Developers

Automate compliance,
on an open platform.

devguard runs on a public API, so the same compliance work you’d do by hand you can script instead. Connect GitHub, GitLab, Jira and Slack, read the docs, and build on top. You connect what you want, and the evidence links back to the control it satisfies.

Start for freeRead the API docs
Integration
Create Ticket
Audit
Open platform

There’s a real API behind all of it.

devguard isn’t a closed box. The platform runs on a public API, so the compliance work you’d otherwise click through you can drive from your own systems instead.

01

A public API, not a closed box

Everything devguard does is backed by a public API. The reference lays out what’s available and how to authenticate, so you can see exactly what you can build on before you write a line.

02

Automate what you’d otherwise click

The routine compliance steps you’d do by hand in the UI are the kind of thing you can drive from your own scripts and scheduled jobs. Less clicking through screens, more of the work on rails.

03

Wire it into the systems you already run

Connect devguard to the dashboards, jobs and internal tools your team already maintains, so compliance data sits alongside the rest of your engineering work instead of in a separate tab.

Read the API docs

CLI

Evidence that keeps itself current

The devguard CLI runs the checks you already have, like npm audit or Trivy, on a schedule and pushes each report into the evidence record it belongs to. Each push replaces the last, so what an auditor opens is days old, not a year.

Runs your checks where they already run — npm audit, Trivy, Terraform plans, any command
Secret scan before anything uploads — a stray credential blocks the push
One current file per collector — a lapsed freshness window shows up on deadlines

Read the CLI reference

~/acme-app · ci
$ npx @devguardch/cli evidence push
ok npm-audit EV-42 · replaced previous file
ok vulnerability-scan EV-57 · replaced previous file
Pushed 2 artifact(s).
Integrations

Connect the tools your team already lives in.

Four connections ship today. GitHub, GitLab and Jira open and sync remediation issues both ways; Slack carries the alerts. You connect each one on purpose and scope what it sees.

GitHub
Two-way issues
GitLab
Two-way issues
Jira
Two-way issues
Slack
Notifications

See all integrations

You connect it. You stay in control.

You connect GitHub, GitLab, Jira or Slack explicitly, with access you can revoke, and as issues update and close the trail comes back and attaches to the control it satisfies. So when the audit comes, the proof is already connected, not reconstructed after the fact. More connectors, including cloud, are on the roadmap, and they’ll work the same way.

Resources

Everything you need to build and keep up.

The docs, the API reference, the integrations and what shipped lately, all in one place.

Documentation

Guides, references and how-tos for every part of devguard.

Read the docs

API & CLI

Authentication, endpoints and examples, plus the CLI that pushes evidence from CI.

Open the reference

Integrations

GitHub, GitLab, Jira and Slack, and how each one connects.

See integrations

Changelog

Everything new in devguard, shipped and dated.

Read the changelog
Developer FAQ

Questions developers actually ask.

Is there a real API?

Yes. devguard runs on a public API, documented at docs.devguard.ch/api. The platform is built to be automated, not only clicked through, so you can read the reference and build against it before talking to anyone.

Is there a CLI?

Yes. The devguard CLI runs collectors you declare, like npm audit or Trivy, secret-scans the output and pushes each report into an evidence record, replacing the previous file. Install it with npx @devguardch/cli and read the reference at docs.devguard.ch/cli.

What integrates with devguard today?

GitHub, GitLab and Jira sync remediation issues both ways, and Slack receives notifications. That’s the live set. More connectors are on the roadmap, and we list only what actually ships.

How does evidence get into devguard?

You connect a tool, like GitHub, GitLab, Jira or Slack, and issues sync back linked to the control they satisfy, or you upload and map a document directly. The devguard CLI can also run your checks in CI and push each report into an evidence record. Cloud auto-collection from AWS, Azure or GCP is on the roadmap.

Can we self-host or keep our data in Switzerland?

devguard is Swiss-hosted by default, in German and English, with on-premise possible. You control where the data sits, and connection credentials are encrypted at rest.

What happens to our data if we leave?

It’s yours. Export your records to CSV and your reports to PDF at any time, and read through the API. Moving in never means you can’t move out.

Where do I start?

Start for free and connect a tool, or read the API docs first. You can look around the whole platform without a sales call.

Build on a platform that tells you the truth.

Start free and connect your stack, or read the API docs first. Cloud auto-collection is on the roadmap; today evidence flows from the tools you connect and the CLI you schedule.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free