Know what you connect.

You choose the repositories and infrastructure Proofline can inspect. Infrastructure access is read-only. The hosted service processes code and environment evidence to investigate deployment risks.

Choose what Proofline can read.

Install the GitHub App for the repositories you choose. Link each repository to its target environment, then connect the supported infrastructure that supplies evidence for that environment.

What each connection supplies
ConnectionAccess and purpose
GitHubRepository code, deployment configuration, pull requests, and the exact commit under review. Proofline also publishes review findings and checks in GitHub.
InfrastructureSupported configuration and deployment records, through read-only permissions you grant. These integrations do not change your infrastructure.

Each integration reads a specific set of resources. Inspect the supported scope before you connect a provider. A connection does not imply access to every resource or API that provider offers.

Use temporary access.

Proofline obtains short-lived GitHub installation tokens and AWS role credentials when it needs them. The product does not persist long-lived GitHub or AWS tokens.

For AWS, setup generates a role with a designated trusted principal and a connection-specific external ID. That external ID is required when Proofline assumes the role. Review the generated trust policy and permission policy before installation.

The AWS guide explains the role and the configuration its read permissions cover.

Understand what the hosted service processes.

The hosted service processes account, configuration, code, infrastructure, and review data from the integrations you authorize. It uses that data to run reviews, record evidence, operate the service, and support your use.

Review model providers process code and evidence included in model requests. Connecting infrastructure does not keep all review data inside your cloud account.

The reviewer uses typed tools. The service checks authorization and scope outside the model. Code experiments run in a disposable sandbox without cloud credentials, write credentials, or customer test secrets.

The privacy policy describes data handling, retention, and access or deletion requests. Contact hello@proofline.sh with requirements your team needs to confirm before connecting.

Keep the review tied to its evidence.

Each review refers to fixed code and recorded environment evidence. Authorization limits which resources the review can inspect. Repository text and pull request content are treated as untrusted input.

Missing permissions, stale records, or unreachable resources can leave a review incomplete. Proofline records those limits so your team can distinguish a supported finding from a gap in the assessment.

Read how a review works for the relationship between the change, the environment snapshot, and the published finding.

Choose the scope before you connect.

Start with one repository and the environment it deploys to. Inspect the requested permissions during setup.

Get Started with GitHub