Multiple repository gates
Manage Pushgate connections across repositories from a shared control plane.
Product reference
Capabilities, example workflows, and integration foundations.
Back to features ↗Workflow examples use your tests and configured mappings. Tool and framework support depends on deployment and version.
Set the requirements. Put them at the right checkpoint.
Manage Pushgate connections across repositories from a shared control plane.
Keep the exact signed policy release behind an evaluation or gate assignment.
Assign requirements to the relevant products and repositories.
Keep policy publication separate from a human approving its gate assignment.
Evaluate evidence when Git pushes pass through Pushgate, before forwarding them to GitHub.
Choose enforcement or visibility for a configured repository connection.
Show developers and agents which requirements need attention when a push is refused.
Verify collected evidence against policy before it reaches the gate.
Turn everyday engineering work into verifiable records.
Capture evidence from builds, tests, scans, and scripts run on your compute or hosted infrastructure.
Package execution evidence in signed, open in-toto and DSSE formats.
Use supported identity-backed signing flows instead of distributing long-lived signing keys.
Attach trusted signing-time evidence to support later signature verification.
Associate evidence with the specific materials and subjects observed during the run.
Capture results from your existing test suites and build commands.
Collect results from supported vulnerability, secret-detection, and security-scanning tools.
Bring supported software bill of materials and dependency scan outputs into the evidence record.
Inspect supported process, filesystem, and network observations from a run. Tracing capabilities depend on the host.
Keep a traceable path from a decision to its proof.
Collect signed attestations from developer environments and automated workflows in one place.
Review evidence in the context of the software and repository it belongs to.
Inspect signed subjects, predicate details, signatures, and associated metadata.
See which requirements the supplied evidence satisfied and which failed.
Retain signed verification summary attestations for policy evaluations.
Follow an evaluation or control record back to its supporting attestation.
Connect technical tests to the controls they support.
Link a policy’s evaluation results to one or more controls in a selected catalog.
Review the policies, per-product and per-repository verdicts, and attestations supporting a control.
Connect relevant technical evidence to Key Security Indicators using versioned framework mappings.
Organize supporting evidence against controls from the configured NIST catalog.
Distinguish a passing evaluation from a failed check, an unevaluated policy, or a control with no bound evidence.
Keep inactive bindings and results from older or different branch heads distinguishable in control views.
Map a signed rescan or remediation check to the controls it supports, with the tested scope retained.
Map signed recovery-test results to relevant recovery controls and KSIs.
Connect signed checks of configuration and drift to relevant control evidence.
Keep the connection between code and controls visible.
Mark the repository paths, patterns, or code locations that a control depends on.
Surface pull-request changes touching configured watchpoints for review.
Retain the label, reason, repository location, and linked controls behind a watchpoint.
Show when a line-based watchpoint needs review after its underlying code changes.
Know who signed, what they can do, and what was observed.
Enroll agents with explicit identities rather than treating an observed tool name as authentication.
Limit service credentials by purpose, audience, and authorized scope.
Manage agent access with credential expiry and revocation.
Support authenticated automated workflows through configured workload identity and signing flows.
Provide certificate issuance and timestamping services for supported signing workflows.
Keep evidence signers, policy publishers, gate activation actors, and push signers distinguishable.
Fit into the workflow your team already uses.
Run supported checks on your compute or hosted infrastructure, including GitHub Actions, RWX, and Namespace; validate the selected runner and capture mode.
Use the Git push boundary as the enforcement point for connected GitHub repositories.
Use supported attestors and command execution to bring your current scanning tools into the evidence workflow.
Produce evidence based on in-toto and DSSE for machine-readable verification.
Connect supported platform workflows through its API surfaces.
Keep control identifiers and mappings tied to their source catalog.
Choose where your evidence control plane runs.
Use the hosted platform for a shared team workspace.
Run the platform UI, API, workflows, evidence storage, and signing services as one application.
Keep appliance data on your host, with a configured persistent data directory.
Use an admin-provisioned deployment without requiring an external identity provider or email service.
Verify the appliance’s signed license locally without a license phone-home requirement.
Packages for Linux x86-64 and ARM64, macOS Apple silicon, and Windows x86-64.
Run the Platform as a container, single binary, VM image, or AWS Marketplace instance. Plan capacity and availability for your environment.