Skip to content

See what your repo actually proves.

Point a fine-grained read-only token at a repository. The scan reports what it can see, and says when it cannot.

  • No account or card
  • One repository per run
  • Token is not stored

Repository intake

One repository. One bounded permission set.

GitHub does not expose the repository controls needed for a useful review without authentication. Use a fine-grained token restricted to the repository and revoke it after the scan. The disclosure beside the field lists every permission used.

Operator's note

A score is useful only when every point can be traced back to an observable signal. Unknown data stays unknown.
- Michal Jatczak, founder · ITSailor
github.com/

Public and private repositories both use a token because several useful controls are not exposed anonymously.

The token is sent only with this scan request. It is not written to a database, cache, analytics service, or logs. A repeat scan by the same credential is served from a 5 min cache namespaced by a one-way digest of the token, so the entry is a hit for that credential and a miss for every other one.

Open the permission boundary above to add a token.

Inspection surface

Five evidence families, with the limits left visible.

01

Delivery automation

GitHub Actions workflow count, workflow files, and release presence.

The scan does not execute builds or prove that a workflow succeeds.

02

Repository security

Dependabot, CodeQL, SECURITY.md, and secret scanning.

A repository signal is not a penetration test or a software-supply-chain certification.

03

Governance

CODEOWNERS and default-branch protection where the supplied token can read it.

Unavailable administration data is reported as missing visibility, not a verified failure.

04

Documentation

README depth, CONTRIBUTING, LICENSE, and security-policy presence.

File presence cannot prove that the content is current or followed by the team.

05

Activity

Recent contribution cadence, issue volume, and repository language.

Activity is context, not a proxy for engineering quality on its own.

Evidence model

The score follows the evidence surface.

The model rewards visible repository practices. It also records when GitHub does not expose a control to the supplied token, so lack of access is not dressed up as certainty.

This is a directional repository-surface review. It does not inspect runtime infrastructure, execute code, prove policy enforcement, or replace a security assessment.

Validate the repository and credential boundary

The request accepts a GitHub owner/repository path and uses the token only against the fixed GitHub REST API origin.

Observed

Collect repository and workflow signals

Metadata, selected policy files, workflow inventory, releases, issues, and available security settings are read server-side.

Observed

Preserve inaccessible states

Every control the token cannot read stays unknown: branch protection, secret scanning, workflow inventory, contribution cadence, and each policy file the API refuses. None of them is treated as a verified pass or a failure.

Not accessible

Apply the versioned scoring rules

The scoring rules are versioned and every point traces to an observable signal. The denominator shrinks when GitHub does not expose a control, and the result states how many points it covered.

Modelled

ITSailor field library

Take the next step without booking a call.

Start with practical, downloadable material. The complete library remains visible below, including every available free pack and diagnostic.

25 free resources in the verified catalog. Reviewed 2026-07-18.

Browse the complete free library (25)

Resource packs

Downloadable pack

Azure Landing Zone Readiness Pack

Discovery, architecture, security baseline, policy and operating-review templates for Azure platform planning.

6 planning templates · policy intent · operating review

Downloadable pack

Azure Virtual Desktop Readiness Pack

Assess AVD requirements, architecture, FSLogix recovery, security, cost and regional outage readiness.

6 planning templates · recovery · cost and outage review

Downloadable pack

Backup & Restore Drill Pack

Plan, run and evidence recovery drills without inventing the process during an incident.

6 working templates · drill evidence · recovery validation

Downloadable pack

Cloud Cost Audit Workbook

The six-tab Excel model ITSailor uses to surface cloud + SaaS waste and rank the savings backlog. Real formulas, not a static sheet.

6-tab Excel model · formulas · prioritised savings backlog

Downloadable pack

Cloud Licence & Renewal Pack

Track renewals, audit licence use, assess new vendors and prepare evidence before commitment windows close.

6 working templates · renewal calendar · audit and reclaim procedures

Downloadable pack

Cloud Migration Cutover Pack

Structure discovery, pilot waves, cutover, rollback and hypercare for cloud and Microsoft 365 migrations.

7 working templates · cutover gates · rollback procedure

Downloadable pack

DORA/NIS2 Decision Templates

Structured decision matrices for mapping regulatory gaps.

Gap analysis · compliance mapping · incident taxonomy

Downloadable pack

GCP Landing Zone Readiness Pack

Discovery, architecture, organisation policy and operating-review templates for a governed Google Cloud foundation.

6 planning templates · policy set · operating review

Downloadable pack

Microsoft 365 Evidence Snapshot

Read-only PowerShell and KQL examples for Secure Score, inactive licensed users and failed sign-in bursts.

2 read-only Graph scripts · 1 KQL query · permissions guide

Downloadable pack

Microsoft 365 Security Review Workpapers

Versioned workpapers for reviewing Microsoft 365 controls, evidence, permissions and remediation priorities.

38 source-linked checks · permission audit · gap analysis

Downloadable pack

Microsoft Defender Incident Response Pack

Operational templates for triage, device isolation, email purge, identity compromise and detection review.

7 working templates · 4 response procedures · review records

Downloadable pack

Microsoft Sentinel Detection Starter

Three KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.

3 KQL samples · 2 runbooks · monthly operating review

Downloadable pack

Resilience Repo Starter Pack

AWS Terraform scaffolding, a BCDR SOP and an infrastructure decision matrix.

AWS Terraform baseline · BCDR SOP · decision matrix

Downloadable pack

Sovereign Exit Kit Starter

Record ownership, architecture, handover evidence and supplier-exit questions before a dependency becomes lock-in.

4 neutral templates · ownership map · handover and supplier-exit checks