GitHub Real-time Monitoring

Every commit. Every PR. Every fork.
Classified in under 30 seconds.

PreserveIP connects to your GitHub organization via webhooks. Every push event, pull request, fork, and code review is instantly queued, scanned by Claude AI for IP leakage signals, and surfaced to your security team — with actor attribution and resource links.

Request Access → See Event Feed
GitHub Event Scanner — acme-ai org Live
push
jsmith pushed to ml-infra/main — "fix training loop timeout"
acme-ai/ml-infra · 3 files added · checkpoints/gpt4-finetune-v3.pt (2.3 GB) · 14:02:11
CRITICAL
PR
contractor-03 opened PR #412 — "Add data preprocessing pipeline"
acme-ai/infra · Modified: src/pipeline/data_loader.py, configs/schema.yaml · 13:48:05
HIGH
fork
departing-eng forked acme-ai/core-llm to personal/core-llm
Fork event detected · Personal account · 5 minutes before offboarding · 13:22:44
HIGH
review
sarah.chen approved PR #398 — "Export model for client demo"
acme-ai/ml-infra · Review comment includes external S3 link · 12:55:17
MEDIUM
push
dev-team pushed to frontend/main — "update UI components"
acme-ai/web · 12 files modified · No IP signals detected · 12:30:02
Clean

Event Coverage

Every GitHub event type — nothing slips through

📤

Push Events

Every commit to every branch across your GitHub organization. File diffs, commit messages, and added file signatures are all scanned.

🔀

Pull Requests

PR titles, descriptions, diff content, and linked issues are classified. External contributors and contractor accounts get extra scrutiny.

🍴

Fork Detection

Fork events are flagged with actor context — especially powerful for detecting pre-departure exfiltration by employees with notice periods.

💬

PR Reviews & Comments

Code review comments and PR discussions can contain external links, credential snippets, or architecture disclosures — all monitored.

📋

Release & Tag Events

Repository releases and tag creation — especially to public repositories — are scanned for model artifacts and dataset attachments.

👁️

Visibility Changes

Private-to-public repository changes are instantly flagged as critical — the single most dangerous configuration change for IP exposure.


Setup

Live in under 5 minutes

1

Add Organization Webhook

GitHub org Settings → Webhooks → Payload URL: your PreserveIP endpoint. Select push, PR, fork, and review events.

2

Set Webhook Secret

Generate a 32-character secret and enter it in both GitHub and PreserveIP. All payloads are HMAC-SHA256 verified.

3

Register Your IP Artifacts

Upload model fingerprints and dataset schemas through the PreserveIP dashboard. Detection activates immediately.

4

Monitor Your SOC Dashboard

Events flow in real time. Your team sees severity, actor, AI reasoning, and a direct link to the GitHub resource within 30 seconds.


Get Started

Connect your org. We'll watch every commit.

Setup takes 5 minutes. 90-day pilot available for design partners.

Start Free Pilot → See Legal Evidence Packaging →