The math is unsettling: for every human logging into enterprise systems today, roughly 82 machine identities are doing the same—service accounts, API keys, certificates, bots. Most companies have no real idea what those machines are doing or how to secure them.
That's the market GitGuardian is wagering on. The Paris-based cybersecurity firm closed a $50 million Series C on February 11, led by Insight Partners, with fresh backing from Quadrille Capital and a roster of returning investors including Balderton, Bpifrance, Eurazeo, Fly Ventures, and Sapphire Ventures. Total funding since the 2017 founding now stands at $106 million. The company isn't disclosing valuation.
The timing feels deliberate. European compliance deadlines are coming due—NIS2 enforcement is rolling out across member states after last October's deadline, and DORA took effect for financial institutions in January. In the U.S., NIST refreshed its digital identity guidance last August. Add to that the explosion of autonomous AI agents (Microsoft alone reported over a million custom agents deployed in a single quarter last year), and you have what CEO Eric Fourrier calls an inflection point for non-human identity governance.
"Organizations that once managed hundreds of service accounts will now face thousands of autonomous AI agents," Fourrier said in a statement accompanying the funding announcement. "We're moving beyond secrets detection into full NHI lifecycle governance."
A Market Built on Mistakes That Never Die
GitGuardian's platform scans code repositories, CI/CD pipelines, and collaboration tools like Slack and Jira for exposed credentials—passwords, API tokens, encryption keys that developers accidentally commit to GitHub or paste into a chat. The company says it detected and remediated 350,000 such exposures in 2025 alone across 610,000-plus repositories.
Perhaps more troubling: Fourrier noted in a company blog post that 70 percent of secrets leaked two years ago remain active. In other words, the exposure never really goes away. It just sits there, a latent vulnerability waiting for someone to notice.
That persistence helps explain why stolen credentials remain one of the most common initial access vectors in data breaches—accounting for anywhere from 16 to 24 percent depending on which dataset you trust. CyberArk's 2025 research found that 72 percent of organizations experienced certificate-related outages, while half reported incidents tied to compromised machine identities. The 82-to-1 ratio of machine-to-human identities comes from that same research.
Insight Partners, which has backed a who's-who of cybersecurity unicorns including Wiz, SentinelOne, and Darktrace, led the round. Quadrille Capital came in as a new investor, with partner Romain Stokes pointing to the "critical" nature of compliance deadlines hitting over the next 18 months as a catalyst for adoption.
Traction That Looks Real
The numbers GitGuardian is putting up suggest product-market fit, at least in segments of the market. The company ended 2025 with more than 115,000 enterprise developers under protection and over 210,000 connected collaboration sources monitored. It claims the top spot as the most-installed app on GitHub Marketplace—509,000 installations and counting.
Customer names include Snowflake, ING, BASF, and Bouygues Telecom. Sixty percent of new enterprise deals were multi-year contracts. Eighty percent of new annual recurring revenue came from North America, a signal that the company has gained traction beyond its European base.
The freemium model helps. Teams of 25 developers or fewer get free access, a wedge strategy that's driven adoption through GitGuardian's open-source CLI tool ggshield and integrations with GitHub, GitLab, and AWS Marketplace.
Beyond Secrets: Governing the Machines

GitGuardian's original pitch—scan your repos for leaked secrets—was narrow but urgent. The company is now stretching that mandate into broader non-human identity lifecycle management. Think centralized inventory and governance across vaults, cloud IAM systems, and Kubernetes environments. Not just detecting the problem, but managing these identities end-to-end.
The product suite now includes a Honeytoken module, launched in 2023, designed to detect intrusions and code leakage by planting fake credentials that trigger alerts when used. More recently, the company released an experimental MCP server that lets AI agents interact directly with GitGuardian's API for scanning and remediation—a meta move, using AI to police AI.
Fourrier says the Series C will fund three priorities: building out AI agent security capabilities, expanding enterprise-scale NHI governance, and pushing deeper into new geographies. The company plans to strengthen its foothold across the Americas and EMEA while opening beachheads in APAC, South America, and the Middle East. That means scaling go-to-market teams and likely more enterprise sales hires.
A Bet on Proliferation

The underlying assumption here is that machine identities will only multiply. AI agents, microservices architectures, API-first companies—all of it tilts toward more non-human actors operating autonomously with varying levels of privilege.
If that thesis holds, GitGuardian is positioning itself as essential infrastructure. If it doesn't—or if enterprises decide they can cobble together homegrown solutions—the company will have a tougher climb. For now, the funding and customer traction suggest the market believes the problem is real, urgent, and maybe a little underestimated.
Fourrier's framing of the challenge is stark: companies are moving from managing hundreds of service accounts to governing thousands of autonomous agents, often with minimal visibility into what those agents are doing or what credentials they hold. Whether GitGuardian can scale fast enough to capture that expanding market—and whether the market itself materializes at the pace investors expect—will define what this Series C ultimately delivers.
