One source of truth.
The DSL file is the diagram. Change the file, the canvas follows; change the canvas, the file follows. No stale export drifting out of sync with reality.
Connect your GitHub account and treat infrastructure diagrams the way you treat everything else that matters — in Git: versioned, reviewable, and owned by your team.
zone "Industrial DMZ" [level: dmz] {- Historian Mirror [icon: historian]+ Historian Mirror [icon: historian, conduit: TLS]+ Jump Host [icon: bastion, access: L2-eng]}
Every diagram is a Basalt DSL file — a precise, human-readable description of your architecture that renders to a live canvas. Because it's text, it belongs in your repository, right next to the systems it describes.
The GitHub connector is the bridge. Link your account once, and your architecture becomes a first-class citizen of your codebase — diffable in a pull request, tracked through history, and owned by your team rather than trapped in a drawing tool.

Sign in to Basalt, then select Connect GitHub in the sidebar.
GitHub asks your permission before Basalt can see anything. You approve the scope on GitHub's own screen — Basalt never sees your credentials.
GitHub attaches to your existing Basalt account as an added capability. Open a diagram from a repo, save one back as a commit or pull request, or spin up a brand-new repo — the connector turns green to confirm.
Your Basalt account, your diagrams, and your team stay exactly as they are — GitHub simply becomes something Basalt can read on your behalf. Sign-in still happens the way it always did; connecting GitHub doesn't create a new identity or a duplicate account.

The DSL file is the diagram. Change the file, the canvas follows; change the canvas, the file follows. No stale export drifting out of sync with reality.
A diagram is text, so an architecture change reads as a diff in a pull request — reviewable, commentable, approvable, the same way code is.
Every version lives in your repo, under your account, with the full audit trail Git already gives you. Nothing locked inside a vendor.
Architecture stops being a document someone made once and forgot. It lives beside the code it maps, and stays current because it's part of the same workflow.
Basalt treats OT and industrial systems as first-class alongside cloud, and pairs every diagram with a deterministic compliance validator that checks it against frameworks like IEC 62443, NIST 800-82, and the Purdue Model.
Putting that in Git is where it gets powerful. An architecture change arrives as a pull request; the compliance check runs against it automatically; and a diagram that fails a segmentation or zoning rule is caught before it merges. For teams that answer to auditors, that's the difference between hoping the architecture is right and proving it.

Access is requested on GitHub's own authorization screen, and you decide what to approve. Basalt only ever writes when you explicitly save, and never handles your GitHub password.
The token GitHub issues is passed straight to Basalt's backend and held in an access-controlled store only our server can reach. It is never returned to your browser.
The connection belongs to your Basalt account and nothing else. Deleting your account removes it.
Revoke Basalt's access from your GitHub settings at any moment and the connection stops working immediately — no dependence on us to cut it off.
How this data is handled is described in full in our Privacy Policy (Section 6, GitHub connector and connected repositories).
Link your GitHub account and browse your repositories inside Basalt.
The full connector workflow is live for pilot teams. If you'd like access, get in touch.
No. Basalt reads the files you open and writes only the changes you explicitly save — a commit, a pull request, or a new repository you ask it to create. It never bulk-clones or copies your repositories.
No. GitHub links onto your existing Basalt account as an added capability. You keep signing in the way you always have.
Access to the repositories you work with — enough to read the files you open and, when you choose to save, to commit changes, open pull requests, and create new repositories. You approve the scope on GitHub, and you can review or revoke it from your settings at any time.
Yes — revoke Basalt from your GitHub account settings, and the connection stops working right away.
In our Privacy Policy. Section 6 covers exactly what the connector reads, how your access token is stored, and how to disconnect.
Connect GitHub from your Basalt dashboard and start treating your diagrams like the source of truth they are.