Branch protection
Required reviewers, signed commits, status checks, linear history
Branch protection, secret scanning, code scanning, Dependabot, SSO, and audit log — read once, mapped to change management, vulnerability, and access controls. Engineers see configuration. Auditors see evidence.
Six signal classes
One App install, scoped per org. Read-only by default. Optional event streaming for incident triggers.
Required reviewers, signed commits, status checks, linear history
Push protection, partner-pattern detection, validity checks
Dependency vulnerability alerts, version updates, security PRs
CodeQL alerts, custom queries, SARIF results
Org-level enforcement, IP allow lists, session policies
Streaming events, member changes, ruleset edits
Branch protection rulesets
The ruleset state on every repo is mirrored to your control library — not retyped into a spreadsheet at audit time.
Pre-mapped controls
Branch protection + required reviews satisfy SOC 2 CC8.1 and ISO A.8.32.
Dependabot + code scanning cover SOC 2 CC7.1 and ISO A.8.8 / A.8.28.
SSO + SAML enforcement maps to SOC 2 CC6.1 and ISO A.5.16 / A.5.17.
Signed commit enforcement evidences integrity controls in SOC 2 PI1.4.
Ship configuration. Inherit evidence. See branch protection, scanning, and SSO map to your control library in real time.