For teams evaluating SiftPulse against GitHub Enterprise Cloud, GitHub Enterprise Server, or running an active compliance review. What's compatible today, what the current security posture looks like, and what's not yet built.
The SiftPulse GitHub App installs against the same OAuth flow on Enterprise Cloud as on github.com. On Enterprise Server, an enterprise admin must allow-list the SiftPulse GitHub App for the org before members can install it — the GitHub admin guide for that allow-list step is linked below.
| Capability | Status | Notes |
|---|---|---|
| GitHub Enterprise Cloud | Supported | Installable from the GitHub Marketplace via the same OAuth flow as github.com orgs. Per-installation tokens, no shared credentials. |
| GitHub Enterprise Server (3.x+) | Supported | Enterprise admins must enable GitHub App allow-listing for the org before install (docs). |
| Single-tenant installation scope | Supported | Each SiftPulse installation is scoped to a single GitHub org/account. Webhook traffic is per-installation; tokens are per-installation. |
| Per-installation GitHub tokens | Supported | GitHub-issued installation tokens are auto-refreshed, encrypted at rest, never logged. |
| GitHub Enterprise Cloud — Data Residency (EU/UK) | Not yet | The Data Residency (DR) addon is not yet supported for EU/UK customers. DR support is on the roadmap — see roadmap below. |
See Enabling GitHub Apps for your Enterprise (GitHub Docs) for the exact allow-list steps an Enterprise Server admin needs to run before installing any GitHub App.
The short version of what's already true today. The full scope — sub-processors, encryption in transit and at rest, access control, retention, GDPR/DPA, EU AI Act Article 50, and responsible disclosure — lives on /security.
lib/ai-act-disclosure.js) so no surface can silently drop it.GET /api/audit/export?repo=<owner/repo>&since=<iso-date> (last 30 days by default).See /security for the full scope.
Honest list, so prospects asking through procurement aren't blindsided by it during a review.
Waitlist only. SiftPulse today runs as a hosted multi-tenant SaaS on Render + Neon. A self-hosted build with a BYOK model endpoint is on the roadmap (see below) — joining the waitlist moves that priority up. /security#on-prem
Not yet supported. The customer dashboard at /app uses magic-link email authentication only — no passwords, no SAML/SSO connector. SAML/SSO is on the roadmap — see /security/enterprise for the current auth model, targeted identity providers, and first-install migration window.
Not yet supported. There is no SAML/SCIM integration with an enterprise IdP today. SCIM provisioning hangs off the same SSO work above.
Audit in progress with our assessor. Expected report issuance Q4 2026. Interim controls evidence and an executive summary are available under NDA — request via the form below or write to security@siftpulse.polsia.app. /security#compliance
Out of scope. SiftPulse does not store, process, or transmit Protected Health Information (PHI). Customers subject to HIPAA should not route PHI through SiftPulse surfaces. /security#compliance
The next 12 months, in order, subject to prioritization by enterprise inbound:
If one of these is a hard requirement for your procurement review, the form below reaches us directly — we respond within two business days.
For teams over 50 repos, under active compliance review, or testing SiftPulse against a regulated workload, we run a scoped evaluation with you directly. We'll align on your GitHub Enterprise tier, the repos you want reviewed, and any compliance questions your security team needs answered before a procurement review.