close

ggscout

Change Your Secrets Game

Stop assuming your secrets are safe—make them visible, governed, and secure.

Image
Image

ggscout

by GitGuardian

ggscout is an external collector that collects secrets metadata from your Secrets Managers and other sources, reconciles it with GitGuardian incidents.

It helps you detect, prioritize, and even push secrets securely into vaults. It never exports plaintext secrets—only hashed fingerprints and metadata.

Image

How to install GitGuardian Scout

Download the binary

To download the binary, please select the appropriate software version.

Image
LinuxOS

Download the binary within a docker image

Use the following command line to deploy GitGuardian Scout on a Docker image.

docker pull gitguardian/nhi-scout/chainguard:latest
Image
Copied

Download the helm chart

Use the following command line to deploy GitGuardian Scout on a Docker image.

helm install nhi-collector [url to download]
Image
Copied

Then install the scout, with a value file:

docker pull gitguardian/nhi-scout--install--value...
Image
Copied

Unifying Secrets.
From Inventory to Impact.

Image
Vault-wide intelligence

Scan rich metadata on every secret (direct path, TTL, rotation time, creation date). All hashed locally. No plaintext secrets ever leave your environment.

Learn how hashing works
Image
Image
End to end map for all secrets

Track vaulted and unvaulted secrets across environments. Unify them into one complete inventory—ideal for remediation, policy audits, and compliance.

See Secrets Map in action
Image
Image
Contextual prioritization

ggscout correlates secrets in vaults and other sources with exposed credentials found elsewhere. Cut through noise. Resolve what’s critical.

How detection works
Image
Image

ggscout integrates with your stack to surface and secure secrets where they live.

Integrations That Go Deep

read/write

Secrets Managers

Image
HashiCorp Vault
AWS secrets manager Logo
AWS Secrets Manager
Azure Key Vault Logo
Azure Key Vault
Image
Google Secret Manager
Image
CyberArk Conjur Cloud
Image
Akeyless
Image
Delinea Secret Server
Learn how hashing works
Image
read-only

CI/CD Systems

Gitlab Logo
GitLab CI
More integrations coming soon
Image
read-only

Infrastructure Sources

Image
Kubernetes

K8s Secrets, ConfigMaps, Deployments, and Service Accounts

More integrations coming soon
Image

Get zero trust secrets intelligence

that never exposes plaintext values outside your environment.

Image
Image

Can ggscout write to my vaults?

Yes, optionally. You can enable "push to vault" mode to help developers remediate and re-vault exposed secrets.

Can we audit what ggscout sends?

Yes. You can run a fetch-only mode to generate a JSON report locally for audit or compliance review.

Can I use ggscout for free?

Yes, ggscout is free under certain circumstances (e.g., in a free plan or for testing without an enterprise license).

Is ggscout open-source?

It's not fully open source yet, but GitGuardian aims for it. Currently, the code source is shared with customers upon request