Try our new research platform with insights from 80,000+ expert users

GitGuardian Platform vs Trellix DLP comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
74
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
GitGuardian Platform
Average Rating
9.0
Reviews Sentiment
7.4
Number of Reviews
24
Ranking in other categories
Application Security Tools (7th), Static Application Security Testing (SAST) (5th), Data Loss Prevention (DLP) (6th), Software Supply Chain Security (4th), DevSecOps (4th)
Trellix DLP
Average Rating
7.8
Reviews Sentiment
6.9
Number of Reviews
11
Ranking in other categories
Data Loss Prevention (DLP) (10th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Joan Ging - PeerSpot reviewer
It dramatically improved our ability to detect secrets, saved us time, and reduced our mean time to remediation
While they do offer some basic reporting, more comprehensive reporting would be beneficial in the long run. This would allow me to demonstrate the value of the product over time to continue to effectively budget for this subscription, especially as they add features that may come at an additional cost. I appreciate the improvements made to reporting over the past year, but continued development in this area will be appreciated. We have encountered occasional difficulties with the Single Sign-On process. There is room for improvement in its current implementation. It works, but was not quite as smooth as the rest of the GitGuardian experience.
RiaanDu Preez - PeerSpot reviewer
Implements confidentiality principles effectively
Over the years, a lot has changed, so it is not that much at the moment. I know they are all working on changing the look and feel, the UI. It is always good to have a more modern look and feel than the old-school square blocks. Other than that, it's mainly support. Having someone within a region who understands the countries and how they approach data and information security is sometimes where the problem lies. It's not always the product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of the solution is external DNS. It is also very secure. They have their own main server and once you configure it, the product takes care of everything. There are no issues in resolving IPs and low latency is also present."
"It's very user-friendly."
"The most valuable features of the solution are performance and security."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"The most valuable feature is its usability."
"Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications."
"Even when there is a high load on our servers, Cloudflare is able to cache the data and serve it to users, ensuring they can still access the website."
"Some of our teams have hundreds of repositories, so filtering by team saves a lot of time and effort."
"There is quite a lot to like. Its user interface is fantastic, and being able to sort the incidents by whether they are valid or for a certain repository or a certain user has been very beneficial in helping investigate what has been found."
"What is particularly helpful is that having GitGuardian show that the code failed a check enables us to automatically pass the resolution to the author. We don't have to rely on the reviewer to assign it back to him or her. Letting the authors solve their own problems before they get to the reviewer has significantly improved visibility and reduced the remediation time from multiple days to minutes or hours. Given how time-consuming code reviews can be, it saves some of our more scarce resources."
"It enables us to identify leaks that happened in the past and remediate current leaks as they happen in near real-time. When I say "near real-time," I mean within minutes. These are industry-leading remediation timelines for credential leaks. Previously, it might have taken companies years to get credentials detected or remediated. We can do it in minutes."
"GitGuardian has many features that fit our use cases. We have our internal policies on secret exposure, and our code is hosted on GitLab, so we need to prevent secrets from reaching GitLab because our customers worry that GitLab is exposed. One of the great features is the pre-receive hook. It prevents commits from being pushed to the repository by activating the hook on the remotes, which stops the developers from pushing to the remote. The secrets don't reach GitLab, and it isn't exposed."
"I like that GitGuardian automatically notifies the developer who committed the change. The security team doesn't need to act as the intermediary and tell the developer there is an alert. The alert goes directly to the developer."
"When they give you a description of what happened, it's really easy to follow and to retest. And the ability to retest is something that you don't have in other solutions. If a secret was detected, you can retest if it is still there. It will show you if it is in the history."
"GitGuardian has pretty broad detection capabilities. It covers all of the types of secrets that we've been interested in... [Yet] The "detector" concept, which identifies particular categories or types of secrets, allows an organization to tweak and tailor the configuration for things that are specific to its environment. This is highly useful if you're particularly worried about a certain type of secret and it can help focus attention, as part of early remediation efforts."
"The tool has prebuilt templates for data classification. It is easier for customers to get started."
"The solution involves implementing the confidentiality, utility, and availability principles."
"The most effective aspect of Trellix DLP is that it does what it's supposed to do."
"Trellix DLP helps handle false positives, but it depends on your configuration. It is quite overwhelming in terms of its dashboard."
"Scalability is feasible since it's on-premises. It's easy to scale there."
"Trellix DLP offers many features, using EDR, EPP, disk encryption, and other features."
"It is a very stable solution."
"Trellix DLP has an agent that continuously scans the endpoint and sends the data to the portal. From there, it continuously leverages data from its threat intelligence."
 

