My company is a partner. We help in product implementation for SaaS analytics. The solution is used for SaaS scans and secret scanning.
Technical Consultant at a computer software company with 201-500 employees
A very stable solution that discovers vulnerabilities with ease and has excellent scanning features
Pros and Cons
- "Dependency scanning is a valuable feature."
- "The customizations are a little bit difficult."
What is our primary use case?
What is most valuable?
Dependency scanning is a valuable feature. The dependency review feature can be run as part of the CI pipeline. Secret scanning and push protection can block threats. It discovers the vulnerabilities. It helps identify the threats that are commonly seen in the industry.
CodeQL provides ease of use. It enables a high degree of customization. We can write our own queries and configure them in bulk for different projects. The tool provides APIs if we want to integrate it with any external system.
What needs improvement?
The customizations are a little bit difficult. We must know how to write queries. Training is a bit limited. GitHub needs to make it simpler for customization.
For how long have I used the solution?
I have been using the solution for almost four years.
Buyer's Guide
GitHub Advanced Security
January 2026
Learn what your peers think about GitHub Advanced Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
What do I think about the stability of the solution?
The tool is very stable.
What do I think about the scalability of the solution?
We have more than 1000 users.
How are customer service and support?
I have contacted support for on-premise configuration. The quality of support depends on the priority of the issue. I rate the support an eight or nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were using multiple products before. We switched to GitHub because we are partners. We also help others to set up the solution.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive.
What other advice do I have?
The tool provides good reports. I recommend the product to others. It has a trial version. We can test all the features. Overall, I rate the product a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Customer/Partner
DevOps Lead at a computer software company with 5,001-10,000 employees
Cost-effective product with valuable security scanning features
Pros and Cons
- "The product's most valuable features are security scan, dependency scan, and cost-effectiveness."
- "There could be DST features included in the product."
What is our primary use case?
The primary use case for GitHub Advanced Security is for SCSS (Semantic Code Search and Scan) dependencies scan and secret scan.
What is most valuable?
The most valuable features are security scan, dependency scan, and cost-effectiveness. Microsoft owns the platform, and it is included with Azure DevOps. We get a lot of good features at a very low cost.
What needs improvement?
There could be DST features included in the product.
For how long have I used the solution?
We have been using GitHub Advanced Security for six months.
What do I think about the stability of the solution?
The stability of GitHub Advanced Security within Azure DevOps is highly commendable. Its serverless architecture, maintained by Microsoft, eliminates scaling concerns and load-related worries. The absence of maintainability costs, such as server upgrades, reduces administrative overhead.
What do I think about the scalability of the solution?
We have 500 GitHub Advanced Security users in our organization.
How are customer service and support?
We refer to the Microsoft documentation in case of technical issues.
Which solution did I use previously and why did I switch?
The decision to switch or adopt GitHub Advanced Security was driven by the seamless integration and alignment with Microsoft technologies, eliminating the need for additional tools with their cloud or dependencies.
How was the initial setup?
It provides one-click integration. It saves a lot of additional costs for setup and third-party consultancy compared to other vendors. It has severless maintenance, which is taken care of by Microsoft.
What other advice do I have?
It is a user-friendly tool for those new to security, offering ease of use and integration within an organization. However, another specialized tool may be required for more advanced security needs, especially concerning data security testing (DST) and potentially information security management systems (ISMS). I rate GitHub Advanced Security a ten out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. customer/partner
Buyer's Guide
GitHub Advanced Security
January 2026
Learn what your peers think about GitHub Advanced Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
Integration and Solution Architect at a government with 501-1,000 employees
Provides essential data security features but its dashboard needs improvement
Pros and Cons
- "It ensures user passwords or sensitive information are not accidentally exposed in code or reports."
- "There could be a centralized dashboard to view reports of all the projects on one platform."
What is our primary use case?
We use GitHub Advanced Security to secure data for multiple applications. It ensures user passwords or sensitive information are not accidentally exposed in code or reports. It scans the project's dependencies and checks if they are up-to-date and free from known security vulnerabilities.
What is most valuable?
GitHub Advanced Security is part of the Azure DevOps ecosystem. So, all the dashboards and information stay in our environment. We are not required to integrate it with any external security solution.
What needs improvement?
There could be a centralized dashboard to view reports of all the projects on one platform.
What other advice do I have?
I rate GitHub Advanced Security a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Co-Founder at a tech services company with 1-10 employees
Initial setup was very easy, scalable product and stable product
Pros and Cons
- "GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need."
- "The report limitations are the main issue."
What is our primary use case?
We keep our firewall security in place. Customers use GitHub because they don't want to coordinate with many tools.
GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need.
What is most valuable?
For customers, GitHub Advanced Security is valuable for several reasons. It offers server security and the key features.
What needs improvement?
The report limitations are the main issue. We can only see a limited number of reports from Advanced Security. Many enterprise customers would prefer PDF reports.
For how long have I used the solution?
I've had experience with this solution for about a year.
What do I think about the stability of the solution?
It's a stable product. I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
It is highly scalable. Our clients are enterprise businesses.
How are customer service and support?
The customer service and support is fine.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was very easy; it wasn't difficult.
What about the implementation team?
GitHub allows for quick deployment depending on the customer's specific needs.
What other advice do I have?
Overall, I would rate the solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Buyer's Guide
Download our free GitHub Advanced Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Application Security ToolsPopular Comparisons
Checkmarx One
CrowdStrike Falcon Cloud Security
OpenText Core Application Security
Sonatype Lifecycle
PortSwigger Burp Suite Professional
HCL AppScan
GitGuardian Platform
Qualys Web Application Scanning
Aikido Security
Buyer's Guide
Download our free GitHub Advanced Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?

















