Read-only integration

Connect GitHub to cybersoftware

Read-only GitHub App install. Seven evidence types collected automatically: members, 2FA enforcement, teams, branch protection, CODEOWNERS, and audit log. Your auditor gets the evidence without a single screenshot.

Go to dashboard to connect

What we collect

Seven evidence types map to the AICPA Common Criteria controls in your SOC 2 report. Same set every sync, no extras.

EvidenceWhat it showsSOC 2 controls
Organization members
github:org:members
All members of the organization with their access type.CC6.1, CC6.3
Org 2FA enforcement
github:org:2fa_enforcement
Whether 2FA is required for all org members.CC6.1, CC6.2
Org teams
github:org:teams
Teams within the organization and their permissions.CC6.3
Repo collaborators
github:repo:collaborators
Per-repo collaborator access including outside collaborators.CC6.3
Branch protection
github:repo:branch_protection
Default-branch protection rules: required reviews, status checks, signed commits.CC8.1
CODEOWNERS
github:repo:codeowners
Presence of a CODEOWNERS file indicating per-path review ownership.CC8.1
Org audit log
github:org:audit_log
Audit-log entries for org admin actions (Team / Enterprise plans only).CC7.2

Permissions we request

All permissions are read-only.

cybersoftware never writes to your repositories, members, or organization settings. No commits, no merges, no admin actions. No access to source code beyond the CODEOWNERS file.

PermissionWhy we need it
Repository: Contents (Read)Read CODEOWNERS file content to verify per-path review ownership.
Repository: Metadata (Read)List repositories accessible to the install.
Repository: Administration (Read)Read branch-protection rules on each repo’s default branch.
Organization: Members (Read)List org members and check the org-wide 2FA enforcement setting.
Organization: Administration (Read)Read audit-log entries (Team / Enterprise plans only).

Subscribed webhook events: installation and installation_repositories. These let cybersoftware know when you install, uninstall, or change the repository selection.

How to connect

Three steps. About a minute start to finish.

  1. 1

    Click Connect in cybersoftware

    On your Integrations tab, click Connect on the GitHub card. A disclosure modal lists exactly what cybersoftware will read.

    cybersoftware dashboard Integrations tab with the GitHub card and Connect button highlighted
    Step 1
  2. 2

    Install on your organization

    GitHub opens a new tab showing the install consent screen. Pick the organization you want to connect.

    GitHub App install consent screen with the organization picker highlighted
    Step 2
  3. 3

    Choose repositories

    Select All repositories (recommended for SOC 2 completeness) or a specific subset. Confirm and GitHub redirects you back to cybersoftware.

    GitHub install screen with the All repositories option highlighted
    Step 3

Choosing repositories

Recommendation: choose All repositories.

SOC 2 covers your entire production environment. Selecting only some repos means branch-protection and CODEOWNERS evidence for the omitted repos is not captured.

Use Selected only when: you have a separate non-production org (test, archived, or sandbox repos) that should be excluded from the SOC 2 boundary. Document the exclusion in your scope statement.

v1 captures branch protection and CODEOWNERS for the first 500 repos. Larger orgs: email surya@cybersoftware.com to raise the cap.

Free tier limitations

GitHub’s audit-log REST API is available only on Team and Enterprise plans. On the Free plan, cybersoftware cannot collect the org audit log from GitHub.

Two workarounds:

  1. Upgrade to GitHub Team ($4 / user / month). For most small teams this is cheaper than the time cost of manual exports each quarter.
  2. Manual audit-log CSV export. In GitHub, visit github.com/organizations/{org}/settings/audit-log, export the CSV, then upload it through cybersoftware's evidence upload page. Repeat each quarter (or each audit cycle for Type 2).

Either path gives your auditor the audit log. The other six evidence types collect normally on Free plans.

How to disconnect

Disconnecting in cybersoftware removes the connection record on our side. To fully revoke GitHub’s access tokens, you must also uninstall the GitHub App from your organization settings.

  1. In cybersoftware: dashboard → Integrations tab → GitHub card → Disconnect.
  2. On GitHub: visit github.com/organizations/{your-org}/settings/installations.
  3. Click Configure next to cybersoftware Evidence Collector, scroll to the Danger Zone, then click Uninstall.
GitHub organization installations settings page with the cybersoftware Evidence Collector Uninstall button highlighted
Disconnect step: uninstall from GitHub’s org settings

Note: previously collected evidence stays attached to your assessment for audit reproducibility. Future syncs simply stop running once the install is removed.

Troubleshooting

cybersoftware shows "pending" for more than 2 minutes after I clicked Install.▾
GitHub’s webhook delivery to cybersoftware is usually instant but occasionally lags by up to a minute under load. Refresh the page first. If the card still does not flip to "Connected," click Connect again. The install URL is idempotent. GitHub will not re-install or duplicate anything if the install already exists.
I got a 500-repo cap warning. What does that mean?▾
cybersoftware collects branch-protection and CODEOWNERS data for the first 500 repos in v1 to keep sync time predictable. If your org has more, email surya@cybersoftware.com to raise the cap for your account. Branch protection and CODEOWNERS are still collected for the first 500 repos.
A gap did not close after I connected GitHub.▾

GitHub closes one gap on its own: multi-factor authentication, once your org requires two-factor authentication for every member.

Branch protection, CODEOWNERS and the org audit log are collected for your auditor but close no gap by themselves. Answer or upload those gaps directly. On GitHub Free the audit log is not collected; see Free tier limitations.

About a minute from here. cybersoftware handles the rest.

Go to your dashboard