Integrations and automated evidence are typically managed by workspace admins.
See Evidence & audits for how automated evidence fits
alongside manual evidence.
What it’s used for
Keldyn uses the data it reads from GitHub to keep evidence for source-code access, change management, secure development, and vulnerability management current. Each refresh updates the evidence and freshness status shown in the integration’s Controls covered table. The integration contributes evidence to these ISO 27001 controls:Full coverage means the data is the artifact the control asks for.
Partial coverage means the data usefully contributes but does not, on its
own, replace everything the control requires. For example, pull-request
reviews support a secure development life cycle but do not prove that the
complete life cycle is defined and followed. Keldyn labels partial coverage
so it isn’t mistaken for complete coverage.
Before you begin
1
Use a GitHub organization owner
Installing the Keldyn GitHub App on an organization requires organization
owner approval. If you aren’t an owner, GitHub may leave the installation
pending until an owner approves it.
2
Choose the repositories to include
During installation, choose whether Keldyn can read all repositories or only
selected repositories. Evidence only covers repositories included in the
GitHub App installation.
3
Keldyn only ever reads
The GitHub App uses read-only repository and organization permissions.
Keldyn never changes repository settings, merges code, edits branches, or
modifies security alerts.
Set up the integration
1
Open Integrations
In the Keldyn web app, go to Integrations and select GitHub.
2
Connect
Select Connect. GitHub opens the Keldyn GitHub App installation flow.
Choose the organization and repositories to connect, review the requested
read-only access, and approve the installation.
3
Authorize your GitHub account
Complete the GitHub authorization request. Keldyn uses it to verify that
your GitHub account can access the installation; it does not store your
user access token.
4
Run the first sync
After GitHub returns you to Keldyn, select Sync now to pull evidence
immediately, or wait for the scheduled refresh. The Controls covered and
Evidence sources tables then show what was collected and how fresh it is.
What data Keldyn collects and why
Keldyn requests read-only access and collects only the data needed to build control evidence.Keldyn does not collect pull-request titles. If Dependabot or code scanning is
disabled, Keldyn records that state as evidence instead of treating the sync
as a technical failure.
Permissions
The Keldyn GitHub App requests these read-only permissions:
Keldyn stores the GitHub App installation ID and organization metadata. It mints short-lived installation tokens when it refreshes evidence and does not store a per-user GitHub token.
Troubleshooting “Access required”
A control shows Access required when the GitHub App cannot read the matching data. Common causes include:- The repository isn’t included in the GitHub App installation.
- The installation is waiting for organization owner approval.
- A required read permission isn’t granted to the GitHub App.
- Organization administration access isn’t available for the 2FA requirement.
Keeping evidence current
Keldyn refreshes access, authentication, and change-management evidence daily. Dependabot and code-scanning evidence refreshes hourly. Evidence that hasn’t refreshed within its expected cadence is marked stale, and failed pulls are marked failed so you can spot gaps. You can also trigger an immediate refresh at any time with Sync now.Next steps
Evidence & audits
Learn how automated integration evidence works alongside manual evidence and
audits.