EuroMakers Logo
SoftwareJournalMy stackSubmit
SoftwareBrowse the European directoryJournalInsights on European softwareMy stackProducts you saved on this deviceSubmit Software
Back to the Journal
Editorial

GitGuardian Counts a Commit in Ninety Days

A contributing developer is a commit-author email that landed one commit on a private org repo in the last 90 days. Starter is free to 25 of those. Cross it, a 30-day trial; then private collaborative repos go dark. Honeytokens sit on Enterprise. EU SaaS is Frankfurt, not Starter.

EM

The EuroMakers Editorial Team

Researching European software

8 September 20265 min read
Editorial cover for GitGuardian Counts a Commit in Ninety Days
Editorial

The Journal · Made in Europe

The GitGuardian docs do not define a seat as someone with a login. They define an email that committed.

We define a contributing developer as a commit author email address. A contributing developer is a developer who made at least one commit to a private collaborative repository within the last 90 days.

— docs.gitguardian.com/platform/user-account/plan-usage, last updated 25 August 2026

A private collaborative repository, same page: a private repo on a VCS organisation that more than one person can push to. A personal private hobby repo is not the meter. A quiet teammate who has not committed since May is not either. One push in the window counts. Two emails from the same person count twice.

GitGuardian pricing FAQ expanded: Who counts as a developer? Public Secrets Monitoring counts anyone with one public GitHub commit; Internal Secrets Monitoring and NHI Governance count anyone with one commit in the last 90 days
gitguardian.com/pricing, 8 September 2026. Public monitoring counts a public GitHub commit anywhere. Internal monitoring counts a commit on a project you are securing, last ninety days.

GitGuardian SAS in Paris ships secrets detection. The software watches where credentials leak: GitHub, GitLab, Bitbucket, Azure DevOps, CI, containers, then Slack and Jira if you pay for those sources. ggshield is the CLI. The dashboard is where an incident gets an owner. That is the job. Not a generic AppSec suite.

GitGuardian homepage: Attackers aren't breaking in, They're logging in, with Book a demo and Start for free, and a mock NHI governance view of an openai-api-key that turned public
gitguardian.com, 8 September 2026. The banner is Developer Endpoint Protection. The mock incident is a key that went public a few minutes ago.

How you actually run it

Connect the Git host. The scanner walks commits in real time. Starter, the free card, gives unlimited real-time scanning, up to 500 historical detections, 1 GB of repository scanning, and 10,000 API calls a month. ggshield as a pre-commit hook is labelled Limited on that tier. Validity checks exist. Frequency is low until you pay.

Growth is the sales card. Internal monitoring widens to CI/CD, containers, and custom sources. Public GitHub monitoring is limited. Remediation playbooks talk to Slack, Jira, ServiceNow. SSO and SCIM land here. Up to 10 teams. US and EU data hosting is printed on this card, not on Starter. Developer Endpoint Protection is an add-on, priced per endpoint per year, mapped 1:1 to platform seats for developer machines.

Enterprise adds unlimited public monitoring, NHI governance across vaults, collaboration tools, file storage, CI logs, self-hosted Helm or KOTS plus GitGuardian Bridge, unlimited custom detectors, and a 12-month audit log. NHI Governance is where honeytokens live on the platform. Their sentence, not a catalog gloss:

When Secrets Monitoring finds an exposed credential, you can deploy a honeytoken in its place. If an attacker attempts to use it, you get instant alerts—turning remediated incidents into tripwires for future intrusion detection.

— gitguardian.com/pricing, How do GitGuardian NHI Governance and GitGuardian Internal Secrets Monitoring work together?

Twenty-five, then the private repos go dark

Starter is free up to 25 contributing developers. The docs still name that plan Free, and the paid middle Business. The shop on 8 September prints Starter, Growth, Enterprise. Same ladder. Different labels. A quote that still says Business is not a different product.

GitGuardian pricing cards: Starter free up to 25 devs with 500 historical detections and 10K API calls, Growth with Contact sales including US and EU data hosting, Enterprise with NHI governance and self-hosted deployment
gitguardian.com/pricing, 8 September 2026. Starter is the free plan. Growth and Enterprise are Contact sales. No euro figure on the page.

