Skip to main content

GitHub-native · release-scoped · client-owned

Add browser evidence to the checkout release your agency is already shipping.

Record browser-observed checkout scripts and selected security-impacting headers, compare them with an approved baseline, and preserve the result inside the caller’s own GitHub workflow.

Release evidence—not PCI certification, penetration testing, production monitoring, alerting, or blocking.

Acceptance sequencev0.3.1
Unchanged checkoutPASS
Controlled script changeREVIEW_REQUIRED
RollbackPASS

Evidence remains in the agency or client repository.

Marketplace ActionPublished GitHub Action · v0.3.1Open evidence ↗Verified browser runRun 30810163186Open evidence ↗Preserved evidenceBaseline · change · rollbackOpen evidence ↗

The release record a source diff cannot provide

Observe the checkout the browser actually receives.

Source and QA records remain useful, but they do not necessarily preserve the exact browser-served script and selected-header state delivered during a release. This adds that narrow evidence layer without pretending to be continuous security monitoring.

01

Observe

Passively record scripts and selected security-impacting headers from one authorised staging or demo checkout.

02

Compare

Compare the browser observation with a previously reviewed baseline and approval records.

03

Decide

Return PASS or REVIEW_REQUIRED without labelling every difference malicious or insecure.

04

Preserve

Keep the passport, comparison, snapshot and readable report inside the caller’s GitHub workflow.

Tight data boundary

Useful evidence without collecting checkout secrets.

Passive GET navigation only. No form submission. Script contents are fingerprinted; complete script bodies are not retained.

  • No cardholder or customer data
  • No credentials, cookies, or form values
  • No URL query values or response bodies
  • No complete script source stored

Founding agency offer

Start with a small acceptance-based evidence pack.

The Action remains free to self-install. Paid work covers scoped configuration, controlled acceptance, evidence verification, and handover.

Founding InstallationImplementation
$750 USD · total fixed scope

Move the accepted evidence workflow into the agreed client implementation.

  • Final GitHub Actions workflow configuration
  • Reviewed baseline and approval records
  • Controlled acceptance-sequence verification
  • Evidence and digest verification
  • Technical handover documentation
  • Access-removal guidance
  • 14 days of setup support
No working acceptance proof, no fee.Scope and access boundaries are agreed in writing before work begins.

Best fit

Merchant-controlled checkout releases using GitHub Actions.

Especially Magento / Adobe Commerce, custom BigCommerce checkout, Salesforce Commerce Cloud, WooCommerce customisation, and custom React or Next.js checkout flows.

Not a fit

Unauthorised testing or a request for a compliance guarantee.

Not for third-party checkout scanning, PCI certification, penetration testing, vulnerability assessment, or replacement of continuous monitoring.

Clear boundaries

Questions technical and delivery teams ask.

Does this certify PCI DSS compliance?

No. It provides release-scoped evidence that may support change-management and evidence processes. It does not by itself satisfy PCI DSS Requirements 6.4.3 or 11.6.1, and it is not a QSA assessment.

Does it replace runtime monitoring or blocking?

No. It complements—but does not replace—CSP, script governance, runtime monitoring, alerting, or blocking controls.

Why is this different from a Git diff?

A Git diff describes source changes. The passport records what a controlled browser observed, the baseline comparison, approval status, and GitHub workflow provenance.

Will TransferVerity receive payment or customer data?

No checkout submission is required. Evidence excludes cardholder data, credentials, cookies, form values, query values, response bodies, and complete script bodies.

Request the one-page agency scope

Test the acceptance sequence before committing to an installation.

Send only non-sensitive architecture and staging details. Never email credentials, private URLs, customer data, or card data.

Request agency scope