Install overview
Add Control9 to the pipelines you already run.
- GitHub Action and GitLab CI component emit the same signed request model
- Keep runners, state backends, and apply steps where they are
- Works the same for human, automated, and agentic change sources
Not a CI platform, scanner, or IaC orchestration product.
Installing the GitHub Action or GitLab CI component connects your pipeline to Control9. Admin account sign-in uses work email or Google; GitHub is not an admin login method.
Request an assessment · Contact us
Action envelope
A signed, redacted request from the pipeline to Control9.
- Carries plan summaries, fingerprints, and deploy intent
- Leaves raw secrets and full source trees out by default
- Becomes the input for policy, approvals, and tracking
A governance signal, not your artifact store or state backend.
Policy reference
Baseline packs that decide allow, observe, approve, or deny.
- Tuned for Terraform, OpenTofu, CDK, and CloudFormation risk
- Start from packaged rules, refine after shadow-mode findings
- Keeps decisions explainable and versioned
Does not replace your existing policy-as-code or execution tools.
Approvals
Human review with a durable record attached.
- Links intent, decision, approver, and deploy outcome
- Survives after CI job logs expire
- Routes high-impact production authority to the right owners
Not an identity provider, chatbot, or ITSM replacement.
Evidence export
Hand off structured governance records from your tenant.
- Export decisions, approvals, and verification outcomes
- Tied to package or enterprise entitlement
- Customer-owned storage and SIEM paths available by package
This marketing site does not store product evidence.
Ask about export options
Billing FAQ
Price by governed surface area, not developer seats.
- Meters protected repos, protected environments, and control events
- Free and Team support self-service checkout
- Growth, Enterprise, and Managed Controls use contact or assessment paths
See pricing for current tier limits and retention windows.
View pricing
Security model
Capture enough to explain decisions. Leave secrets out.
- Default capture is metadata, fingerprints, policy context, and redacted excerpts
- Raw secrets, full source, and full command output stay out by default
- Retention follows your package entitlement
Read the full security page for capture and retention detail.
Security and data handling