Install overview

Add Control9 to the pipelines you already run.

  • GitHub Action and GitLab CI component emit the same signed request model
  • Keep runners, state backends, and apply steps where they are
  • Works the same for human, automated, and agentic change sources

Not a CI platform, scanner, or IaC orchestration product.

Installing the GitHub Action or GitLab CI component connects your pipeline to Control9. Admin account sign-in uses work email or Google; GitHub is not an admin login method.

Request an assessment · Contact us

Action envelope

A signed, redacted request from the pipeline to Control9.

  • Carries plan summaries, fingerprints, and deploy intent
  • Leaves raw secrets and full source trees out by default
  • Becomes the input for policy, approvals, and tracking

A governance signal, not your artifact store or state backend.

Policy reference

Baseline packs that decide allow, observe, approve, or deny.

  • Tuned for Terraform, OpenTofu, CDK, and CloudFormation risk
  • Start from packaged rules, refine after shadow-mode findings
  • Keeps decisions explainable and versioned

Does not replace your existing policy-as-code or execution tools.

Approvals

Human review with a durable record attached.

  • Links intent, decision, approver, and deploy outcome
  • Survives after CI job logs expire
  • Routes high-impact production authority to the right owners

Not an identity provider, chatbot, or ITSM replacement.

Evidence export

Hand off structured governance records from your tenant.

  • Export decisions, approvals, and verification outcomes
  • Tied to package or enterprise entitlement
  • Customer-owned storage and SIEM paths available by package

This marketing site does not store product evidence.

Ask about export options

Billing FAQ

Price by governed surface area, not developer seats.

  • Meters protected repos, protected environments, and control events
  • Free and Team support self-service checkout
  • Growth, Enterprise, and Managed Controls use contact or assessment paths

See pricing for current tier limits and retention windows.

View pricing

Security model

Capture enough to explain decisions. Leave secrets out.

  • Default capture is metadata, fingerprints, policy context, and redacted excerpts
  • Raw secrets, full source, and full command output stay out by default
  • Retention follows your package entitlement

Read the full security page for capture and retention detail.

Security and data handling