home
Products
Developer Endpoint Protection
GitGuardian Developer Endpoint Protection detects intrusion on your developers workstations, finds secrets sitting there before attackers do, and stops them leaking by your developers' agents with AI Hooks.
Endpoint Protection is only available for workspaces with a Business or Enterprise plan.
Machine scans with secrets findings, MCP tool calls, and complete AI agents sessions require ClickHouse on your instance.
Why securing your endpoints matter
Repositories, CI, and collaboration tools only see secrets that leave the laptop.
API keys in .env files, tokens in shell history, and credentials in MCP or AI coding agent configs often stay on the machine for days, weeks or months.
Endpoint Protection closes that gap with the same ggshield engine many teams already run in pre-commit or CI, deployed at scale through your MDM on a schedule (not a continuous EDR-style agent).
Alongside that inventory, honeytoken protection adds intrusion detection to the same deployment. It plants a decoy credential where credential harvesters look first, so you are alerted the moment one of your machines is compromised.
Where to go next
- Getting started: try Endpoint Protection on a single machine
- Core concepts: capabilities, privacy model, and what is scanned
- Protect endpoints with Honeytokens: turn every machine into a tripwire for credential harvesters
- Monitor coverage: track scanning and honeytoken coverage across the fleet
- Remediate findings: act on the secrets discovered on your endpoints
- Prevent leaks with AI Hooks: block secrets in prompts and tool calls in AI coding tools
- Deploy Endpoint Protection: MDM rollout with a service account token