Skip to main content

SaaS vs Self-Hosted

Core concepts​

SaaS vs Self-Hosted​

  • SaaS (Software-as-a-Service) means the application is hosted and maintained by the vendor. Example: GitGuardian SaaS is hosted on GitGuardian's servers, start for free!
  • Self-Hosted or On-Premise means the application is hosted on the customer's servers. Example: GitGuardian Self-Hosted is deployed on the customer's servers, choose your installation method.

Deployment​

  • SaaS: GitGuardian manages and controls the servers, databases, and infrastructure.
  • Self-Hosted: GitGuardian ensures compatibility with the customer’s environment.

For more details about self-hosted, refer to the System Requirements page.

Versions and Upgrades​

  • SaaS: GitGuardian controls version releases and can quickly address issues with hotfixes or rollbacks. (SaaS Release Notes)
  • Self-Hosted: The customer decides when to deploy new versions. GitGuardian provides support when needed and sends newsletters with each new release. (Self-Hosted Release Notes)

For more details about self-hosted, refer to the Upgrade page.

Maintenance​

  • SaaS: GitGuardian monitors the platform and handles alerts.
  • Self-Hosted: GitGuardian has no direct visibility and includes self-monitoring capabilities within the platform, managed by the customer.

For more details about self-hosted, refer to the Health Checks page.

Support and Debugging​

  • SaaS: GitGuardian has full access to data and logs, enabling quick bug identification and fixes.
  • Self-Hosted: GitGuardian relies on customer-provided data ("support bundle") to investigate issues, potentially lengthening the resolution process.

For more details about self-hosted, refer to the Support page.

Feature matrix​

The software running in our SaaS and Self-Hosted solutions is essentially the same. However, some features are not available in Self-Hosted versions due to significant differences in environments, requiring more effort for them to work in a self-hosted setup. The tables below highlight some of the differences between our SaaS and Self-Hosted offerings.

  • ✅ available
  • ⌛ coming soon
  • ❌ not available

Secrets scanning sources​

For more details, refer to the Secrets Scanning Integrations Overview page.

Scan source nameGitGuardian SaaSGitGuardian Self-HostedAdditional Details
GitHub.com✅✅
GitHub Enterprise Server✅✅
GitLab.com✅✅
GitLab Self-Hosted Community Edition✅✅
GitLab Self-Hosted Premium/Ultimate Plan✅✅
Bitbucket Cloud✅✅ (2025.2.0)
Bitbucket Server/Data Center✅✅
Slack✅✅ (2024.3.0)
Microsoft Teams✅✅ (2024.3.0)
Jira Cloud✅✅ (2024.4.0)Recurrent scanning instead of webhooks from 2026.6.0
Jira Data Center✅✅ (2024.12.0)
ServiceNow✅✅ (2025.5.0)No historical scan
Confluence Cloud✅✅ (2024.7.0)
Confluence Data Center✅✅ (2024.11.0)
Azure Container Registry✅✅ (2025.6.0)
Google Artifact Registry✅✅ (2025.6.0)
JFrog Container Registry✅✅ (2025.6.0)
DockerHub✅✅ (2025.6.0)
AWS Container Registry (ECR)✅✅ (2025.8.0)
Microsoft SharePoint Online✅✅ (2025.9.0)
Microsoft OneDrive✅✅ (2025.9.0)
Bring Your Own Sources✅✅ (2025.9.0)

Alerting and Notifications​

For more details, refer to the Alerting and Notifications page.

Notifier nameGitGuardian SaaSGitGuardian Self-Hosted
Slack✅✅
PagerDuty✅✅
Splunk✅✅
Discord✅✅
Jira Cloud✅✅ (2024.5.0)
Jira Data Center✅✅ (2024.12.0)
Microsoft Teams✅✅ (2025.1.0)

Honeytoken​

For more details, refer to the Honeytoken page.

Feature NameGitGuardian SaaSGitGuardian Self-HostedAdditional Details
Honeytoken✅✅
Honeytoken Deployment Jobs✅✅ (2024.4.0)
Honeytoken "Publicly Exposed" Detailed Location✅❌The “Publicly Exposed” tag exists for both, but exact location on GitHub.com is available only for SaaS.

Other features​

Feature NameGitGuardian SaaSGitGuardian Self-HostedAdditional Details
AI Filters✅✅ (2026.6.0)
Remediation Tracking✅✅ (2025.1.0)
False Positive Remover (Machine Learning)✅✅ (2025.1.0)
Secret Enricher (Machine Learning)✅✅ (2025.3.0)
Similar Incident Grouping (Machine Learning)✅⌛Not supported on self-hosted yet but will be added in a future release.
Incident Prioritization Risk Score (Machine Learning)✅⌛Not supported on self-hosted yet but will be added in a future release.
Public Monitoring✅✅ (2026.7.0)Detects secrets leaked on public sources. On self-hosted, requires outbound network access to reach GitGuardian's Public Monitoring service.
Secret "Publicly Leaked" Tag✅PartialSelf-hosted: "Source publicly visible" is always available; "Public incident linked" additionally requires the Public Monitoring feature (available from 2026.7.0); "Outside perimeter" is not available on self-hosted. SaaS: all three exposure types are visible with a Public Monitoring subscription.
Secrets Analyzer✅✅ (2025.4.0)
Advanced Analytics✅✅ (2025.12.0)
Analytics Overview✅⌛Coming soon...
Secrets Manager integration✅✅ (2025.3.0)ggscout is deployed on the GitGuardian Self-Hosted cluster
IP allowlist✅❌This feature is not available on self-hosted environments, as there are alternative methods to restrict access.
GG Bridge✅✅ (2026.9.0)On self-hosted, you install the bridge server yourself and declare bridges in your Helm values: see GitGuardian Bridge Self-Hosted.
GitGuardian Assistant✅⌛
Generic Detectors for non-VCS sources✅⌛
GitGuardian MCP server✅✅ (2026.7.0)