verity

Integrations

Live

Your systems checked daily, with the proof attached.

Connect GitHub with a read-only token and seven checks run every day on how your software is reviewed, protected and released. Results attach to the controls they map to as dated evidence, and a broken connection shows as an error, never as a failed control.

Live connector
GitHub
GitHub checks, run daily
7
Token access needed
Read only
The Connections page, with GitHub ready to connect, systems such as Amazon Web Services, Cloudflare, Okta, Microsoft Entra ID, Google Workspace, GitLab, Bitbucket, Jira and Slack not yet available, and a Request integration button

Product screen · demonstration data

Connect GitHub

Seven checks on how your software is built and released

Paste a personal access token that can only read your GitHub organisation. Verity encrypts it before it is stored and keeps it out of every log. The first run starts at once, then the checks run daily, answering questions a SOC 2 auditor asks about reviews, branch protection and scanning.

  • Default branch protected; an approving review required before merge
  • Merged changes reviewed; checks must pass before merge
  • Secret scanning and dependency alerts switched on
  • Two-factor sign-in required for access to code
GitHub checks
  • Default branch is protectedDaily · SD-06, SD-01Passing
  • Merges need an approving reviewDaily · SD-06, SD-01Passing
  • Merged changes were reviewedDaily · SD-01, SD-06Failing
  • Checks must pass before mergeDaily · SD-02Passing
  • Secret scanning is onDaily · SD-11Passing
  • Dependency alerts are onDaily · SD-03, LM-11Could not check
  • Two factor is required for code accessDaily · IAM-03Passing

The seven live checks · sample results

On the control

Results land on the controls they answer

Each check maps to the controls it can support. Open a control's Automation tab to see what ran, when and what it found. The output is attached to the control as dated evidence, at most once a day unless the result changes, so a passing check does not bury the record in copies.

  • Results read Passing, Failing or Could not check
  • A broken connection shows Needs attention, with the reason
  • Checks stop rather than quietly report a pass
A control's detail page with an Automation panel offering to connect the system its checks need, linked evidence marked Current, and the control's SOC 2 mappings

Product screen · demonstration data

What comes next

Cloud, identity and ticketing connections are on the way

GitHub is the first live connector. Connections for cloud infrastructure, identity providers, ticketing, alerting, observability and vulnerability scanners are planned, each designed around read-only, least-privilege access. If the system you rely on is not listed, request it from the Connections page so it can be prioritised.

  • Amazon Web Services and other cloud platforms
  • Okta, Google Workspace, and Microsoft 365 and Entra ID
  • Jira, Slack, PagerDuty, Datadog and more
  • Request integration records what you need
Planned connections
  • Amazon Web ServicesCloud infrastructureComing soon
  • OktaIdentity providerComing soon
  • Google WorkspaceIdentity providerComing soon
  • Microsoft 365 and Entra IDIdentity providerComing soon
  • JiraTicketingComing soon
  • SlackOn call and alertingComing soon

Planned · coming soon

Capabilities

Everything it includes.

  • GitHub connector

    Seven daily checks on reviews, branch protection, scanning and two-factor sign-in.

  • Read-only tokens

    Nothing in Verity needs write access to your source control.

  • Encrypted credentials

    Tokens encrypted before they are stored, and kept out of logs.

  • Evidence on controls

    Dated results attached to mapped controls, at most once a day unless changed.

  • Error is not fail

    A broken connection shows Needs attention; checks never report a pass they did not see.

  • Request a system

    Register interest in a system that is not there yet, so it can be prioritised.

  • Coming soon

    Cloud infrastructure

    Amazon Web Services, Microsoft Azure, Google Cloud and other platforms.

  • Coming soon

    Identity providers

    Okta, Google Workspace, and Microsoft 365 and Entra ID.

  • Coming soon

    Ticketing and alerting

    Jira, Linear and others for work; PagerDuty and Slack for alerts.

Common questions

Integrations, answered.

What access does the GitHub connection need?
Read only. Create a personal access token that can read the organisation you want checked. Nothing in Verity needs to write to your source control, and a read-only token limits what a mistake can cost. Verity encrypts the token before it is stored, and it never appears in a log.
Does a failing check mean our control failed?
Not necessarily. A failing check found something other than what the control claims, and its detail says what. A check that could not run reads Could not check, never Failing, so a broken connection never looks like a failed control.
What happens if our token expires?
The connection shows Needs attention with the reason, and the checks stop rather than report a pass. Disconnect and connect again with a fresh token, and the schedule resumes.
When will AWS and our identity provider be supported?
They are planned, and we do not give dates. Each planned system is marked Coming soon here and on the Connections page. If yours is missing, request it so it can be prioritised.

See it with your own frameworks.

Book a demo and we will walk through this module with the frameworks and regulators you answer to.