Prove Your Compliance.
Don't Just Claim It.
The world's first compliance-native Git platform with blockchain attestation.
GuardGit scans your repositories against 12 regulatory frameworks, computes your compliance posture, and lets you prove it on-chain with zero-knowledge proofs. No auditor needs to trust you. They can verify.
This Is Not “Yet Another Git Platform”
GitHub, GitLab, and Bitbucket host code. GuardGit provides you with the resources for finding, fixing, and generating evidence that your code is compliant.
Not a scanner. A compliance platform.
Other tools find vulnerabilities. GuardGit maps them to regulatory controls, computes your compliance posture, and generates audit-ready evidence.
Not another Git host. A compliance control plane.
GuardGit uses Gitea as a Git substrate and layers a full compliance engine on top. Your code stays yours. Compliance becomes automatic.
Not trust-me compliance. Prove-it compliance.
With Vericode, your scan results are anchored on Horizen blockchain and verified with zero-knowledge proofs on zkVerify. Auditors can verify without seeing your code.
How It Works
From import to on-chain proof in four steps.
Import Your Repos
Connect your GitHub repositories or create new ones. GuardGit wraps your existing workflow.
Scan for Compliance
Run framework-specific scanners that evaluate your code against 1,143+ security signals.
Review Findings
See exactly what passed and what failed, grouped by signal, with file-level detail and remediation guidance.
Attest On-Chain
Anchor your compliance posture on Horizen blockchain and generate zero-knowledge proofs via zkVerify.
Everything You Need to Prove Compliance
A complete compliance control plane for your repositories.
Multi-Framework Scanning
Proprietary scanners built from official regulatory sources of truth. Not generic checklists. Evaluate against CMMC, ISO 27001, SOC 2, HIPAA, and 11 more frameworks simultaneously.
Signal-Level Findings
Findings grouped by compliance signal, not raw scanner output. See 5 unique issues across 40 files, not a confusing list of 40 items. Each finding maps to specific regulatory controls.
Compliance Posture Score
Real-time 0-100 score computed from your open findings, weighted by severity. Track improvement over time. Per-framework compliance percentages and control coverage metrics.
Vericode: Blockchain Attestation
DataHubz's proprietary Vericode engine anchors your compliance posture on blockchain and generates zero-knowledge proofs. Prove compliance without exposing your code. In partnership with Horizen and zkVerify.
Evidence Export
Export findings as JSON or beautifully formatted PDF reports. Compliance dashboard exports with framework coverage, posture scores, and findings distribution.
CSE Registry Integration
Powered by the Compliance Signal Enumeration registry. 1,143+ signals, 2,062+ control mappings, finding templates with remediation guidance, and tool mappings for 20+ security tools.
Finding Management
Suppress findings with auditable reasons (false positive, accepted risk, compensating control). Every suppression records who, when, and why. Suppressed is never confused with passed.
Per-User Blockchain Wallet
Each user creates or imports their own Horizen wallet. Export private keys anytime. Your wallet, your attestations, your compliance proofs. Fully sovereign.
12 Regulatory Frameworks. One Platform.
Scan against any framework. See exactly which controls pass and which don't.
Vericode: Trustless Compliance
Proprietary DataHubz technology enabling the world's first blockchain-attested compliance platform for code repositories.
Evidence Anchoring
DataHubz's Vericode engine anchors your compliance evidence as a SHA-256 hash on Horizen MainNet. Immutable, timestamped, and permanently verifiable through our partnership with Horizen.
Zero-Knowledge Proofs
DataHubz's proprietary proof circuits generate Groth16 proofs verified on zkVerify mainnet. Prove you have zero critical vulnerabilities without revealing a single line of code.
Your Keys, Your Proofs
Each user has their own Horizen wallet. Generate, import, or export private keys. Your compliance attestations are sovereign. No vendor lock-in. No trust required.
Stop Claiming Compliance.
Start Proving It.
Sign up free. Import your repos. Run your first scan. Attest on-chain. All in under 5 minutes.