competes for the non-human identity governance buyer in the identity and access management team. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Entro Security | competes with | Competes for the same machine-identity and secrets buyer inside the identity team. | |
| Oasis Security | competes with | Competes for the non-human identity lifecycle buyer. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Akeyless | adjacent | Adjacent rather than competing, because GitGuardian sells the search for credentials that were never put in a secrets manager, and ggscout reads from Akeyless as one such store. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| CyberArk | adjacent | Adjacent and also an integration partner, since ggscout reads secrets metadata from CyberArk Conjur Cloud among other vault products. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with GitGuardian.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
GitGuardian is durable on the detection service and thin nearly everywhere else. In the default deployment the scanning runs on the company's side of the line, which is why its open-source command-line tool needs an API key to work at all. The detector set covering more than 550 credential types stays with the vendor. Leaving costs the work of re-integrating repositories, pipelines, chat tools and vault connectors, and the cited record does not size that migration. A free plan for 25 developers and a self-serve entry point put much of the adoption outside any procurement review. It fits best where credentials are scattered across tools no single platform owns.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers pay for scanning, an inventory and a remediation workflow, all of which the software produces on its own. The findings arrive as incidents routed to a developer, and the customer's own people decide what to rotate. Nothing in the reviewed record shows GitGuardian taking on judgment, accountability or liability for the outcome. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Real friction accumulates: connectors into repositories, build pipelines, chat and ticketing tools, read access configured against several vault products, and the remediation playbooks and incident routing a security team configures on top. The cited record documents no mechanism beyond that integration and workflow effort, and it does not size the migration, so this is friction rather than a documented barrier to leaving. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The trust center records SOC 2 Type II maintained since 2022 with a named auditor, GDPR, independent penetration tests and cybersecurity insurance. Each of those a funded competitor obtains through ordinary enterprise preparation, so they ease a procurement review rather than block a replacement. The reviewed sources identify no federal authorization, no product-carried mandate and no retained liability that would. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Distinguishing a live credential from a random string across more than 550 credential types, at the speed of a pre-commit hook and across the whole public commit stream, is detection engineering rather than integration work. How hard the problem is has been measured rather than asserted. In an academic comparison of nine tools, five scored below 7 percent precision and the top score was 75 percent. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The evidenced buyer band runs from a single team to a regulated enterprise. Named customers include a bank and a stock exchange operator, the kind of buyer that purchases behind procurement and legal review. At the other end, the free plan covers up to 25 developers with no credit card and the GitHub Marketplace listing lets a team start without a purchase decision. So adoption can begin without reaching a purchasing review at all. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | GitGuardian is a platform that observes rather than infrastructure that anything runs on. No customer traffic and no authentication flow passes through it, and the ggscout collector reads from the vaults that do sit in that path. Removing it stops the scanning and the inventory rather than an application. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The detector set is a retained asset rather than a technique in use. The command-line tool is open source, yet an academic evaluation records that it needs an API key because the scanning runs through GitGuardian's own service, so the logic covering more than 550 credential types is not in the public repository. A funded rival could accumulate comparable coverage with time and effort, which is this rung's own standard. |
GitGuardian segments by the team that has to act on a finding rather than by company size. Developers get a scanner that runs before a commit leaves the laptop, security operations analysts get the queue of exposures to close, and the identity team gets an inventory of the machine accounts behind those credentials. The vendor writes the same split into its own navigation, with pages for developers, security operations analysts, security engineers and identity and access management.
The commercial segment is the enterprise with credentials scattered across tools it does not host. Growth carries internal monitoring, limited public monitoring, remediation playbooks and single sign-on, while machine-identity governance, wider public monitoring, collaboration and file-storage sources, and self-hosted deployment are held for Enterprise. So the customer with one code host and one vault has much less to buy than the customer with repositories, chat, ticketing and several vaults.
Underneath sits a self-serve segment that never talks to sales. The free Starter plan covers up to 25 developers with no credit card, and the GitHub Marketplace listing puts the product in front of developers choosing security apps for themselves.
GitGuardian describes four core capabilities covering the places a credential can end up. Internal Secrets Monitoring watches a customer's repositories, pipelines, registries and collaboration tools, Public Secrets Monitoring watches public GitHub, NHI Governance inventories machine identities, and Developer Endpoint Protection extends coverage to the developer's own machine. Honeytoken ships inside NHI Governance, planting decoy credentials that alert when an intruder uses one.
