gittan.
How it worksPricingDocs Sign in

Why gittan

How we think

For your role

Dev teamsPlatform engineersEngineering leaders

Getting started

OverviewCreate your orgFirst pushTeams & reposYour first pipelineImport reposPublic repos & packagesDevice authorizationFrom GitHub Actions

Pipelines

OverviewConfigurationPoliciesShared stepsBase imagesImage pinningDeploy hooksPipeline previewDeploy feedbackExamples

Teams & metrics

OverviewTeam metricsCode reviewChangelogDependenciesNotifications

Security

OverviewPeopleMachines & tokensPipeline identitySupply chainAudit logSecurity findingsChange managementGroup sync

Reference

CLIPipeline YAMLPolicy YAML

Security

Security is not a tier — it is how the platform works. Organized by who or what needs access.

People

How humans access gittan. Email OTP out of the box, SSO when you need it.

Machines & tokens

Service accounts and deploy tokens for machine-to-machine access.

Pipeline identity

Per-run tokens, secret injection, and why pipelines never need long-lived credentials.

Supply chain

Provenance, vulnerability scanning, and image pinning.

Security findings

Vulnerabilities and policy violations surfaced by pipeline scans, tracked per repo and per team.

Group sync

Map your IdP groups to gittan teams.

Audit log

Every security-relevant action in your org, logged with who did it and when.