Poliogo

Connect GitHub

Install the Poliogo GitHub App on the repositories you choose. Compliance updates come back as pull requests.

How it connects
GitHub App installation
Setup time
Under 60 seconds
Access
Read, plus branch + PR creation

How the connection works

  1. AuthoriseApprove Poliogo on the provider's own screen. No password ever reaches us.
  2. Select repositoryYour repositories are listed for you — nothing to paste or misremember.
  3. Detection stays onEvery later scan is diffed against this one, so a new tool becomes an update.

What it looks like once connected

An illustration of this connection inside your Poliogo dashboard — not live data.

Live sync activeExample
acme-inc/acme-web · main

Detected in this project

  • Stripestripe in package.json
  • SupabaseSUPABASE_URL in .env.example
  • OpenAIfetch to api.openai.com — no SDK
  • PostHognew since your last scan
Last scan: 2 minutes ago3 documents up to date
Files are read in memory and dropped when the request ends. What persists is this list of service names.

Exact permissions requested

Every permission this connection asks for, named as GitHub names it on its own consent screen — so you can compare this table to what you are shown.

PermissionGrantWhat it is used for
ContentsReadRead manifests, source text and .env.example in the repositories you select.
MetadataReadList your repositories and their default branch so you can pick one.
Email addressesReadIdentify your account when you sign in with GitHub.
Contents — branch + pull requestWriteCreate a poliogo/* branch and open a pull request on it. Changes reach your default branch only through a pull request you approve.

Setting it up

What you do, and what you will be looking at while you do it.

  1. Start the connection

    Press Connect GitHub below. You are sent to GitHub's own installation screen — your password never reaches Poliogo, and there is nothing to copy or paste.

  2. Choose which repositories it can see

    Pick All repositories, or name just the ones you want covered. This is the boundary: anything you leave out is unreachable, not merely unscanned. You can change the selection whenever you like in GitHub under Settings → Applications, and revoking takes effect immediately.

  3. Pick the repository for this project

    Back in Poliogo, choose the repository this product lives in. The scan reads your default branch and takes under 60 seconds.

  4. Check what it found

    You get a plain-English list of every detected service, each with the file and line it was proved from. Add anything it missed, remove anything you do not want covered — nothing is written until you approve it.

  5. Merge the first pull request

    Poliogo opens a PR adding your policy pages and the consent banner wiring. Merge it like any other change. From then on a stack change prepares the next one — opened on its own from Pro Builder up, on your one-click approval below that.

Poliogo · New projectExample

Choose how to scan your app

Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.

Git RepositoryRecommendedThe most accurate scan — we read the dependencies your app actually ships.Choose another way
GitHubGitLabBitbucket

Connect GitHub and pick a repository — read-only, and the only source we can watch for you.

Authorise on GitHub

ContentsRead
MetadataRead
Email addressesRead
Contents — branch + pull requestWrite

Granted on GitHub's own screen — this panel can show it, never widen it.

Connect GitHub

Select repositories

Find a repository (12)
acme-webPrivateacme-siteacme-docsAlready scanned
Choose which repositories Poliogo can read →Read my project
Tell us what you use instead
The Poliogo setup screen for GitHub, drawn from the same catalogue the app reads. An illustration — not live data, and nothing here is clickable.

What Poliogo detects from GitHub

The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.

What it reads

  • Dependency manifests — package.json, requirements.txt, Cargo.toml, go.mod, composer.json, pubspec.yaml and the rest.
  • The endpoints your code actually calls. A raw fetch to api.openai.com is found even with no SDK installed.
  • Environment variable names in .env.example — STRIPE_SECRET_KEY proves Stripe without reading any secret.
  • Your framework and where its routes live, so generated policy pages land in the right folder.
  • Cookies and tracking scripts referenced anywhere in the source.

What it never reads

  • Repositories you did not select.
  • The value of any secret or environment variable.
  • Your default branch, except through a pull request you approve — updates arrive on a poliogo/* branch.

Ready to connect GitHub?

The free plan covers one project with no credit card. You approve everything before a single document is written.

Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.