AUTOGOVERN / CONNECTED EVIDENCE

Discovery & Integrations

Discover declared AI dependencies. Bring traceable repository and CI evidence into your customer reviews.

User guide ↗
API contract ↗

GitHub · Read-only repository scan

Reads package.json, requirements.txt and pyproject.toml at the repository root. Optional CI collection reads up to 20 workflow runs for the captured commit. It does not request application source, secret files, logs or artifacts, or modify GitHub. Only extracted metadata is retained; raw manifests are not stored.

For private repositories, use a fine-grained token limited to the selected repository, with Contents: read and, for CI, Actions: read. The token is sent to GitHub for this scan only and is not stored. GitHub permissions ↗

Continuous GitHub connections

Keep repository evidence and discovered dependency records up to date. Organization admins choose a system and authorize recurring reads. New evidence is collected privately and still requires review before customer disclosure.

Choose an assessment above.

Manage registered systems ↗