Two tools carry that into the customer's environment. The ggshield command-line scanner detects more than 550 credential types at the pre-commit stage, and it needs an API key because the detection itself runs as GitGuardian's hosted service. The ggscout collector reads secrets metadata from HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, Google Secret Manager, CyberArk Conjur Cloud, Akeyless and Delinea Secret Server, hashes it inside the customer's environment, and sends fingerprints and metadata rather than plaintext.
The AI claim is about triage rather than detection. GitGuardian describes agentic prioritization that triages incidents the way a security operations engineer would, and auto-routing that assigns each one to the right developer. It also ships a server for the Model Context Protocol, so a coding agent can scan files, manage incidents and place honeytokens from inside an editor such as Cursor or Windsurf. The company describes that server as built with read-only permissions.
Outside measurement of the detection exists and is unflattering. North Carolina State University researchers compared nine tools against 818 repositories and ran ggshield version 1.14.3. On the 15-repository sample they timed, it was the slowest tool, at 4.8 hours, with precision and recall the researchers described as relatively low. Only 18 percent of the true secrets it found were also found by Gitleaks. That test covers the free command-line tool in 2023 rather than the platform sold now, which leaves the current engine's accuracy measured only by the company.
Two motions run side by side. The free Starter plan and the GitHub Marketplace listing pull developers in without a conversation, and the company claims a reach of more than 600,000 developers. The paid motion is a quoted deal through Growth and Enterprise, and Enterprise is where machine-identity governance, wider public secrets monitoring and self-hosted deployment live. Licenses can also be bought through the AWS Marketplace.
Named references sit on both sides of the record. SiliconANGLE lists DigitalOcean, Snowflake, Datadog, ING Groep, Euronext and BASF as customers, GitGuardian separately names Deutsche Telekom and BASF, and its own site carries named practitioners at Vermeer, Qlik and Orange Business describing what the product did for them.
Geography is concentrated and the company says so. Seventy percent of revenue comes from the United States, and North America supplied more than 80 percent of new annual recurring revenue in 2025. The Series C proceeds are earmarked for Asia Pacific, South America and the Middle East alongside the existing markets.
GitGuardian meters by developer, and it defines the term. For internal monitoring and machine-identity governance a developer is any active contributor to a secured project who has committed in the last 90 days, so the meter tracks working engineers rather than seats or scan volume. Endpoint protection is priced separately, per endpoint per year, in two tiers.
Only the bottom tier carries a published rate. Starter is free for up to 25 developers with no credit card, and both Growth and Enterprise say to contact sales, so the price of what an enterprise actually buys is not public.
What each tier includes is public, and the packaging carries the strategy. Growth bundles internal monitoring across code, pipelines and registries, limited public monitoring, remediation playbooks and single sign-on. Enterprise adds machine-identity governance with honeytokens, wider public monitoring, collaboration and file-storage sources, self-hosted deployment and a twelve-month audit log.
In the default deployment the customer runs the collectors and GitGuardian runs the detection. The ggshield scanner and the ggscout collector install in the customer's own pipelines and infrastructure, and an academic evaluation of the scanner records that it calls GitGuardian's API to identify a secret, so the detection logic sits on the vendor's side of that line.
The design keeps plaintext credentials where they already are. GitGuardian describes ggscout collecting secrets metadata, converting it into an encrypted form inside the customer's environment, and sending only that, and the ggscout page states that plaintext secrets never leave, only hashed fingerprints and metadata.
An enterprise that will not run on the vendor's cloud has another option. Self-hosted deployment is listed as available at the Enterprise tier and on the trust center, which moves the platform inside the customer's own perimeter.
Half of the trust argument is architectural. Secrets metadata is hashed inside the customer's environment before it is sent, plaintext credentials stay put, and an enterprise can take a self-hosted deployment instead of the vendor's cloud.
The other half is a published trust record with real content behind it. GitGuardian's trust center states annual SOC 2 Type II audits by Prescient Assurance, maintained since 2022, alongside GDPR, encryption in transit and at rest, independent penetration tests and a 48-hour incident notification commitment. It also records monthly vulnerability scans, a private bug bounty and cybersecurity insurance. Enterprise buyers get twelve months of audit log retention.
Separately from what it holds, GitGuardian sells compliance as a reason to buy. Its homepage lists PCI DSS, CIS, NIS2, SOC 2, DORA, ISO 27001, SOX and GDPR as frameworks that now expect demonstrable control over secrets and machine identities, which describes what the buyer owes an auditor rather than what GitGuardian is certified against.
