The GitCover ecosystem

An ecosystem with clearly separated roles.

GitCover is more than software: it is the interplay of an open community, a freely accessible body of rules, Git-native tools and a service-provider craft that translates all of this into practice. This separation keeps the open core trustworthy and the craft viable.

The four layers

Community · Open Source

gitcover.org

The open trust and standards core: reference models, tools and the community behind Git-native compliance. Becomes public once the legal prerequisites are met.

Standardisation

gcbok.org

The GitCover Body of Knowledge (GCBoK) standardises the proper use of Git repositories for compliance — traceable, multilingual and freely accessible. It is the shared language of all participants.

Tools · Compliance-as-Code

gcc.gitcover.org

GitCover Commons gUG maintains the open tools and the normative core: GCPN (evidence chains), GCEP (exchange protocol), GCSYNC, OSCAL and OPA/Rego mechanics. All versioned, testable, Git-native.

Practice · bridge

gitcover.de

This site: where businesses and public bodies meet the service-provider craft — with self-check, directory, qualification path and knowledge.

Who does what

Clear responsibilities — so you can focus on your business.

Not an opaque network, but clearly separated roles: every task has exactly one owner. That way you always know who is responsible — and never have to deal with structure.

Rules

The open rule set

Awareness, standardisation and open tools — free to use, independent of any order.

Community & OSS
Build

Tools & development

The Git-native tools and adaptations for your operation — maintained and advanced.

Engineering
Deliver

Adoption & operation

Your local contact for advice, rollout and ongoing operation — with clear, contractually defined services.

Projects & services
Protect

Foundation & sovereignty

Own infrastructure and long-lived protection so evidence stays available, independent and permanent.

Infrastructure & IP

The division of labour in one sentence: rules are open, tools are free, adoption and operation are the craft's job, the foundation stays in your own hands.

Always current

Daily AI news — what actually affects you.

AI, regulation and tools change almost daily. We filter out what really matters for compliance, evidence and operations — and translate the news value into concrete consequences. Stay current without following every channel yourself.

Signal over noise

What is new — and why it matters

New legal acts, standards and tools, classified by impact on your daily work: act, watch or ignore.

State of the art

Tools that move with it

New developments flow into the open tools — versioned, testable, without forcing you to migrate.

Context

Knowledge that lasts

Short articles with GCBoK reference: understandable, verifiable and clearly cross-referenced to the standardisation.

Git-native as a method

Why Git and not a database abroad?

Historisation as proof

Every change is a commit with timestamp, author and hash. The history itself is the evidence — not a log next to the matter.

Open format, open tools

Readable with standard tools, permanently. No proprietary format that fails to outlive the retention period.

Compliance-as-Code

Rules as versioned policies (OPA/Rego), catalogues as OSCAL — verifiable and testable in CI/CD instead of prose in a manual.