Cons

"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"One area of improvement is in the Access Rules. Hypothetically, if we wanted to block or challenge traffic outside of the United States, the only way to currently do that (as far as I know) is to enter every single country outside of the United States. That could be a labor intensive job. A solution could be to enable users to create a rule where traffic is only allowed within a certain country."
"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"We are a product integrator and reseller, and we would like to have a better partner relationship, similar to a channel sales relationship. Sometimes we are on our own or get diverted by Cloudflare because they have direct sales, which competes with us and makes it difficult to build a relationship with this company since we want to be an MSP or a managed service provider for the solution."
"An integrated SSO feature would be useful for Cloudflare DNS."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"I would like Cloudflare to offer a dedicated account manager for large enterprise clients like us."
"We have encountered occasional difficulties with the Single Sign-On process."
"For some repositories, there are a lot of incidents. For example, one repository says 255 occurrences, so I assume these are 255 alerts and nobody is doing anything about them. These could be false positives. However, I cannot assess it correctly, because I haven't been closing these false positives myself. From the dashboard, I can see that for some of the repositories, there have been a lot of closing of these occurrences, so I would assume there are a lot of false positives. A ballpark estimate would be 60% being false positives. One of the arguments from the developers against this tool is the number of false positives."
"Right now, we are waiting for improvement in the RBAC support for GitGuardian."
"I would like to see more fine-grained access controls when tickets are assigned for incidents. I would like the ability to provide more controls to the team leads or the product managers so that they can drive what we, the AppSec team, are doing."
"It would be nice if they supported detecting PII or had some kind of data loss prevention feature."
"One improvement that I'd like to see is a cleaner for Splunk logs. It would be nice to have a middle man for anything we send or receive from Splunk forwarders. I'd love to see it get cleaned by GitGuardian or caught to make sure we don't have any secrets getting committed to Splunk logs."
"We'd like to request a new GitGuardian feature that automates user onboarding and access control for code repositories."
"They could give a developer access to a dashboard for their team's repositories that just shows their repository secrets. I think more could be exposed to developers."
"Coverage for Mac OS is lacking as features like clipboard and print protection don't function as expected."
"Trellix is incompatible with Linux, and its DLP part is incompatible with Mac. Sometimes, it does not work on Windows, either."
"Trellix needs to improve customer support."
"The bugs need improvement."
"Having someone within a region who understands the countries and how they approach data and information security is sometimes where the problem lies."
"It's not very user-friendly for a beginner, so it would be easier if the platform or console were manageable or user-friendly. The dashboard could be simplified."
"The support team's response time during the night is an area of concern where improvements are required."
"In future releases, I would like to see like to see encryption available on the cloud-based version."
 

Pricing and Cost Advice

"The cost primarily depends on the size of the organization."
"So far I use free tier and happy with it. You can subscribe to business package if needed."
"There are no additional costs beyond the standard licensing fees."
"I give the price a five out of ten."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"We don't have any issues with the price."
"A free version of the solution is available."
"The price of the solution is expensive."
"It's a little bit expensive."
"It's not cheap, but it's not crazy expensive either."
"We have seen a return on investment. The amount of time that we would have spent manually doing this definitely outpaces the cost of GitGuardian. It is saving us about $35,000 a year, so I would say the ROI is about $20,000 a year."
"I am only aware of the base price. I do not know what happened with our purchasing team in discussions with GitGuardian. I was not privy to the overall contract, but in terms of the base MSRP price, I found it reasonable."
"The pricing and licensing are fair. It isn't very expensive and it's good value."
"You get what you pay for. It's one of the more expensive solutions, but it is very good, and the low false positive rate is a really appealing factor."
"It could be cheaper. When GitHub secrets monitoring solution goes to general access and general availability, GitGuardian might be in a little bit of trouble from the competition, and maybe then they might lower their prices. The GitGuardian solution is great. I'm just concerned that they're not GitHub."
"The pricing is reasonable. GitGuardian is one of the most recent security tools we've adopted. When it came time to renew it, there was no doubt about it. It is licensed per developer, so it scales nicely with the number of repos that we have. We can create new repositories and break up work. It isn't scaling based on the amount of data it's consuming."
"The pricing depends on the number of users in a company."
report
Use our free recommendation engine to learn which Data Loss Prevention (DLP) solutions are best for your needs.
846,617 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
20%
Computer Software Company
13%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
21%
Government
12%
Media Company
10%
Financial Services Firm
6%
Financial Services Firm
14%
Manufacturing Company
13%
Comms Service Provider
11%
Computer Software Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about GitGuardian Internal Monitoring ?
It's also worth mentioning that GitGuardian is unique because they have a free tier that we've been using for the fir...
What needs improvement with GitGuardian Internal Monitoring ?
We'd like to request a new GitGuardian feature that automates user onboarding and access control for code repositorie...
What do you like most about Trellix?
Trellix can transfer the data through the cloud. The storage device control is an important feature.
What needs improvement with Trellix?
Trellix DLP can improve by addressing the lack of features such as deep drive DLP and email notifications present in ...
What advice do you have for others considering Trellix?
I rate Trellix DLP a five out of ten overall. This is because while it has a strong management feature with ePO, it n...
 

Also Known As

Cloudflare DNS
GitGuardian Internal Monitoring
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Automox, 66degrees (ex Cloudbakers), Iress, Now:Pensions, Payfit, Orange, BouyguesTelecom, Seequent, Stedi, Talend, Snowflake... 
Information Not Available
Find out what your peers are saying about GitGuardian Platform vs. Trellix DLP and other solutions. Updated: April 2025.
846,617 professionals have used our research since 2012.