Govern AI-assisted pull requests before they merge.
APort verifies pull-request evidence, protected-path changes, workflow permissions, and repository context before AI-generated code reaches main.
Buyer
Who this is for
Security leaders and engineering teams using Claude, Codex, Cursor, or GitHub automation to open and update pull requests.
Outcomes
- Start report-only, then make APort a required check when the team is ready.
- Protect workflows, package manifests, API surfaces, and other high-risk paths.
- Persist hosted signed decisions under the customer org when using managed mode.
Controls
- Pull-request and push evidence validation
- Protected path findings
- Workflow permission escalation review
- OIDC-bound repository identity
- Agent attribution and review trailers
Proof
- GitHub job summary
- Signed hosted decision
- Decision reasons and structural findings
- README badge for repository status
Setup
Set up GitHub Guard the way your team works.
Start agent-first when the agent has repo context, switch to human review when a security owner wants the path, or use the CLI when the integration is already clear.
Recommended
Let my agent prepare GitHub Guard.
Best for teams already using Claude, Codex, or Cursor to open pull requests.
set up APort GitHub Repository Guard for this repo — https://aport.io/skillCopy this into the agent that already has access to your repo or runtime environment. Require a diff before enforcement or secrets are enabled.
Implementation
Existing implementation page
The GitHub page remains the setup surface for one-command install, managed hosted mode, and workflow examples.
Open my GitHub setupRelated products
Build the control path in layers.
Runtime Enforcement
APort guardrails evaluate shell, file, web, MCP, repository, and framework tool calls before the agent can act.
Decision Audit Trails
APort records policy decisions with context, reasons, timestamps, and signatures so teams can reconstruct what happened and why.
Enterprise AI Governance
APort helps companies roll out guardrails, hosted verification, repository protection, and signed evidence across employee AI tools and agent workflows.