← All integrations

Code & vulnerabilities · integration

GitHub

Organisation and repository controls for GitHub.

ISO 27001SOC 2PCI DSSDPDPARBISEBI CSCRFIRDAI

What ProofLayer proves

Read-only evidence, evaluated against versioned rules.

  • The org requires 2FA, members have 2FA, no public repo creation, and the default permission is read
  • Default branches are protected, reviews are required, force-push is off, and dependency vulnerability alerts are on

Configure in ProofLayer

Live in minutes.

  1. Connections → New connection → pick this provider and name the account.
  2. Install ProofLayer’s read-only GitHub App on the org, or paste a fine-grained read-only PAT (write-only).
  3. Click Test connection — ProofLayer verifies read access from the control plane and reports a clear reason if anything is off.
  4. Set the scan schedule; every run appends to the evidence chain for this account.
  5. Choose the framework mapping(s) and, optionally, a push target (CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack).

Grant access from your side

Read-only, least-privilege, revocable.

You create the access in your own console and paste a credential ProofLayer stores sealed — it never writes to your systems.

  1. Install the ProofLayer GitHub App on your organisation (read-only), or
  2. Create a fine-grained personal access token with read-only org and repo scopes.

In-account agent option. Run the agent with your token as an environment variable; it never leaves your host. The collector posts evidence outbound-only, so ProofLayer holds no credential into your environment.

Start

Connect GitHub against your next audit.