rkito
Getting Started

Up and running
in an afternoon.

Four steps. No bespoke tooling. No long onboarding engagement. The first design audit on a real PR — the same day you start.

01

Adopt a Steering foundation in one click

AWS Well-Architected · OWASP Top 10 · ISO 27001 · CIS Benchmarks · SOC 2 · and more

rkito ships with pre-built Steering standards — AWS Well-Architected Framework, OWASP Top 10, ISO 27001 compliance templates, and more. One click adopts them into your org's Steering corpus. Review, customise, and approve. You have design intent from day one. No authoring from scratch.

Your own Steering artifacts can be added at any time. The open standards are a starting point, not a constraint.


02

Point rkito at your GitHub repository

Source code · Terraform · Helm · Kubernetes · OpenAPI · Docker Compose

Connect your repository. rkito reads your codebase — source code, Terraform, Helm charts, Kubernetes manifests, OpenAPI specs, and more — and automatically discerns your components, services, system boundaries, interfaces, and infrastructure topology. Everything discovered is loaded into your Architecture Ledger as a baseline.

rkito does not store your source code. It reads structure and extracts architectural entities. Your code stays in GitHub.


03

Review and commit your Architecture Ledger

Auto-generated Change Intention · Architect review workflow · Commit & merge to activate

The discovery run generates a Change Intention — a structured proposal of every architectural entity rkito found. Architects review, update, and approve it. You commit and merge. Your Architecture Ledger is live — the verified baseline against which every future PR will be audited.

This is the only manual step in the setup. After this, the CDA runs automatically on every PR without architect involvement — unless drift is detected.


04

Install the rkito GitHub App

GitHub App install → PR webhook auto-configured → CDA active on next PR

Install the rkito GitHub App into your organization. The PR webhook is configured automatically — no manual callback setup, no YAML to write. Every pull request from this point forward triggers the CDA gate before it reaches code review.

That is it. The next PR that opens gets a design audit against your Steering standards and Architecture Ledger.


Done.

The next PR your team opens gets a full design audit — evaluated against your Steering standards and Architecture Ledger, automatically, before it reaches code review. No architect needs to be present.

Deployment

Run it where you need it.

Three deployment models. The same design audit gate, the same CDA capability — wherever your constraints require it to run.

GitHub Actions
Available now
Run in your existing workflow

Add the rkito CDA as a step in your existing GitHub Actions pipeline. No infrastructure to manage. The design audit gate runs alongside your current build, test, and code quality steps — exactly where it belongs.

  • Drop-in GitHub Actions step
  • Results posted as PR check
  • Findings appear as PR comments
  • Blocks merge on unplanned drift
rkito Cloud
Early access
Fully managed · AWS · Data residency

Hosted on AWS. rkito Cloud handles CDA execution, results storage, and the full platform — fully managed, no infrastructure to run. For regulated industries, data residency compliance is available subject to AWS datacenter availability in your region, meeting judicial boundary requirements.

  • Fully managed — zero infrastructure
  • AWS-hosted · highly secure
  • Data residency compliance available
  • Judicial boundary requirements supported
On-Premises
Enterprise
Docker · Air-gapped environments

For teams that cannot send code or architectural data to external services, rkito ships as a Docker container. Run the full CDA stack inside your own infrastructure. No data leaves your environment.

  • Docker container deployment
  • Air-gapped environment support
  • No data leaves your network
  • Full feature parity with cloud

Data residency compliance on rkito Cloud is subject to AWS datacenter availability in your region. Contact us for specific jurisdiction requirements.

Open standards built in

You do not start from a blank page. These Steering foundations are pre-built in rkito and available for one-click adoption into any org.

AWS Well-Architected

Operational excellence, security, reliability, performance, cost

OWASP Top 10

Web application security risk and design constraint coverage

ISO 27001

Information security management and control compliance

CIS Benchmarks

Hardening and configuration security standards

SOC 2 Type II

Trust service criteria for security, availability, and privacy

NIST CSF

Cybersecurity framework for critical infrastructure

Custom Steering artifacts can be authored at any time. Open standards are a starting point, not a ceiling.

Ready to start?

Starter is free. No credit card. Up in an afternoon.