Getting started
From signing up to your first signed proof, in about a day.
What you need before you start
An email address, and either a repository you can grant read access to or a web address you can add a DNS record for. No card at signup: the plan you choose starts a 7-day trial, and you are asked for payment before it ends, not before you have seen it work.
You do not need to be an administrator of your GitHub organisation. You can install for your own account and pick individual repositories, or send the installation link to somebody who can.
The path
Confirm your email with the six-digit code we send and set a password — or sign in with Google or Microsoft, which can vouch for the address instead — then create your company and its first workspace. After that, connect where your code lives, add the first thing to watch, run a scan, look at what it found, let it fix one, and collect the proof. The in-product checklist at /onboarding tracks this and ticks each step from your actual records rather than from clicks.
Start with the system you would mind losing, not a side project. The point of the first scan is to find out whether this tells you anything useful, and it will tell you more about a real system.
How long it takes
A small repository scans in a few minutes; a large one with dependencies and a container image can take twenty. You are emailed when it finishes.
A fix proposal takes a few minutes after that. Reviewing it is the part that takes your time, and it should — it is a change to your code.