Start with one application
BuildVouch brings application records, security findings, evidence and release decisions into an organisation workspace. Begin with one real application and one release candidate.
1. Sign in and choose your organisation
Use your work email or Google sign-in. If you have an authenticator enrolled, complete its verification. Open the organisation you belong to. A new account does not receive platform administration.
2. Add an application
From the portfolio, choose Add application. Record its name, a stable slug, repository and domain. These are metadata. They do not connect a repository or verify a release.
3. Connect a selected repository
An organisation owner opens Connection → Connect with GitHub and follows authorization, repository selection, detected settings and the first evidence report. The operator must complete the one-time GitHub App registration first. Existing operator-managed bindings remain supported. Generic workflow success is not automatically assigned to release controls.
Read Guided GitHub connection. Operators can also use the manual connector guide.
4. Review the controls
Open Requirements. BuildVouch seeds eight controls: build, type checking, tenant isolation, authentication, storage isolation, private credential scanning, dependency scanning and backup restoration. An owner may add stricter custom requirements.
5. Evaluate a release
Enter the complete 40-character commit SHA and environment in Releases. BuildVouch evaluates the latest verified evidence for that exact repository, commit and environment. Missing, failed, unknown or expired evidence blocks the candidate.
Read Release decisions for review and approval rules.
6. Record the next action
Assign remediation to a finding or record the application's next action. Keep manual notes useful and factual. They do not become verified evidence.
The internal pilot
Cyclotron Technologies starts with RAQOZ, CostGrid, Synquestra and UxerProof. House of Alpha is a separate later customer organisation. Its application records are not seeded by this build.