Cross 25 on Free and two things can happen. Adding repositories can start a 30-day Business trial by itself. If that trial is already spent, private collaborative repositories are no longer monitored. Public scanning is a different meter: one public commit anywhere on GitHub. Open-source contributors who are not employees are not supposed to inflate the public count. Employees are, including on personal public repos.

GitGuardian docs plan table: under 25 developers Free monitors all repositories; over 25 developers Free does not monitor private collaborative repositories; Trial and Business keep monitoring, with a note that exceeding 25 starts a trial or stops private-repo monitoring after it expires
docs.gitguardian.com/platform/user-account/plan-usage, 8 September 2026. The >25 Free cell is the cliff: private collaborative repositories NOT monitored.

The free plan does not get Frankfurt

Growth prints US and EU data hosting. The EU SaaS region is AWS Frankfurt, requested when you create a new Business or Enterprise account. GitGuardian’s own hosting post is blunt: the option is not available on the free plan. Existing US workspaces cannot migrate to EU. Self-host if you need the data off their SaaS entirely.

The laptop is a separate bill

On 16 June they shipped Developer Endpoint Protection inside ggshield. Not a new agent. Scheduled scans of .env files, shell history, MCP configs, AI coding-agent caches. Their diagram: only hashed metadata leave the machine. Credentials are not sent in clear text. Deploy through Intune, Jamf, or Kandji. Linux and Windows servers are still beta. It does not rotate secrets. That is Internal Monitoring and NHI. Each paid endpoint includes at least one honeytoken as a tripwire.

GitGuardian Developer Endpoint Protection: Every laptop is a credential store, with a diagram of ggshield machine scan of .env, .zshrc, mcp.json, AWS credentials and Cursor config, showing only metadata and hashed secrets leave the machine
gitguardian.com/developer-endpoint-protection, 8 September 2026. The privacy claim is on the diagram: metadata only, hashed secrets.

Their early-access number: about 150 secrets per developer laptop, some in the thousands, around 40 percent in AI directories and logs. The State of Secrets Sprawl 2026 report, 17 March, counted 28.65 million new hardcoded secrets on public GitHub in 2025. That report is why the homepage leads with logging in, not breaking in. It is not the invoice.

Who should not start here. Anyone who needs EU SaaS on Starter: Frankfurt is the next card. Anyone who wants honeytokens without Enterprise or the endpoint add-on. Anyone with 26 commit-author emails on private org repos who thought the free scanner would keep watching those repos after the trial. Anyone who needs a published euro price: Growth and Enterprise are Contact sales, also via AWS Marketplace. Anyone whose plan is to move a US workspace into Frankfurt later. Anyone who thought ggshield alone was the product: the CLI is the guardrail. The dashboard is where the ninety days are counted.

If the job is catching leaked credentials before they are used, start with the listing, then Pricing, then Plan and usage. Look for contributing developers. A login is not the unit.

New to the EuroMakers Journal? Start with how the Journal works.

#GitGuardian#Paris#France#Secrets#Security#AppSec

Find your next European tool

Browse a curated directory of software made in Europe across every category your team relies on.

Explore the directory

Keep reading

Editorial cover for Checkmk Raw Is Called Community
Editorial
7 September 2026

Checkmk Raw Is Called Community

Raw is Community. Enterprise is Pro. OpenTelemetry is Ultimate and Cloud, not Pro. On 7 September the Euro cards billed ~3,000 services as 100 hosts: Pro from €190 a month, Ultimate from €275.

5 min readRead
Editorial cover for Things 3.23 Puts a Checkbox on Repeats
Editorial
6 September 2026

Things 3.23 Puts a Checkbox on Repeats

Until 3.23, a repeating to-do in Things had no checkbox until it landed in Today. Now it does. Four Apple apps, paid once each. Things Cloud is TLS and AES at rest, not a web inbox.

5 min readRead
EuroMakers

European software, found when you need it. Origin on every listing.

Explore the directory

Discover

  • All software
  • Journal
  • My stack

Contribute

  • Submit software
  • Contact

Our standard

  • Why we list it
  • Privacy

© 2026 EuroMakers. Made with conviction in Europe.

Logos provided by Brandfetch and Logo.dev.

EuroMakers logo rising behind an illustrated Alpine valley, European town, railway, and cyclists