Channel partner programs, MSP, VAR, SI, Channel partners, MSSP

GitGuardian Bets on the Channel to Fix a Growing Non-Human Identity Problem

Non-human identities are now everywhere. API keys, tokens, service accounts, and secrets are multiplying faster than most security teams can track. Breaches tied to leaked credentials are no longer edge cases. They’re routine outcomes of modern software delivery.

That’s the backdrop for GitGuardian launching a channel partner program aimed at VARs, solution providers, MSPs, and MSSPs that want to turn secrets security into something operational, not another tool bolted onto an already crowded stack.

As cloud adoption, automation, and AI workflows accelerate, the attack surface shifts away from users and toward machines. Most organizations know secrets sprawl is a problem. What they struggle with is making it manageable at scale. That’s where partners come in.

Turning secrets security into a managed service

GitGuardian is explicit about how MSPs and MSSPs should think about this problem.

Carole Winqwist, CMO at GitGuardian, told ChannelE2e, “Secrets security is fundamentally an ongoing operational challenge, not a one-time implementation. And this is precisely what creates the managed services opportunity for MSSPs,” said Carole Winqwist, CMO at GitGuardian.

She pointed to the sheer volume of legacy exposure most enterprises carry. “Historical scanning and remediation create the initial engagement,” she said, describing cleanup efforts that often stretch six to eighteen months as partners work through years of exposed credentials across repositories, CI/CD pipelines, logs, and registries. GitGuardian’s research shows that 70% of leaked secrets remain active for more than two years, turning neglect into long-term risk.

That initial remediation opens the door, but it doesn’t solve the problem.

Even with tooling in place, secrets don’t stop appearing. “Even with GitGuardian deployed, new secrets are continuously introduced as developers write code, configure infrastructure, and integrate APIs,” Winqwist said.

This is where the managed service model takes over. Partners handle continuous monitoring, triage, coordination with development teams, revocation workflows, and regular reporting. GitGuardian tracked 23.8 million newly exposed secrets in 2024 alone, reinforcing that secrets security is a day-to-day operational task, not a quarterly scan.

For MSSPs, that reality translates into clear service constructs: SLAs, response timelines, and measurable posture improvement over time.

Program mechanics that matter to partners

The partner program is designed to remove common friction points. Compensation neutrality means GitGuardian’s sales teams aren’t penalized for working through partners. Deal registration and renewal protection give partners confidence that the accounts they build will stay theirs.

Enablement is focused on helping partners explain secrets security in practical terms: how it fits into development workflows, how it reduces incident risk, and how it complements existing AppSec and cloud security efforts instead of competing with them.

Expanding from secrets to NHI governance

GitGuardian is also looking beyond detection. As it moves toward broader non-human identity governance, the partner motion changes. “The evolution to NHI governance fundamentally changes who partners engage with inside customer organizations,” Winqwist said.

Historically, secrets sprawl shows up in AppSec and DevSecOps teams that understand code and pipelines. Identity and Access Management teams, meanwhile, own vaults, rotation policies, and access governance. “The opportunity is expanding from ‘deploy a secrets scanner for DevOps teams’ to ‘become the trusted NHI governance advisor across AppSec and IAM organizations,’” she said.

GitGuardian says its partner program is evolving to support that shift, helping partners operate across both practices rather than treating them as silos.

Non-human identity risk isn’t theoretical, and it isn’t slowing down. It’s persistent, operational, and under-owned inside most organizations. Vendors that make it easier for partners to deliver this work as an ongoing service are more likely to show up in real environments, not just roadmaps. GitGuardian’s channel push reflects that reality. It treats secrets security as work that has to be run, measured, and sustained. For partners and the ops leaders they serve, that framing matters more than any feature list.

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds