Skip to content

See what your repo actually proves.

Point a fine-grained read-only token at a repository. The scan reports what it can see, and says when it cannot.

  • No account or card
  • One repository per run
  • Token is not stored

Repository intake

One repository. One bounded permission set.

GitHub does not expose the repository controls needed for a useful review without authentication. Use a fine-grained token restricted to the repository and revoke it after the scan. The disclosure beside the field lists every permission used.

Operator's note

“A score is useful only when every point can be traced back to an observable signal. Unknown data stays unknown.”
- Michal Jatczak, founder · ITSailor
github.com/

Public and private repositories both use a token because several useful controls are not exposed anonymously.

The token is sent only with this scan request. It is not written to a database, cache, analytics service, or logs. A repeat scan by the same credential is served from a 5 min cache namespaced by a one-way digest of the token, so the entry is a hit for that credential and a miss for every other one.

Open the permission boundary above to add a token.

Inspection surface

Five evidence families, with the limits left visible.

01

Delivery automation

GitHub Actions workflow count, workflow files, and release presence.

The scan does not execute builds or prove that a workflow succeeds.

02

Repository security

Dependabot, CodeQL, SECURITY.md, and secret scanning.

A repository signal is not a penetration test or a software-supply-chain certification.

03

Governance

CODEOWNERS and default-branch protection where the supplied token can read it.

Unavailable administration data is reported as missing visibility, not a verified failure.

04

Documentation

README depth, CONTRIBUTING, LICENSE, and security-policy presence.

File presence cannot prove that the content is current or followed by the team.

05

Activity

Recent contribution cadence, issue volume, and repository language.

Activity is context, not a proxy for engineering quality on its own.

Evidence model

The score follows the evidence surface.

The model rewards visible repository practices. It also records when GitHub does not expose a control to the supplied token, so lack of access is not dressed up as certainty.

This is a directional repository-surface review. It does not inspect runtime infrastructure, execute code, prove policy enforcement, or replace a security assessment.

Validate the repository and credential boundary

The request accepts a GitHub owner/repository path and uses the token only against the fixed GitHub REST API origin.

Observed

Collect repository and workflow signals

Metadata, selected policy files, workflow inventory, releases, issues, and available security settings are read server-side.

Observed

Preserve inaccessible states

Every control the token cannot read stays unknown: branch protection, secret scanning, workflow inventory, contribution cadence, and each policy file the API refuses. None of them is treated as a verified pass or a failure.

Not accessible

Apply the versioned scoring rules

The scoring rules are versioned and every point traces to an observable signal. The denominator shrinks when GitHub does not expose a control, and the result states how many points it covered.

Modelled

ITSailor field library

Take the next step without booking a call.

Start with practical, downloadable material. The complete library remains visible below, including every available free pack and diagnostic.

26 free resources in the verified catalog. Reviewed 2026-07-18.

Browse the complete free library (26)

Resource packs

Downloadable pack

Azure Landing Zone Readiness Pack

Discovery, architecture, security baseline, policy and operating-review templates for Azure platform planning.

6 planning templates · policy intent · operating review

Downloadable pack

Azure Virtual Desktop Readiness Pack

Assess AVD requirements, architecture, FSLogix recovery, security, cost and regional outage readiness.

6 planning templates · recovery · cost and outage review

Downloadable pack

Backup & Restore Drill Pack

Plan, run and evidence recovery drills without inventing the process during an incident.

6 working templates · drill evidence · recovery validation

Downloadable pack

Cloud Cost Audit Workbook

The six-tab Excel model ITSailor uses to surface cloud + SaaS waste and rank the savings backlog. Real formulas, not a static sheet.

6-tab Excel model · formulas · prioritised savings backlog

Downloadable pack

Cloud Licence & Renewal Pack

Track renewals, audit licence use, assess new vendors and prepare evidence before commitment windows close.

6 working templates · renewal calendar · audit and reclaim procedures

Downloadable pack

Cloud Migration Cutover Pack

Structure discovery, pilot waves, cutover, rollback and hypercare for cloud and Microsoft 365 migrations.

7 working templates · cutover gates · rollback procedure

Downloadable pack

DORA/NIS2 Decision Templates

Structured decision matrices for mapping regulatory gaps.

Gap analysis · compliance mapping · incident taxonomy

Downloadable pack

Microsoft 365 Evidence Snapshot

Read-only PowerShell and KQL examples for Secure Score, inactive licensed users and failed sign-in bursts.

2 read-only Graph scripts · 1 KQL query · permissions guide

Downloadable pack

Microsoft 365 Security Review Workpapers

Versioned workpapers for reviewing Microsoft 365 controls, evidence, permissions and remediation priorities.

38 source-linked checks · permission audit · gap analysis

Downloadable pack

Microsoft Defender Incident Response Pack

Operational templates for triage, device isolation, email purge, identity compromise and detection review.

7 working templates · 4 response procedures · review records

Downloadable pack

Microsoft Sentinel Detection Starter

Three KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.

3 KQL samples · 2 runbooks · monthly operating review

Downloadable pack

Resilience Repo Starter Pack

AWS Terraform scaffolding, a BCDR SOP and an infrastructure decision matrix.

AWS Terraform baseline · BCDR SOP · decision matrix

Downloadable pack

Sovereign Exit Kit Starter

Record ownership, architecture, handover evidence and supplier-exit questions before a dependency becomes lock-in.

4 neutral templates · ownership map · handover and supplier-exit checks

Diagnostics

Interactive tool

AI Readiness Scan

Get an AI deployment verdict, risk register, and 90-day plan from what you declare.

18 declared controls · risk register · unknowns stay unknown

Interactive tool

Automation ROI Scenario Builder

Model one workflow from your own operating numbers and see the range it produces.

Your own baseline · three scenarios · 7 scored questions of 10

Interactive tool

Azure Cost Review

Read your own Azure cost export without it leaving your browser.

FREE · NOTHING UPLOADED

Interactive tool

DevEx Maturity Scan

Inspect one GitHub repository across five evidence families.

5 evidence families · unreadable controls stay unknown · token not stored

Interactive tool

Email Deliverability Scanner

Ensure your emails hit the inbox, not the spam folder.

Live DNS checks · 29 DKIM selectors

Interactive tool

Microsoft 365 Licence Overlap Check

Check whether the add-on you are about to buy is already in the plan you hold.

15 add-ons · every verdict sourced to Microsoft · unsettled pairs stay unsettled

Interactive tool

Microsoft 365 Security Scorecard

Review your Microsoft 365 security posture across 38 risk-weighted controls.

38 checks · 6 categories · source-linked assessment

Interactive tool

Offboarding Risk Profiler

Identify access leaks and data risks for departing users.

Risk profile · gap matrix · remediation timeline

Interactive tool

SaaS Auditor - License, Spend & Shadow IT

Find every SaaS you run - and pay for - across users, spend, and SSO.

Three scan paths · browser-local CSV processing