Connect with a read-only key
You create the credential yourself, scoped to the minimum the checks need, and paste it in. Each integration page lists exactly which permissions that is, and the key is revocable on your side at any time.
53 integrations, 165 automated checks, every one listed on this page. Most run over a read-only key you scope yourself; GitHub, GitLab, Jira, Asana and Slack sync work both ways; and the MCP server lets your AI read your compliance data.
devguard reads your configuration with a read-only key and turns what it finds into evidence on your controls
Work flows both directions: remediation opens as issues in your tracker, status flows back as evidence
Point Claude, Cursor or any MCP client at your compliance data and ask it questions
No teasers and nothing "coming soon": each tile below is shipped, and its page lists every check it runs
Plus a generic HTTP and TLS check runner for anything with an endpoint See the developer docs
The same three steps for every provider on this page — nothing scraped behind your back
You create the credential yourself, scoped to the minimum the checks need, and paste it in. Each integration page lists exactly which permissions that is, and the key is revocable on your side at any time.
Each check reads your configuration and verifies one concrete thing — 2FA enforced, branch protected, TLS on every domain. It only ever reads: devguard holds no write access and remediates nothing silently.
A passing check becomes evidence on the control it supports; a failing one becomes a finding you decide how to treat. Nothing pages your engineers, and the trail is ready when the audit comes.
Every connection is one you make: scoped by you, read-only where the page says read-only, revocable whenever you want. Checks run from Swiss infrastructure, and results and evidence stay in Switzerland.
20 minutes on how you run certification today. Bring your current platform's test or control list and we'll tell you honestly where these checks cover it — and where they don't yet.