Your code is sensitive.Access stays deliberate.

ShipCheck is designed around scoped repository access, authenticated events, isolated workspaces, controlled AI analysis, and an auditable path from evidence to merge decision.

Controls at every boundary.

The product limits access at the GitHub installation, request, workspace, repository, and action layers.

GitHub App access

Repository access follows the installations and repositories you explicitly authorize. Short-lived installation tokens are used when access is required.

Least-privilege credentials

Secrets stay server-side, installation scope is checked, and normal operation does not require a pasted personal access token.

Verified webhook events

Incoming GitHub events are authenticated before ShipCheck accepts repository or pull-request activity.

Workspace isolation

Account, repository, scan, contract, and team access are scoped to the authenticated owner and workspace.

Controlled AI processing

AI-assisted review can be controlled per repository while deterministic checks continue independently.

Deliberate write actions

Scanning reads and analyzes repository context. Repository-changing actions require an explicit user action.

Connected when needed. Revocable by design.

Repository access remains tied to GitHub installation scope, while ShipCheck retains only the operational records needed for scans, contracts, governance, and history.

01

Authorize

Choose repositories in the GitHub App installation.

02

Process

Fetch the scoped context required for a requested scan.

03

Decide

Store evidence, verdicts, and governed behavior history.

04

Revoke

Remove repositories or uninstall the app through GitHub.

What is protected, and how.

A concise view of the boundary, enforcement mechanism, and control available to your team.

BoundaryShipCheck controlYour control
Repository selectionControlled in the GitHub App installationYou decide which repositories are visible
Source processingScoped to analysis and verificationOnly context needed for the requested workflow
Team accessWorkspace roles and repository permissionsOwner, admin, member, and viewer controls
Merge governancePolicy-backed GitHub checksApprovals, exceptions, expiry, and audit history
DisconnectRemove access through GitHubFuture installation access stops when removed

Security should stay inspectable.

Review the policies, control repository access in GitHub, and keep every merge decision connected to its evidence.