Poliogo

Connect Vercel

Connect your Vercel account to confirm which deployment your policies cover — no repository access needed.

How it connects
Read-only OAuth integration
Setup time
Under 60 seconds
Access
Read-only

How the connection works

  1. Connect accountApprove the integration on the provider's own screen.
  2. Select projectYour projects and their production URLs are listed for you.
  3. Detection stays onVariable names are re-read on each scan, so a new service is noticed.

What it looks like once connected

An illustration of this connection inside your Poliogo dashboard — not live data.

Live sync activeExample
acme-web · Production

Detected in this project

  • STRIPE_SECRET_KEYname only — value never read
  • POSTHOG_API_KEYname only — value never read
  • SUPABASE_URLname only — value never read
  • OPENAI_API_KEYname only — value never read
Last scan: 3 minutes ago3 documents up to date
Variable names only. Poliogo never requests a value, and no table in the database has a column to keep one in.

Exact permissions requested

Every permission this connection asks for, named as Vercel names it on its own consent screen — so you can compare this table to what you are shown.

PermissionGrantWhat it is used for
Projects: ReadReadList your projects and their production URLs.
Environment variables: Read (names)ReadRead variable names to detect services. Values are never requested.
DeploymentsNot requestedNot requested. Poliogo never deploys, redeploys or cancels anything.

Setting it up

What you do, and what you will be looking at while you do it.

  1. Connect your Vercel account

    Press Connect Vercel below and approve the read-only integration. Poliogo only ever lists your projects.

  2. Pick a project

    Your projects and their production URLs are listed for you — nothing to type or misremember. The URL you pick is the one your policies will name as the service they cover.

  3. Let it read the variable names

    Poliogo reads the names of your environment variables and never the values. A variable called STRIPE_SECRET_KEY proves you take payments; its contents are neither requested nor stored, and no table in the database has a column to keep one in.

  4. Check what it found and generate

    Review the detected list and generate your documents.

  5. Want the deeper scan? Add the repo

    Variable names prove which services exist; the source sweep proves how they are called, including raw fetch calls with no SDK. Connecting the repository Vercel deploys from adds that on top — the two connections coexist on one project.

Poliogo · New projectExample

Choose how to scan your app

Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.

Hosting PlatformVercel, Netlify, Railway — connect your account. Cloudflare — paste a read-only token.Choose another way
VercelNetlifyRailwayCloudflare

Connect your Vercel account and pick a project — nothing to type.

Connect your Vercel account

Projects: ReadRead
Environment variables: Read (names)Read
DeploymentsNot requested

Granted on Vercel's own screen — this panel can show it, never widen it.

Connect Vercel

Pick a deployment

acme-webacme-web.vercel.app
acme-webacme-web.vercel.appacme-web-stagingacme-web-staging.vercel.appacme-docsacme-docs.vercel.app

Environment variables detected

STRIPE_SECRET_KEYStripe
POSTHOG_API_KEYPostHog
SUPABASE_URLSupabase

Names only. No value is requested, and no table in the database has a column to keep one in.

Project synced · 3 minutes agoRead my project
Tell us what you use instead
The Poliogo setup screen for Vercel, drawn from the same catalogue the app reads. An illustration — not live data, and nothing here is clickable.

What Poliogo detects from Vercel

The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.

What it reads

  • Your project or site list, so you can pick the right one instead of typing an address.
  • The production URL, which is what your policies name as the service they cover.
  • Environment variable names — enough to prove which services you use.

What it never reads

  • Environment variable values. They are never requested and never stored.
  • Your source code — a hosting connection does not grant repository access.
  • Anything writable. Nothing is deployed, changed or redeployed.

Ready to connect Vercel?

The free plan covers one project with no credit card. You approve everything before a single document is written.

Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.