Skip to main content
Public verificationCheck certification and field status without entering a restricted workspace.
Independent reviewCertification decisions remain tied to reviewable evidence and accountable personnel.
Protected recordsSensitive evidence stays separated from the public trust view.
Source repository linkage

Connect code, firmware, safety-case, and deployment repositories to NASCA review.

Organizations and their engineering teams can attach repository evidence during registration. NASCA supports provider-neutral connection posture across GitHub, GitLab, Bitbucket, Azure DevOps, Gitea, Forgejo, and generic Git servers.

GITHUB

GitHub

Supports GitHub Cloud and GitHub Enterprise Server connection proof.

Hosts
github.com · github.enterprise.example
Verification
OAUTH_APP · ACCESS_TOKEN · DEPLOY_KEY · WEBHOOK · MANUAL_ATTESTATION
Link GitHub repository
GITLAB

GitLab

Supports GitLab SaaS and self-managed GitLab repository proof.

Hosts
gitlab.com · gitlab.enterprise.example
Verification
OAUTH_APP · ACCESS_TOKEN · DEPLOY_KEY · WEBHOOK · MANUAL_ATTESTATION
Link GitLab repository
BITBUCKET

Bitbucket

Supports Bitbucket Cloud and Data Center proof channels.

Hosts
bitbucket.org · bitbucket.enterprise.example
Verification
OAUTH_APP · ACCESS_TOKEN · WEBHOOK · MANUAL_ATTESTATION
Link Bitbucket repository
AZURE_DEVOPS

Azure DevOps

Supports Azure DevOps organizations, projects, and repository evidence binding.

Hosts
dev.azure.com · visualstudio.com
Verification
OAUTH_APP · ACCESS_TOKEN · WEBHOOK · MANUAL_ATTESTATION
Link Azure DevOps repository
GITEA

Gitea

Supports self-hosted Gitea installations for sovereign/internal operators.

Hosts
gitea.example · git.company.example
Verification
ACCESS_TOKEN · DEPLOY_KEY · WEBHOOK · MANUAL_ATTESTATION
Link Gitea repository
FORGEJO

Forgejo

Supports Forgejo/self-hosted community forge deployments.

Hosts
forgejo.example · code.company.example
Verification
ACCESS_TOKEN · DEPLOY_KEY · WEBHOOK · MANUAL_ATTESTATION
Link Forgejo repository
GENERIC_GIT

Generic Git

Provider-neutral fallback for regulated/self-hosted repositories.

Hosts
git:// · ssh:// · https://git.example
Verification
DEPLOY_KEY · WEBHOOK · MANUAL_ATTESTATION
Link Generic Git repository
Evidence flow

How repository evidence enters certification review

  1. Create or sign into the NASCA account.
  2. Register the organization or owner.
  3. Register the AI/autonomous system and classify the asset lane.
  4. Choose a provider and enter one or more real source repositories.
  5. Submit the evidence package through the NASCA registration workflow.
  6. Record every provider webhook, merge, or commit-range change through the repository-change review gate.
  7. Open the public registry profile and verify repository evidence and recertification posture.