Products
Repository governance

Govern AI-assisted pull requests before they merge.

APort verifies pull-request evidence, protected-path changes, workflow permissions, and repository context before AI-generated code reaches main.

Buyer

Who this is for

Security leaders and engineering teams using Claude, Codex, Cursor, or GitHub automation to open and update pull requests.

Outcomes

  • Start report-only, then make APort a required check when the team is ready.
  • Protect workflows, package manifests, API surfaces, and other high-risk paths.
  • Persist hosted signed decisions under the customer org when using managed mode.

Controls

  • Pull-request and push evidence validation
  • Protected path findings
  • Workflow permission escalation review
  • OIDC-bound repository identity
  • Agent attribution and review trailers

Proof

  • GitHub job summary
  • Signed hosted decision
  • Decision reasons and structural findings
  • README badge for repository status

Setup

Set up GitHub Guard the way your team works.

Start agent-first when the agent has repo context, switch to human review when a security owner wants the path, or use the CLI when the integration is already clear.

Recommended

Let my agent prepare GitHub Guard.

Best for teams already using Claude, Codex, or Cursor to open pull requests.

agent instruction
set up APort GitHub Repository Guard for this repo — https://aport.io/skill

Copy this into the agent that already has access to your repo or runtime environment. Require a diff before enforcement or secrets are enabled.

Implementation

Existing implementation page

The GitHub page remains the setup surface for one-command install, managed hosted mode, and workflow examples.

Open my GitHub setup

Related products

Build the control path in layers.