GitGuardian Counts a Commit in Ninety Days
A contributing developer is a commit-author email that landed one commit on a private org repo in the last 90 days. Starter is free to 25 of those. Cross it, a 30-day trial; then private collaborative repos go dark. Honeytokens sit on Enterprise. EU SaaS is Frankfurt, not Starter.
The EuroMakers Editorial Team
Researching European software

The Journal · Made in Europe
The GitGuardian docs do not define a seat as someone with a login. They define an email that committed.
We define a contributing developer as a commit author email address. A contributing developer is a developer who made at least one commit to a private collaborative repository within the last 90 days.
— docs.gitguardian.com/platform/user-account/plan-usage, last updated 25 August 2026
A private collaborative repository, same page: a private repo on a VCS organisation that more than one person can push to. A personal private hobby repo is not the meter. A quiet teammate who has not committed since May is not either. One push in the window counts. Two emails from the same person count twice.

GitGuardian SAS in Paris ships secrets detection. The software watches where credentials leak: GitHub, GitLab, Bitbucket, Azure DevOps, CI, containers, then Slack and Jira if you pay for those sources. ggshield is the CLI. The dashboard is where an incident gets an owner. That is the job. Not a generic AppSec suite.

How you actually run it
Connect the Git host. The scanner walks commits in real time. Starter, the free card, gives unlimited real-time scanning, up to 500 historical detections, 1 GB of repository scanning, and 10,000 API calls a month. ggshield as a pre-commit hook is labelled Limited on that tier. Validity checks exist. Frequency is low until you pay.
Growth is the sales card. Internal monitoring widens to CI/CD, containers, and custom sources. Public GitHub monitoring is limited. Remediation playbooks talk to Slack, Jira, ServiceNow. SSO and SCIM land here. Up to 10 teams. US and EU data hosting is printed on this card, not on Starter. Developer Endpoint Protection is an add-on, priced per endpoint per year, mapped 1:1 to platform seats for developer machines.
Enterprise adds unlimited public monitoring, NHI governance across vaults, collaboration tools, file storage, CI logs, self-hosted Helm or KOTS plus GitGuardian Bridge, unlimited custom detectors, and a 12-month audit log. NHI Governance is where honeytokens live on the platform. Their sentence, not a catalog gloss:
When Secrets Monitoring finds an exposed credential, you can deploy a honeytoken in its place. If an attacker attempts to use it, you get instant alerts—turning remediated incidents into tripwires for future intrusion detection.
— gitguardian.com/pricing, How do GitGuardian NHI Governance and GitGuardian Internal Secrets Monitoring work together?
Twenty-five, then the private repos go dark
Starter is free up to 25 contributing developers. The docs still name that plan Free, and the paid middle Business. The shop on 8 September prints Starter, Growth, Enterprise. Same ladder. Different labels. A quote that still says Business is not a different product.

Cross 25 on Free and two things can happen. Adding repositories can start a 30-day Business trial by itself. If that trial is already spent, private collaborative repositories are no longer monitored. Public scanning is a different meter: one public commit anywhere on GitHub. Open-source contributors who are not employees are not supposed to inflate the public count. Employees are, including on personal public repos.

The laptop is a separate bill
On 16 June they shipped Developer Endpoint Protection inside ggshield. Not a new agent. Scheduled scans of .env files, shell history, MCP configs, AI coding-agent caches. Their diagram: only hashed metadata leave the machine. Credentials are not sent in clear text. Deploy through Intune, Jamf, or Kandji. Linux and Windows servers are still beta. It does not rotate secrets. That is Internal Monitoring and NHI. Each paid endpoint includes at least one honeytoken as a tripwire.

Their early-access number: about 150 secrets per developer laptop, some in the thousands, around 40 percent in AI directories and logs. The State of Secrets Sprawl 2026 report, 17 March, counted 28.65 million new hardcoded secrets on public GitHub in 2025. That report is why the homepage leads with logging in, not breaking in. It is not the invoice.
Who should not start here. Anyone who needs EU SaaS on Starter: Frankfurt is the next card. Anyone who wants honeytokens without Enterprise or the endpoint add-on. Anyone with 26 commit-author emails on private org repos who thought the free scanner would keep watching those repos after the trial. Anyone who needs a published euro price: Growth and Enterprise are Contact sales, also via AWS Marketplace. Anyone whose plan is to move a US workspace into Frankfurt later. Anyone who thought ggshield alone was the product: the CLI is the guardrail. The dashboard is where the ninety days are counted.
If the job is catching leaked credentials before they are used, start with the listing, then Pricing, then Plan and usage. Look for contributing developers. A login is not the unit.
New to the EuroMakers Journal? Start with how the Journal works.
Find your next European tool
Browse a curated directory of software made in Europe across every category your team relies on.
Explore the directory
