What is AI coding platform governance?+
It is a senior review of the tools that write, host, and merge your code — GitHub, Cursor Origin, Copilot, and similar platforms. We look at where source of record lives, whether a second host is on by default, who can opt out, and whether your contracts, SOC 2 narrative, and customer security answers still match reality.
How is this different from an AI code audit?+
An AI code audit inspects what merged: security, architecture, licensing, and tests in the repositories. Platform governance inspects the toolchain that produced it: hosting, sync, defaults, identity, and policy. Most teams that rolled out Copilot or Cursor now need both. Start here if Origin or a new forge is already live and nobody wrote the decision down.
Is this only for Cursor Origin?+
Origin is the forcing function this month, but the engagement is the toolchain. We cover GitHub as system of record, Copilot and Cursor as authors, any mirror or agent-native host, and the policy you will reuse when the next vendor ships a similar feature.
Who is this for?+
CTOs, VPs of Engineering, and security leads at product companies that already pay for Copilot or Cursor. Typical triggers: a new code-host feature that shipped opt-out, a GitHub outage that tempted people onto a second forge, or a questionnaire that now asks where source is stored and which AI tools may train on it.
What do we get at the end?+
A written posture: system of record, allowed mirrors, admin opt-out status, contract and questionnaire gaps, and a 30-day action list. Optional next step is a Copilot / Cursor code audit on the repos that already moved, or ongoing AI code oversight as the team keeps shipping.
How long does a platform governance review take?+
Most reviews land in a week after a 30-minute scoping call and read-only admin / policy access. You do not need to pause delivery. You do need someone who can confirm what is enabled in GitHub and in the AI coding vendor's admin console.
Do you process our source through third-party AI?+
No. Client code stays in client environments. We inspect policy, admin settings, and architecture with senior engineers. We do not run proprietary source through external models as part of the engagement.
What if we already decided GitHub stays the system of record?+
Then document it, confirm Origin or any mirror is actually off or scoped, and make sure developers cannot create Origin-native repos that skip GitHub. A verbal 'we still use GitHub' is not a control if the default is on.
Can this feed SOC 2 or customer security reviews?+
Yes. Teams use the written posture to answer where source lives, which AI coding tools are approved, how opt-out is enforced, and what gets reviewed before merge. Pair with an AI code audit when the questionnaire also asks how Copilot or Cursor output is inspected.