Your first audit
Use this checklist for your first successful audit in Guardix.
Before you start
Section titled “Before you start”- Signed in (Authentication)
- Know which branch or commit represents the code you want reviewed
- For private repos: GitHub App authorized (Connecting repositories)
- Skim Audit setup options for contract scope and documentation
- Open Code Audits → New audit and connect or select your repository (or upload a source archive when that option is available).
- Select branch, tag, or commit for the snapshot.
- Optionally set contract scope and attach additional documentation (Audit setup options).
- Start the audit and confirm pricing at Stripe checkout (team workspaces may apply a free-audit credit).
- Watch progress on the audit page — expect hours for a full pipeline, not minutes. Answer any open questions on the in-progress page if shown (Open questions).
- When completed, open findings and scan severities top-down, or use the code heatmap for a file-level view.
- Mark review labels per finding and set an audit verdict when your team agrees on overall status.
- Download a report or copy a share link when ready (Downloading reports, Sharing audit results).
If something fails
Section titled “If something fails”- Read error messages in the UI — duplicate repo or permission issues are often explained there.
- For in-progress vs completed confusion, confirm you are viewing the correct scan version in the UI.
Understanding findings — how to read and prioritize what you see.