§GitHub connector · beta

Your architecture, versioned like code.

Connect your GitHub account and treat infrastructure diagrams the way you treat everything else that matters — in Git: versioned, reviewable, and owned by your team.

plant-network.basalt · pull request #214
zone "Industrial DMZ" [level: dmz] {
- Historian Mirror [icon: historian]
+ Historian Mirror [icon: historian, conduit: TLS]
+ Jump Host [icon: bastion, access: L2-eng]
}
OKIEC 62443 zoning check passedWARNconduit SL below zone target · 62443-3-3
3 frameworks
validated on every PR
0 credentials
shared with Basalt
100% text
diagrams as DSL files
Git-native
history you already own
THE IDEA

Diagrams aren't pictures. They're files.

Every diagram is a Basalt DSL file — a precise, human-readable description of your architecture that renders to a live canvas. Because it's text, it belongs in your repository, right next to the systems it describes.

The GitHub connector is the bridge. Link your account once, and your architecture becomes a first-class citizen of your codebase — diffable in a pull request, tracked through history, and owned by your team rather than trapped in a drawing tool.

Isometric laptop rendering a Basalt diagram as code
HOW CONNECTING WORKS

One click. No passwords shared.

01

Start from your dashboard.

Sign in to Basalt, then select Connect GitHub in the sidebar.

02

Grant access on GitHub.

GitHub asks your permission before Basalt can see anything. You approve the scope on GitHub's own screen — Basalt never sees your credentials.

03

You're linked.

GitHub attaches to your existing Basalt account as an added capability. Open a diagram from a repo, save one back as a commit or pull request, or spin up a brand-new repo — the connector turns green to confirm.

It's a link, not a second login.

Your Basalt account, your diagrams, and your team stay exactly as they are — GitHub simply becomes something Basalt can read on your behalf. Sign-in still happens the way it always did; connecting GitHub doesn't create a new identity or a duplicate account.

A person signing in on their phone
WHY PUT DIAGRAMS IN GIT

Four things you get the moment architecture is text.

One source of truth.

The DSL file is the diagram. Change the file, the canvas follows; change the canvas, the file follows. No stale export drifting out of sync with reality.

Change you can review.

A diagram is text, so an architecture change reads as a diff in a pull request — reviewable, commentable, approvable, the same way code is.

History that's actually yours.

Every version lives in your repo, under your account, with the full audit trail Git already gives you. Nothing locked inside a vendor.

Next to the systems it describes.

Architecture stops being a document someone made once and forgot. It lives beside the code it maps, and stays current because it's part of the same workflow.

BUILT FOR REGULATED AND INDUSTRIAL TEAMS

Compliance as a gate. Not a document review.

Basalt treats OT and industrial systems as first-class alongside cloud, and pairs every diagram with a deterministic compliance validator that checks it against frameworks like IEC 62443, NIST 800-82, and the Purdue Model.

Putting that in Git is where it gets powerful. An architecture change arrives as a pull request; the compliance check runs against it automatically; and a diagram that fails a segmentation or zoning rule is caught before it merges. For teams that answer to auditors, that's the difference between hoping the architecture is right and proving it.

CHECKS ON EVERY PR
  • IEC 62443zone / conduit segmentation
  • NIST 800-82OT control baselines
  • Purdue Modellevel-crossing rules
SECURITY & PRIVACY

We treat your GitHub access as the sensitive credential it is.

A hand holding a padlock

You grant the scope.

Access is requested on GitHub's own authorization screen, and you decide what to approve. Basalt only ever writes when you explicitly save, and never handles your GitHub password.

Your access key never touches the browser.

The token GitHub issues is passed straight to Basalt's backend and held in an access-controlled store only our server can reach. It is never returned to your browser.

Tied to your account.

The connection belongs to your Basalt account and nothing else. Deleting your account removes it.

Revocable anytime.

Revoke Basalt's access from your GitHub settings at any moment and the connection stops working immediately — no dependence on us to cut it off.

How this data is handled is described in full in our Privacy Policy (Section 6, GitHub connector and connected repositories).

WHAT'S AVAILABLE NOW

Everything the connector does. Live today.

LIVE

Connect and list repositories

Link your GitHub account and browse your repositories inside Basalt.

LIVE

Open, commit, and check

  • Open .basalt files straight from a repo onto the canvas.
  • Save changes back as commits and pull requests, as reviewable diffs.
  • Automated compliance checks that run on every pull request.

The full connector workflow is live for pilot teams. If you'd like access, get in touch.

QUESTIONS

Does Basalt store my code?

No. Basalt reads the files you open and writes only the changes you explicitly save — a commit, a pull request, or a new repository you ask it to create. It never bulk-clones or copies your repositories.

Does connecting create a second account?

No. GitHub links onto your existing Basalt account as an added capability. You keep signing in the way you always have.

What access does Basalt request?

Access to the repositories you work with — enough to read the files you open and, when you choose to save, to commit changes, open pull requests, and create new repositories. You approve the scope on GitHub, and you can review or revoke it from your settings at any time.

Can I disconnect?

Yes — revoke Basalt from your GitHub account settings, and the connection stops working right away.

Where can I read how you handle this data?

In our Privacy Policy. Section 6 covers exactly what the connector reads, how your access token is stored, and how to disconnect.

Bring your architecture into your codebase.

Connect GitHub from your Basalt dashboard and start treating your diagrams like the source of truth they are.