GitGuardian agents tell you which Public Monitoring incidents are actually yours
Release Date: August 27, 2026
![]()
On public sources, the hard question is rarely whether something is a secret. It is whether it is yours. A leak that matches your perimeter can just as easily be a developer's personal side project, a contractor's repository, or someone entirely unrelated who happens to use the same technologies. Until now, answering that meant reading commits by hand.
GitGuardian now runs AI agents over your public secret incidents and answers it for you.
What does this mean for you?
- A Company-related verdict on every analyzed incident: Related, Uncertain or Unrelated, available as a column, as a filter, and as three ready-made saved views.
- A risk score set by the agents. Unlike the previous ML score, it weighs how relevant a leak is to your company, not only the technical risk of the secret. An incident the agents rule Unrelated always scores 0, so sorting by risk score sinks the leaks that are not yours to the bottom of your list.
- The reasoning, not just the verdict. A new Analysis tab shows the company the agents identified, why they reached their conclusion, the score with its rationale, and which agent concluded.
What changes when it is enabled
The agents' risk score replaces the ML risk score on public incidents, and the Context related to company tag is superseded by the Company-related verdict. Because the analysis does not arrive at the same moment as the incident, risk score filtering is no longer available for notifications on public incidents.
Where it stands today
The agents analysis is in beta and is being rolled out progressively. Analysis of your incident history is also being extended, and may not be available for all your incidents yet.
Get Started Today!
Talk to your Customer Success Manager or contact support@gitguardian.com. They can check where your workspace stands and enable it for you.
Learn more about the agents analysis
Enhancements
- SSO & SCIM: Added support for signing in via SSO/SCIM when the identity provider does not supply first and last name, deriving these values from the user's email address.
Fixes
- Incidents: Fixed an issue where the revoke button was not displayed for revocable secrets for members with Full Access.