Muji Lab

TutorialbyMuji Lab

Invite us
to your repository.

One account, one click, revocable.

A private repository is your project at GitHub, visible to you alone. To let us audit it, you open a named door: one specific account, which you close whenever you want. We read your code and never touch it, and GitHub's history attests to it. Thirty seconds.

Adding mujilab-audit as a collaborator on a private repository.

Four steps.

  1. 01

    From your project's page, open Settings. The one in the project's row, to the right of Insights, not your account's.

  2. 02

    In the left menu, click Collaborators. GitHub may ask for your password again here: that is its own security, on its own site.

  3. 03

    Click Add people, then type mujilab-audit, one word, with a dash.

  4. 04

    Send the invitation. You will recognize Muji, sitting peacefully, in the profile picture.

Word for word.

What the video says, to read at your own pace or find one word again.

Read the full transcript

Your project is online. One gesture left: giving us read access. From your project's page, open Settings. Careful: the one in this row, next to Insights, not your account's.

In the left menu, Collaborators. GitHub may ask for your password again here: that is its own security before touching access. We never see it.

Add people, then type mujilab-audit, one word with a dash. That is our reading account. You will recognize Muji, sitting peacefully, in the profile picture.

Send the invitation. On our side, this account reads your code and never touches it: that is a written commitment, and your project's GitHub history attests to it. The slightest change would be visible there, with its author and date. And you can cut this access whenever you want.

That is it, your part is done. We accept the invitation on our side, your space moves forward on its own, and you get an email. Nothing to watch. And when the audit is over, you cut the access in two clicks: that is the third video.

Get your project audited

Your code is online and we have read access. We look for what breaks and what leaks, then hand you the list of what to fix, in order.

See the audit service

We refuse your passwords: the code only, never your credentials.

A question? Write to us.