Solutions

Scale your judgment across every team.

You cannot review every change in every repo. You can decide what good looks like once, and let each team’s scan hold the line.

Scan coveragerepos by owning team
checkout · 2 repos
checkout-api2d agoCurrent14
cart41d agoStale (30+ days)6
payments · 1 repo
ledger9d agoOver 7 days11
Unassigned · 1 repo
legacy-batchneverNever scanned

Example data. Repos with no team binding are grouped under Unassigned, so the mapping gap shows instead of hiding.

Know which repos nobody scans

Scan Coverage groups your repos by owning team, with the last scan time and staleness of each. Never-scanned and stale repos are marked. Repos with no team binding are grouped as Unassigned, so the mapping gap is visible.

PlanPer-team views start at the Plus plan. See pricing.

70 controls, with the evidence behind them

Every control maps to the services it covers. Control status is computed for each team, and the organization answer is the worst of them: a control counts only when every team is covered.

Teams inherit evidence through service ownership. Your backup drills for a shared database count for every team that depends on it.

Compliance postureTeams view
Controlcheckoutpaymentsplatform
SLO-Tied AlertingRC-001 · detective2
Synthetic MonitoringRC-002 · detective1
Alert Noise ReductionRC-004 · corrective975
On-Call CoverageRC-005 · preventive2
Incident RunbooksRC-006 · preventive4

Example data. A lit row is one failure class that recurs across teams. A lit column is one team with many.

Practices count too

Some controls are practices, not code: on-call coverage, runbooks, alert reviews. Record them as evidence from the CLI, scoped to the team that does the practice.
rvl — evidence
$ rvl evidence submit --control=RC-004 --team=checkout \
--type=document --name="Monthly alert review" …

Evidence carries a scope: team, service, or global. A control counts for the organization only when every team is covered.

Not a replacement for you

One early user said it well: it is the non-naive version of “make me an AI SRE”. You do not replace the SRE. You make them superpowered.

Run your first scan free.

Install the CLI, scan a repo, and read the findings in your terminal. Your source code stays on your machine.