What's New at GitGuardian: AI Leak Triage & Laptop Secrets Scanning

We found 15x more valid secrets on developer laptops than in code repositories. In this September edition of What's New in GitGuardian, Sr. Product Managers Léna Cuissard and Emmanuelle Franquelin walk through two updates: agents that triage public secret leaks for you, and Developer Endpoint Protection coming together as one package.

Public Secrets Monitoring: agents that separate signal from noise
Public Secrets Monitoring detects corporate secrets your developers leak outside your repositories, including on personal GitHub accounts. That closes a big blind spot, but deciding which leaks actually belong to your company used to take manual investigation. Now agents do that work: each public incident is marked either "unrelated, safe to discard" or "company related, high risk, remediate now."

Developer Endpoint Protection: every laptop is a credential store
The pieces of Developer Endpoint Protection now work together:

  • Endpoint scan: an inventory of every secret on developer machines (.env files, shell history, logs, cloud credential stores, MCP configs)
  • AI hooks: prevention that stops secrets from leaking through AI coding assistants
  • Machine cleanup: removes unneeded secrets from log files, history files and more
  • The result: 15x more valid secrets found on endpoints than in repositories. Next up, helping teams move credentials out of plaintext and into safe places like password managers.

⏱️ Chapters

0:00 Intro

0:11 Public Secrets Monitoring: agents that triage public leaks

1:15 Developer Endpoint Protection: scan, AI hooks, cleanup

1:57 15x more valid secrets on endpoints than in repos

2:08 What's next: getting credentials out of plaintext

Learn more about GitGuardian: https://www.gitguardian.com/
Book a demo: https://www.gitguardian.com/book-a-demo

#github #githubsecurity #cybersecurity #secretssecurity #aisecurity