# GitHub Advanced Security

## Security that moves at the speed of development

Ready to use it in your repositories? [Get started now](https://github.com/get_started?with=advanced-security)

## Stop leaks before they start
[Explore Secret Protection](https://github.com/security/advanced-security/secret-protection?locale=en-US)

## Fix vulnerabilities in your code
[Explore Code Security](https://github.com/security/advanced-security/code-security?locale=en-US)

### Write secure code at scale with AI-driven insights and automated fixes from GitHub Copilot Autofix.
Strengthen your development with AI

### Find and fix vulnerabilities in real time by integrating application security right into GitHub.
Empower your team with native AppSec

> GitHub Advanced Security has solved the risk of leaked credentials. Now, developers are alerted to the problem before they push the code live. They have a direct feedback loop.

Florian Koch, Lead developer at Deutsche Vermögensberatung

## GitHub Secret Protection
For teams and organizations serious about stopping secret leaks.

$19USD  per active committer/month

Ready to use it in your repositories?
[Get started now](https://github.com/get_started?with=secret-protection)

## GitHub Code Security
For teams and organizations committed to fixing vulnerabilities before production.

$30USD per active committer/month

Ready to use it in your repositories?
[Get started now](https://github.com/get_started?with=code-security)

Discover how our security solution can benefit your organization.

### Frequently asked questions

#### What is GitHub Advanced Security?
GitHub Advanced Security (GHAS) encompasses GitHub’s application security products comprising GitHub Secret Protection and GitHub Code Security. GHAS adds cutting-edge tools for static analysis, software composition analysis, and secret scanning to the GitHub platform that developers already know and love. GHAS makes it easy for developers to find and fix vulnerabilities earlier in the software development life cycle.

#### Why choose GitHub Advanced Security instead of a third-party AppSec product?
GitHub Advanced Security operates entirely in the native GitHub workflows that developers already know and love. By making it easier for developers to remediate vulnerabilities as they go, GitHub Advanced Security frees time for security teams to focus on critical strategies that protect businesses, customers, and communities from application-based vulnerabilities.

#### What is DevSecOps?
DevSecOps refers to a combination of the development, security, and operations tools necessary to develop software applications.

#### What is AppSec?
Application security (AppSec) is the process of finding, fixing, and preventing security vulnerabilities in applications. GitHub Advanced Security provides AppSec tools for static application security testing (SAST), which identifies vulnerabilities in the code itself.

#### Can I use GitHub Advanced Security with Microsoft Azure DevOps?
Yes. GitHub Advanced Security is available as an [add-on](https://azure.microsoft.com/en-us/products/devops/github-advanced-security) for Azure DevOps.

#### Where can I find case studies and reference customers?
Read our [customer stories](https://github.com/customer-stories?locale=en-US) to learn how customers like [Telus](https://github.com/customer-stories/telus?locale=en-US), [Mercado Libre](https://github.com/customer-stories/mercado-libre?locale=en-US), and [KPMG](https://github.com/customer-stories/kpmg?locale=en-US) use GitHub Advanced Security to secure applications and accelerate the software development lifecycle.

#### Can I review documentation before purchase?
Yes. As with all GitHub products, [documentation](https://docs.github.com/en/get-started/learning-about-github/about-github-advanced-security) for GitHub Advanced Security is publicly available.

#### Does GitHub offer consulting, training, and other deployment services?
Yes! Please visit [Expert Services](https://docs.github.com/en/enterprise-cloud@latest/code-security/code-scanning/managing-code-scanning-alerts/about-autofix-for-codeql-code-scanning) to learn more.
