Get started

three steps
audit-linked

From waitlist sign-up to your first audit-linked morning PR.

Three steps close the gap between joining the waitlist and a Driftlock deployment in your VPC. You bring two watchlist surfaces and a CI identity; Driftlock brings the hermetic sandbox and the audit trail — your reviewers see only the pull requests that traced back to a real signal.

connect repo → configure → morning PR

The three steps

From GitHub App install to your first morning digest, in three steps.

Each step has a single team owner. Most trials reach the morning-digest PR within five working days; air-gapped deployments take a few days longer at step two for offline runner signing.

Step 1

Connect repo

Install the Driftlock GitHub App on the repos you want watched. Webhook subscriptions for pushes, pull requests, branch updates, Dependabot alerts, and check runs start landing in the in-VPC watcher within minutes — no new credentials required.

STEP 1 · GITHUB APP INSTALL + WEBHOOK SUBSCRIPTIONSGitHub Appdriftlock-trial · org-level installapi.github.com/apps/driftlock-trialwebhookDriftlock watcherin-VPC receiverauthenticates via App install credsSUBSCRIBED EVENTSpushpull_requestbranch_protection_ruledependabot_alertcheck_runinstall once per org · webhook events auto-subscribe on each watched repo

Step 2

Configure

Choose the signal sources the watcher should listen on — Dependabot, CI failures, NVD high-severity CVEs, on-call alerts — and the approver group whose sign-off closes a PR. A committed .driftlock/config.yaml pins both, reviewed by your platform team before anything drafts.

.driftlock/config.yaml

committed with the repo

# .driftlock/config.yaml
# committed alongside your repo; the watcher reads it on each branch draft.

sources:
  - github.dependabot      # Dependabot alerts as a branch trigger
  - ci.github-actions      # failed CI jobs surface as branch triggers
  - nvd.high               # NVD high+CVSS as branch triggers
  - oncall.pagerduty       # paged alerts as branch triggers

approvers:
  - "@acme/platform-eng"   # review queue; SIGNED-OFF closes the PR

sandbox:
  toolchain: hermetic-nix
  cache: shared-topology
  egress: deny-by-default

signing:
  commit: kms://acme/cosign
  sbom:   kms://acme/sbom
  rekor:  https://rekor.acme.internal

Step 3

First PR

By the next morning, an audit-linked pull request sits on your desk — every row links back to the alert, log line, or CVE GUID that produced it. Reviewers sign off in /demo without retracing the trigger; the diff stays within the path that tripped.

acme/platform-api

fix/cve-2026-2178

ready 6m

CI: green
awaiting sign-off

Pin pgwire to 0.14.4 to address GHSA-2026-2178

Bumps pgwire from 0.14.2 to 0.14.4 · sandbox run #412

trigger:GHSA-2026-2178

acme/payments

fix/flaky-test-charge-retry

ready 12m

CI: green
awaiting sign-off

Stabilise charge_retry_spec flake (3rd occurrence this week)

No dep change · sandbox run #413

trigger:CI run #8421

acme/auth-bff

chore/bump-jose-5.9

ready 18m

CI: green
awaiting sign-off

Bump jose from 5.7.0 to 5.9.6 (NVD CVSS 7.5)

Bumps jose from 5.7.0 to 5.9.6 · sandbox run #414

trigger:NVD CVE-2026-0917

Reviewers sign off in /demo — the live queue with the same rows but interactive toggles.

See the live sign-off flow

connect repo → configure → first PR

What lands on your desk

The trial cohort leaves the ten-day window with four concrete artefacts.

The trial is scoped, not a sandbox demo. Driftlock deploys into your cloud account, runs against a CI identity you already trust, and finishes with a walkthrough of the resulting audit trail. Every PR carries the alert, log, or advisory that produced it — the same flow /demo exercises, run against a live repo.

Nothing is shared with us after the trial ends unless you opt in. The deployment goes with you — same keys, same VPC, same audit log.

Trial deliverables

  • One self-hosted Driftlock deployment in your VPC.Helm + Terraform; nothing leaves your network.
  • A watching GitHub App on two repos of your choice.Dependabot, CI, and on-call surfaces wired in.
  • One audit-linked pull request per overnight signal during the trial.Signed commits; SBOM regenerated on every dependency touch.
  • A walkthrough of the audit trail with your platform team on day ten.Same reviewers who will sign off — the same flow /demo exercises.

ten days · self-hosted · audit-linked

Reserve a trial slot

Start with the waitlist, finish the trial in your VPC.

Drop your work email below and we'll reach out within two business days to scope a trial against one of your real monorepos. Each cohort runs the four deliverables above; pricing matches the tier the trial validates.

Start with the waitlist

We'll reply with a calendar link and a one-page brief on the trial. No follow-up sequence — just the call.