GitGuardian positions itself as one platform spanning the life of a credential, from the moment a developer writes one to the moment a security team rotates or revokes it. The pitch on its homepage is explicitly complementary to the vault vendors rather than competitive with them: vaults protect what is inside them, and GitGuardian finds the key in a chat message or a personal repository that never made it in.
That posture makes the vault vendors partners in the plumbing. The ggscout collector reads from HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, Google Secret Manager, CyberArk Conjur Cloud, Akeyless and Delinea Secret Server, so the product depends on read access to stores other companies sell.
The developer-facing edge of the ecosystem is where the position is thinnest. The free command-line scanner is open source but calls GitGuardian's hosted service to do the detection. The code host it distributes through ships a competing scanner of its own, which North Carolina State University researchers measured as the most precise of the nine tools they compared.
Eric Fourrier and Jérémy Thomas started GitGuardian in 2017 while working full-time as data scientists and software engineers, collecting public GitHub commits in real time until the scale of the leakage became clear. Fourrier is co-founder and chief executive now. Thomas held the chief executive role at the Series B in December 2021, when SecurityWeek reported he would move to the United States to open an American office, so coverage from that period names a different person in the job.
Execution shows in a steady release cadence rather than a single launch. The company's own timeline records public secrets monitoring in 2018, internal secrets monitoring in 2020, honeytokens in 2023, machine-identity governance in 2025, and developer endpoint protection in 2026. A filing on the United States Securities and Exchange Commission's EDGAR system covering the year ended December 31, 2025 lists GitGuardian SAS of Paris among equity investments held at five percent or more.
The public standing this team has built rests on research rather than pedigree. GitGuardian's measurement of leaked credentials across public GitHub is what an academic benchmark of nine detection tools cites when it sets up the size of the problem, so a vendor's own count has become a figure researchers work from in the market it sells into.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | GitGuardian Trust Center | official | 2026-09-04 |
| f2 | SecurityWeek on the GitGuardian Series C | press | 2026-09-04 |
| f3 | GitGuardian NHI Governance page | official | 2026-09-04 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | GitGuardian homepage “Monitor every source where secrets leak: code repositories, CI/CD, container registries, Jira, Slack, and public GitHub.” | official | 2026-09-04 |
| s2 | GitGuardian NHI Governance page “Our CLI tool called ggscout, safely collects secrets and their metadata from your secrets managers.” | official | 2026-09-04 |
| s3 | GitGuardian Honeytoken product page “Create a honeytoken through the GitGuardian dashboard or API.” | official | 2026-09-04 |
| s4 | GitGuardian About Us page (founding story, product timeline, investor list) “When Eric and Jérémy founded GitGuardian in 2017, they were working full-time as data scientists and software engineers.” | official | 2026-09-04 |
| s5 | GitGuardian pricing page “Up to 25 devs” | official | 2026-09-04 |
| s6 | GitGuardian ggshield command-line scanner page “550+ types of hardcoded secrets” | official | 2026-09-04 |
| s7 | GitGuardian ggscout collector page “ggscout is an external collector that collects secrets metadata from your Secrets Managers and other sources, reconciles it with GitGuardian incidents.” | official | 2026-09-04 |
| s8 | GitGuardian Trust Center (rendered capture; compliance, hosting, encryption and testing summary) “Our trust programme includes annual SOC 2 Type II audits by Prescient Assurance, strong encryption in transit and at rest, independent penetration tests, and a 48-hour incident notification commitment.” | official | 2026-09-04 |
| s9 | SecurityWeek: GitGuardian Series C funding article “Secrets security firm GitGuardian announced on Wednesday that it has raised $50 million to advance non-human identity governance and AI agent security.” | press | 2026-09-04 |
| s10 | SecurityWeek: GitGuardian Series B funding article “Code security company GitGuardian on Tuesday announced raising $44 million in a Series B funding round, which brings the total raised by the company to $56 million.” | press | 2026-09-04 |
| s12 | DevOps.com: column on the GitGuardian MCP server “Existing as a kind of combined DevOps traffic light and GPS route map system for agentic injection, latest to pledge allegiance to the MCP mantra is GitGuardian, a non-human identity (NHI) security, automated secrets detection and remediation company.” | press | 2026-09-04 |
