Skip to content
CodeQuay

Sign-in Passkeys, authenticator apps and company accounts

The safe harbor
for your code.

The European git platform where the server enforces the rules, for everyone: no force-pushes to protected branches, no secrets in your history, an audit log nobody can rewrite. You focus on the code.

  • Data in EU data centers
  • Built in Italy
  • No exceptions for admins
main v2.4.0

How it works

What happens on every git push

No plugins to install, no hooks to set up on anyone's machine. Everything happens on the server, in a moment, the same way for everyone on the team.

  1. Step 1: Push as usual

    Your team keeps the git it knows, over HTTPS or SSH.

  2. Step 2: Protections

    Force-pushes and deletions on protected branches are rejected. Admins included.

  3. Step 3: Secret scanning

    Keys and tokens are stopped before they reach the history, with file and line.

  4. Step 4: Audit log

    Who, what, when and from where. Denied attempts included.

  5. Step 5: Backup and restore

    Nightly backups, with an automatic restore test every week.

CodeQuay by the numbers

  • 0 exceptions

    Branch protections apply to owners and admins too.

  • <2 s

    p95 for history, diff and blame on a 100,000-commit repository.

  • 7 days

    At most between two automatic backup restore tests.

  • 5 min

    Between watchdog checks on services, disk and certificates.

The platform

Security isn't an add-on.
It's how the platform works.

Eleven strengths, one platform. They stay out of the way until you need them, and then they speak plainly.

The server enforces the rules, not good intentions

A local hook can be switched off, a convention can be forgotten. Here the check runs on every push, and the rejection is explained right in the terminal of whoever tried it, in their own language.

  • No force-push on protected branches
  • Immutable release tags
  • Owners and admins included
Example: a force-push to the protected main branch is rejected by the server, which explains why and suggests integrating the remote changes with fetch plus merge or rebase.

Secrets stopped at push

Private keys, cloud tokens and API keys are blocked before they reach the history.

Append-only audit log

It can only grow: nothing is edited, nothing is deleted.

Isolation between projects

If you're not a member, you can't even tell a repository exists.

Modern sign-in

No password to remember, unless you want one.

  • Passkeys
  • TOTP apps
  • Google
  • Apple
  • Microsoft 365
  • OIDC

Alerts and system status

A watchdog every 5 minutes, and an email to admins if something is off.

  • Services
  • Disk and certificates
  • Backup and restore

Move from GitHub with your full history

Import branches and tags with a secret scan, then mirror automatically: GitHub Actions keeps running as it does today.

Backups with tested restores

Nightly backups and an automatic restore test every week. To us, a backup that has never been tested doesn't exist.

Built-in CI/CD, with the syntax you know

GitHub Actions workflows run on CodeQuay runners: on push, on tags, manually or on a schedule, with approvals for deployments.

Data in Europe, Italian company

Built in Italy by arimaslab. Instances run in data centers in the European Union, with no third-party tracking.

  • EU data centers
  • Built in Italy
  • No third-party tracking

Before and after

Same situation,
two different outcomes.

What happens when the rules depend on local conventions, and what happens with CodeQuay.

An admin force-pushes to main

Convention only

Allowed: whoever has the highest permissions bypasses conventions and local hooks.

With CodeQuay

Rejected by the server, owners and admins included, with the reason explained in the terminal.

A cloud key ends up in a commit

Convention only

It lands in the history: you have to rewrite history and rotate the key, often days later.

With CodeQuay

The push is rejected before the commit enters the repository, with the file and line.

Tag v2.4.0 is moved to a different commit

Convention only

The same version number can point to different code at different times.

With CodeQuay

Release tags are immutable: a fix ships as a new version.

You need to know who did what, and when

Convention only

You piece it together from scattered logs, if there are any.

With CodeQuay

An append-only audit log with user, action, time, IP and outcome, denied attempts included.

An external contractor works on a single project

Convention only

They can often see at least the names of the organization's other repositories.

With CodeQuay

To them, other projects don't exist: they don't show up in lists and return 404.

You need to restore a repository

Convention only

Only then do you find out whether the backup actually works.

With CodeQuay

Restores are tested automatically every week; if one fails, an alert goes out.

Who it's for

For teams accountable
for their code.

All use cases

FAQ

The questions we hear most often

The short answers. You'll find all the others on the FAQ page.

All questions
  • How do I get an account?

    Sign-up is open: anyone can create an account at git.codequay.it/signup and start on the Free plan, then upgrade online to Team or Business whenever they like.

    If someone invites your email address to an organization, a project or a repository, you can also create your account from the invitation link: the address counts as already verified.

    Plans and sign-up Direct link

  • What is a passkey, and how do I use one on CodeQuay?

    A passkey is a credential that replaces your password: it lives on your device or in your password manager and is unlocked with your fingerprint, face or PIN. It's bound to the site it was created for, so a look-alike page can't use it, which makes it the strongest protection against phishing.

    On CodeQuay you add one after your first sign-in, from Settings → Security. From then on you sign in by picking the passkey, with no password and no codes: a passkey unlocked with your fingerprint, face or PIN already counts as strong authentication.

    You can register more than one, for example on your laptop and your phone. Passkeys synced by iCloud Keychain, Google Password Manager or a password manager are available on all your devices, and hardware security keys work too.

    Sign-in and passkeys Direct link

  • What if I accidentally commit a key or a token?

    The push is rejected. CodeQuay scans the new files in every push and stops any that contain recognizable credentials: private keys, AWS access keys, Google API keys, live Stripe keys, GitHub tokens, Slack tokens and CodeQuay personal tokens. The message points to the file and line and shows only the start of the value; the audit log records the rule that was broken, never the secret.

    To move on, remove the secret from the history (a later commit that deletes it isn't enough) and revoke the credential. If the secret was already in the history of an imported repository, the import scan flags it: in that case it needs to be rotated.

    Secret blocking Direct link

  • Can I migrate from GitHub and keep my full history?

    Yes. You authorize the instance key as a deploy key on the GitHub repository and start the import: it copies every branch and every tag with the full history (pull requests aren't imported), protects the default branch and scans the entire history for secrets, reporting type, file, line and commit without ever showing the value. If it's interrupted, just run it again and it picks up where it left off.

    Developers only need to change the remote URL in their existing clones: commits, hashes, branches and tags stay the same. Coming from another git platform? Use git clone --mirror and git push --mirror.

    How migration works Direct link

  • Where is my data stored?

    Repositories, databases and backups stay in data centers in the European Union. CodeQuay is built in Italy by arimaslab srl, and neither the website nor the platform uses third-party tracking, analytics or advertising.

    Data and sovereignty Direct link

  • How much does CodeQuay cost?

    Prices are per user, excluding VAT, billed monthly or yearly (which costs less), and they're published on the Pricing page:

    • Free: €0
    • Team: €6 per user per month, or €60 per user per year (2 months free)
    • Business: €18 per user per month, or €180 per user per year (2 months free)
    • Sovereign: Custom quote

    Protections, secret blocking at push, the audit log and tested backups are included in every plan; a dedicated instance, in the EU or on your premises, is quoted on request.

    Pricing and plans Direct link

CodeQuay · by arimaslab

Bring your code
into asafe harbor.

A guided migration from GitHub, with your full history and your CI right where it is.