Your provider, your audit log, your account.

Single sign-on and provisioning from the provider you already run, an audit log of every governing act, retention you set, an export you can take, and the whole stack in your own AWS account if you want it there.

Request an invite
Settings · Single sign-on

One issuer per space.

OpenID Connect or SAML 2.0, a role on first sign-in, an email domain that routes people to it, and a switch that makes it the only door. However anyone signed in, whoever made an attempt still cannot approve it.

Single sign-on in the docs

Single sign-on settings for a space: protocol, the redirect URL to register, issuer URL, client ID and secret, email domain, role on first sign-in, and the require switch
Single sign-on for a space: the issuer, the domain, the role, and the switch that requires it.

Identity

Sign-in and membership come from the provider you already run.

OpenID Connect or SAML 2.0

One issuer per space: Okta, Microsoft Entra, Google Workspace, or any provider that speaks either. The secret is sealed and never shown again.

A required mode

A space can require its issuer. Password sessions are turned away at the space; API tokens and connected harnesses are not affected. It can only be turned on from a session that came through the issuer, so nobody locks everyone out.

Lookup by email domain

People who type an address at your domain on the sign-in page are sent straight to your issuer.

SCIM 2.0 provisioning

Your identity provider adds and removes people. Deprovisioning removes membership at once and keeps the account, so merge records keep their names.

Audit

Every governing act, by name.

Every change to who may sign in, push, decide or land, and every decision, written as a sentence with who did it and what it was about. Nothing in it is edited after the fact; the space's export carries all of it.

The audit log of a space: single sign-on issuer set, member removed, attempt approved by a person, merged and signed, git credential minted, each with who and when
The audit log of one space: single sign-on set and removed, an attempt approved by a person, a merge signed, credentials minted and revoked.

What you keep, and how you leave

Retention you set, an export you can take, and a door out that needs nobody's permission.

Artifact retention per space

The longest any CI artifact in the space is kept, in days. Merge records and the audit log are never subject to it.

Export of a space as one file

Members, every goal, every attempt, every landing with its signed merge record, and the audit log. Git itself is a bundle per repository. Nothing in an export can contain a secret.

Self-serve account closure

A person exports their own data and closes their own account. Closure revokes everything the account held at once.

Encrypted at rest

Repositories, artifacts and the database are encrypted at rest with the provider's managed keys. The database keeps seven days of point-in-time recovery.

A space's general settings: name, slug with a reason for the record, artifact retention in days, private vulnerability reporting, and transfer of ownership
A space's settings: the retention cap in days, and every change asks for a reason that goes on the audit record.
Space export: download the whole space as one file, and the git clone line for each of its four repositories
The whole space as one file, and a clone line per repository. Private keys are never held; tokens are hashed.

In your own account

The same stack that runs the hosted service, from published images, in your AWS account, on your own model key. Every merge signed with a key that never leaves it.

Self-host on AWS

One Terraform apply, about an hour the first time. The self-host package

The security posture

Encryption, sign-in, authorization, audit, backups and retention, in one table, with the controls map behind it. Security

The paperwork

Data processing

The addendum, as a page. Data processing addendum

Subprocessors

Who touches your data, and for what. Subprocessors

Security reports

Answered first, in person. Security

Request an invite

The alpha is by invitation. Say who you are and what you run; a person reads every request.