Read-only integration

Connect GitHub to Polara

Read-only GitHub App install. Seven evidence types collected automatically: members, 2FA enforcement, teams, branch protection, CODEOWNERS, and audit log. Closes change-management and audit-trail gaps without a single screenshot.

Go to dashboard to connect

What we collect

Seven evidence types map to the AICPA Common Criteria controls in your SOC 2 report. Same set every sync, no extras.

EvidenceWhat it showsSOC 2 controls
Organization members
github:org:members
All members of the organization with their access type.CC6.1, CC6.3
Org 2FA enforcement
github:org:2fa_enforcement
Whether 2FA is required for all org members.CC6.1, CC6.2
Org teams
github:org:teams
Teams within the organization and their permissions.CC6.3
Repo collaborators
github:repo:collaborators
Per-repo collaborator access including outside collaborators.CC6.3
Branch protection
github:repo:branch_protection
Default-branch protection rules: required reviews, status checks, signed commits.CC8.1
CODEOWNERS
github:repo:codeowners
Presence of a CODEOWNERS file indicating per-path review ownership.CC8.1
Org audit log
github:org:audit_log
Audit-log entries for org admin actions (Team / Enterprise plans only).CC7.2

Permissions we request

All permissions are read-only.

Polara never writes to your repositories, members, or organization settings. No commits, no merges, no admin actions. No access to source code beyond the CODEOWNERS file.

PermissionWhy we need it
Repository: Contents (Read)Read CODEOWNERS file content to verify per-path review ownership.
Repository: Metadata (Read)List repositories accessible to the install.
Repository: Administration (Read)Read branch-protection rules on each repo’s default branch.
Organization: Members (Read)List org members and check the org-wide 2FA enforcement setting.
Organization: Administration (Read)Read audit-log entries (Team / Enterprise plans only).

Subscribed webhook events: installation and installation_repositories. These let Polara know when you install, uninstall, or change the repository selection.

How to connect

Three steps. About a minute start to finish.

  1. 1

    Click Connect in Polara

    On your Integrations tab, click Connect on the GitHub card. A disclosure modal lists exactly what Polara will read.

    Polara dashboard Integrations tab with the GitHub card and Connect button highlighted
    Step 1
  2. 2

    Install on your organization

    GitHub opens a new tab showing the install consent screen. Pick the organization you want to connect.

    GitHub App install consent screen with the organization picker highlighted
    Step 2
  3. 3

    Choose repositories

    Select All repositories (recommended for SOC 2 completeness) or a specific subset. Confirm and GitHub redirects you back to Polara.

    GitHub install screen with the All repositories option highlighted
    Step 3

Choosing repositories

Recommendation: choose All repositories.

SOC 2 covers your entire production environment. Selecting only some repos means branch-protection and CODEOWNERS evidence for the omitted repos is not captured, and the change-management gap (K1) may not close automatically.

Use Selected only when: you have a separate non-production org (test, archived, or sandbox repos) that should be excluded from the SOC 2 boundary. Document the exclusion in your scope statement.

v1 captures branch protection and CODEOWNERS for the first 500 repos. Larger orgs: email founder@polaralabs.com to raise the cap.

Free tier limitations

GitHub’s audit-log REST API is available only on Team and Enterprise plans. On the Free plan, the audit-trail gap (B4) will not auto-close from GitHub alone.

Two workarounds:

  1. Upgrade to GitHub Team ($4 / user / month). For most small teams this is cheaper than the time cost of manual exports each quarter.
  2. Manual audit-log CSV export. In GitHub, visit github.com/organizations/{org}/settings/audit-log, export the CSV, then upload it through Polara’s evidence upload page. Repeat each quarter (or each audit cycle for Type 2).

Either path closes gap B4. The other six evidence types collect normally on Free plans.

How to disconnect

Disconnecting in Polara removes the connection record on our side. To fully revoke GitHub’s access tokens, you must also uninstall the GitHub App from your organization settings.

  1. In Polara: dashboard → Integrations tab → GitHub card → Disconnect.
  2. On GitHub: visit github.com/organizations/{your-org}/settings/installations.
  3. Click Configure next to Polara Evidence Collector, scroll to the Danger Zone, then click Uninstall.
GitHub organization installations settings page with the Polara Evidence Collector Uninstall button highlighted
Disconnect step: uninstall from GitHub’s org settings

Note: previously collected evidence stays attached to your assessment for audit reproducibility. Future syncs simply stop running once the install is removed.

Troubleshooting

Polara shows "pending" for more than 2 minutes after I clicked Install.
GitHub’s webhook delivery to Polara is usually instant but occasionally lags by up to a minute under load. Refresh the page first. If the card still does not flip to "Connected," click Connect again. The install URL is idempotent. GitHub will not re-install or duplicate anything if the install already exists.
I got a 500-repo cap warning. What does that mean?
Polara collects branch-protection and CODEOWNERS data for the first 500 repos in v1 to keep sync time predictable. If your org has more, email founder@polaralabs.com to raise the cap for your account. The first 500 repos still close gap K1 for the in-scope production environment.
K1 or B4 did not close after I connected GitHub.

K1 (change management): confirm your repos’ default branches each have a protection rule with "require pull-request reviews before merging" enabled. Polara closes K1 only when the production default branch is actually protected.

B4 (audit trail): if your org is on GitHub Free, the audit-log REST API is not exposed and B4 will not auto-close from GitHub. See Free tier limitations above for the two workarounds.

About a minute from here. Polara handles the rest.

Go to your dashboard
polara labs

Polara Labs builds both sides of the audit: the readiness platform startups use to earn a SOC 2 report or an ISO 27001 certificate, and the practice OS audit firms use to run the examination. Every price is published on the page it belongs to.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.