Sanctra is deliberate. Every stage is transparent, every artifact is inspectable, and nothing modifies your default branch without your explicit review.
OAuth into Sanctra, install the GitHub App with least-privilege scopes, and pick exactly which repositories Sanctra can see. Access is per-installation and revocable at any time.
A sparse checkout inspects your package files, lockfiles, existing Dockerfiles, workflows, env hints, and folder shape. You get a health score, detected stack, and a ranked list of findings — each backed by evidence.
Each recommendation carries severity, effort, and the files it applies to. Include what you want in the generation pass; skip the rest with an optional reason kept in history.
The generation wizard shows a file tree, code diff, and validation results. Errors block PR creation; warnings require explicit acknowledgment. Nothing writes to your default branch.
A Sanctra branch appears in GitHub with the generated files, a summary description, and links back to the analysis. Review it like any other PR. Merge on your schedule.
Request access to the private beta.