Skip to main content
The GitHub integration connects a GitHub App installation to Keldyn’s continuous-evidence engine. Once connected, Keldyn reads repository access, organization authentication settings, branch protections, pull-request reviews, and vulnerability-scanning results on a schedule and turns them into live evidence for the related controls.
Integrations and automated evidence are typically managed by workspace admins. See Evidence & audits for how automated evidence fits alongside manual evidence.

What it’s used for

Keldyn uses the data it reads from GitHub to keep evidence for source-code access, change management, secure development, and vulnerability management current. Each refresh updates the evidence and freshness status shown in the integration’s Controls covered table. The integration contributes evidence to these ISO 27001 controls:
Full coverage means the data is the artifact the control asks for. Partial coverage means the data usefully contributes but does not, on its own, replace everything the control requires. For example, pull-request reviews support a secure development life cycle but do not prove that the complete life cycle is defined and followed. Keldyn labels partial coverage so it isn’t mistaken for complete coverage.

Before you begin

1

Use a GitHub organization owner

Installing the Keldyn GitHub App on an organization requires organization owner approval. If you aren’t an owner, GitHub may leave the installation pending until an owner approves it.
2

Choose the repositories to include

During installation, choose whether Keldyn can read all repositories or only selected repositories. Evidence only covers repositories included in the GitHub App installation.
3

Keldyn only ever reads

The GitHub App uses read-only repository and organization permissions. Keldyn never changes repository settings, merges code, edits branches, or modifies security alerts.

Set up the integration

1

Open Integrations

In the Keldyn web app, go to Integrations and select GitHub.
2

Connect

Select Connect. GitHub opens the Keldyn GitHub App installation flow. Choose the organization and repositories to connect, review the requested read-only access, and approve the installation.
3

Authorize your GitHub account

Complete the GitHub authorization request. Keldyn uses it to verify that your GitHub account can access the installation; it does not store your user access token.
4

Run the first sync

After GitHub returns you to Keldyn, select Sync now to pull evidence immediately, or wait for the scheduled refresh. The Controls covered and Evidence sources tables then show what was collected and how fresh it is.
From the integration detail page, Controls covered shows whether GitHub is actively feeding each control and whether the control is satisfied. Evidence sources shows each data fetch, the controls it covers, and its freshness.

What data Keldyn collects and why

Keldyn requests read-only access and collects only the data needed to build control evidence.
Keldyn does not collect pull-request titles. If Dependabot or code scanning is disabled, Keldyn records that state as evidence instead of treating the sync as a technical failure.

Permissions

The Keldyn GitHub App requests these read-only permissions: Keldyn stores the GitHub App installation ID and organization metadata. It mints short-lived installation tokens when it refreshes evidence and does not store a per-user GitHub token.

Troubleshooting “Access required”

A control shows Access required when the GitHub App cannot read the matching data. Common causes include:
  • The repository isn’t included in the GitHub App installation.
  • The installation is waiting for organization owner approval.
  • A required read permission isn’t granted to the GitHub App.
  • Organization administration access isn’t available for the 2FA requirement.
Open your GitHub App installations, confirm the organization, repository access, and permissions, then run Sync now again. Controls not affected by the missing access continue to refresh normally. If the installation was suspended or removed, Keldyn marks the connection Reauth required. Select Reconnect and complete the installation flow again.

Keeping evidence current

Keldyn refreshes access, authentication, and change-management evidence daily. Dependabot and code-scanning evidence refreshes hourly. Evidence that hasn’t refreshed within its expected cadence is marked stale, and failed pulls are marked failed so you can spot gaps. You can also trigger an immediate refresh at any time with Sync now.

Next steps

Evidence & audits

Learn how automated integration evidence works alongside manual evidence and audits.