| s13 | Help Net Security (labelled Sponsored industry news): GitGuardian multi-vault integration announcement “With Non-Human Identities—digital references used to authenticate machine-to-machine access—now outnumbering human users 100:1, organizations face unprecedented challenges in securing their secrets across multiple vault platforms.” | press | 2026-09-04 |
| s15 | SEC EDGAR XBRL report: equity investments with ownership of at least 5 percent, twelve months ended Dec. 31, 2025 “GitGuardian SAS, Paris, France” | regulatory | 2026-09-04 |
| s16 | arXiv 2307.00714: A Comparative Study of Software Secrets Reporting by Secret Detection Tools “For example, ggshield took the highest amount of time (4.8 hours) among all the tools, but the precision and recall were relatively low.” | research | 2026-09-04 |
| s18 | SiliconANGLE: GitGuardian Series C article “Notable GitGuardian customers included DigitalOcean Holdings Inc., Snowflake Inc., Datadog Inc., ING Groep N.V., Euronext N.V. and BASF SE.” | press | 2026-09-04 |
| s19 | GitGuardian blog: 2025 enterprise momentum announcement “PARIS, France, and NEW-YORK, NY — January 14th, 2026” | official | 2026-09-04 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | GitGuardian homepage “Monitor every source where secrets leak: code repositories, CI/CD, container registries, Jira, Slack, and public GitHub.” | official | 2026-09-04 |
| s2 | GitGuardian NHI Governance page “Our CLI tool called ggscout, safely collects secrets and their metadata from your secrets managers.” | official | 2026-09-04 |
| s3 | GitGuardian Honeytoken product page “Create a honeytoken through the GitGuardian dashboard or API.” | official | 2026-09-04 |
| s4 | GitGuardian About Us page (founding story, product timeline, investor list) “When Eric and Jérémy founded GitGuardian in 2017, they were working full-time as data scientists and software engineers.” | official | 2026-09-04 |
| s5 | GitGuardian pricing page “Up to 25 devs” | official | 2026-09-04 |
| s6 | GitGuardian ggshield command-line scanner page “550+ types of hardcoded secrets” | official | 2026-09-04 |
| s7 | GitGuardian ggscout collector page “ggscout is an external collector that collects secrets metadata from your Secrets Managers and other sources, reconciles it with GitGuardian incidents.” | official | 2026-09-04 |
| s8 | GitGuardian Trust Center (rendered capture; compliance, hosting, encryption and testing summary) “Our trust programme includes annual SOC 2 Type II audits by Prescient Assurance, strong encryption in transit and at rest, independent penetration tests, and a 48-hour incident notification commitment.” | official | 2026-09-04 |
| s9 | SecurityWeek: GitGuardian Series C funding article “Secrets security firm GitGuardian announced on Wednesday that it has raised $50 million to advance non-human identity governance and AI agent security.” | press | 2026-09-04 |
| s10 | SecurityWeek: GitGuardian Series B funding article “Code security company GitGuardian on Tuesday announced raising $44 million in a Series B funding round, which brings the total raised by the company to $56 million.” | press | 2026-09-04 |
| s12 | DevOps.com: column on the GitGuardian MCP server “Existing as a kind of combined DevOps traffic light and GPS route map system for agentic injection, latest to pledge allegiance to the MCP mantra is GitGuardian, a non-human identity (NHI) security, automated secrets detection and remediation company.” | press | 2026-09-04 |
| s13 | Help Net Security (labelled Sponsored industry news): GitGuardian multi-vault integration announcement “With Non-Human Identities—digital references used to authenticate machine-to-machine access—now outnumbering human users 100:1, organizations face unprecedented challenges in securing their secrets across multiple vault platforms.” | press | 2026-09-04 |
| s15 | SEC EDGAR XBRL report: equity investments with ownership of at least 5 percent, twelve months ended Dec. 31, 2025 “GitGuardian SAS, Paris, France” | regulatory | 2026-09-04 |
| s16 | arXiv 2307.00714: A Comparative Study of Software Secrets Reporting by Secret Detection Tools “For example, ggshield took the highest amount of time (4.8 hours) among all the tools, but the precision and recall were relatively low.” | research | 2026-09-04 |
| s18 | SiliconANGLE: GitGuardian Series C article “Notable GitGuardian customers included DigitalOcean Holdings Inc., Snowflake Inc., Datadog Inc., ING Groep N.V., Euronext N.V. and BASF SE.” | press | 2026-09-04 |
| s19 | GitGuardian blog: 2025 enterprise momentum announcement “PARIS, France, and NEW-YORK, NY — January 14th, 2026” | official | 2026-09-04 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.