AUTOGOVERN / CONNECTED EVIDENCE
Discovery & Integrations
Discover declared AI dependencies. Bring traceable repository and CI evidence into your customer reviews.
GitHub · Read-only repository scan
Reads package.json, requirements.txt and pyproject.toml at the repository root. Optional CI collection reads up to 20 workflow runs for the captured commit. It does not request application source, secret files, logs or artifacts, or modify GitHub. Only extracted metadata is retained; raw manifests are not stored.
Create a private assessment
Create a named record to hold repository evidence. It starts without a risk rating or score; complete the assessment in the Workbench later.
Private scan history
Review each scan and select which items to import as private evidence.
Select an assessment above to view its scan history.
Continuous GitHub connections
Keep repository evidence and discovered dependency records up to date. Organization admins choose a system and authorize recurring reads. New evidence is collected privately and still requires review before customer disclosure.
Choose an assessment above.