Your source code stays in the instance. So does everything that reads it.
Reign Ops runs GitHub Enterprise, GitLab Self-Managed and Bitbucket Data Center as a single-tenant dedicated instance. The code, the secrets and the pipeline artifacts stay yours, and every AI coding tool that touches them passes a boundary you control.
A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both available today; Google Cloud is planned for 2027. Air-gapped and sovereign are in development.
Where the code lives matters more than the feature set.
Every source-control platform in this market has the features. The question underneath the evaluation is a different one, and it is answered by the deployment model rather than the product.
A breach at that layer is not a breach of a tool. Hardening the substrate stopped being an engineering decision when it became the operating context of the institution.
Each one is a distinct identity that has to be accounted for.
Hardening inside the boundary is the only version of this that survives a bad quarter at a vendor you do not control.
That is the tradeoff this page exists to remove. You keep the control of a self-managed instance; iTmethods carries the operations.
iTmethods does not custody customer code, secrets or pipeline artifacts. The substrate is operated by iTmethods. The artifacts are owned by the customer.
Three supported platforms. One operating model.
The operating posture does not change with the platform. What changes is what your engineers already know and what your licenses already cover.
GitHub Enterprise
GitHub Enterprise Server, operated as a single-tenant dedicated instance inside your authorization boundary. Actions runners isolated per environment with short-lived OIDC tokens, and branch protection applied as policy-as-code rather than as settings somebody remembered to tick.
GitLab Self-Managed
GitLab Ultimate or Premium, operated as a single-tenant dedicated instance against your own identity provider. Runners isolated per environment, CI/CD variables under the same identity boundary as the platform, and branch and push controls as policy-as-code.
Bitbucket Data Center
Bitbucket Data Center, operated as a single-tenant dedicated instance alongside the rest of an Atlassian estate under one operating model. Atlassian preserved Bitbucket Data Center in its published Data Center plans while other products moved.
One operating model across all three: your identity provider at the platform edge, runners isolated per environment, the audit log streamed to your SIEM, and patching on a cadence matched to upstream releases. Running something else? Tell us what it is →
Policy as code, not manual setup.
These are applied at deployment rather than negotiated afterwards, and each one is configuration under version control rather than a setting somebody remembered to tick.
Your identity provider at the platform edge, on the protocol you already run. Group and sub-group inheritance enforced rather than reimplemented.
Short-lived tokens, no long-lived registration secrets, and no shared execution surface between environments that are not supposed to see each other.
Streamed to the system your security team already watches, rather than held in a console they would have to be given a seat in.
Substrate, runner fleet and dependencies, on a cadence matched to upstream releases. Version currency is our work rather than something waiting for a quiet week.
iTmethods makes no compliance, certification or accreditation claim under any framework. What each framework asks for, and the limits on what any supplier can tell you about your own position, is set out on regulatory alignment.
Your engineers already adopted them. The question is what they can reach.
Copilot, Cursor, Claude Code, GitLab Duo, Atlassian Intelligence and whatever ships next all read and write the same substrate. Reign Gateway governs them at the call layer, which is the one place a policy can apply to all of them at once, whoever built them.
The same substrate, with work arriving in it.
Reign Ops is sold and operated on its own terms, and a customer who never adopts Reign Factory loses nothing on this page. But the two were designed to meet here, and this is where that is most concrete.
The Factory relationship is stated in the present tense here because the merge request lands in the platform this page is about. That is the test the band has to pass on any Reign Ops page, and it is the only thing that earns the present tense.
What we run, what you run.
Written down before anything is deployed, so the boundary is a document rather than a discovery.
| Who | What they hold | Examples |
|---|---|---|
| Reign Ops, automated | Decisions closed inside the substrate without human intervention: the runtime, the identity boundary, the network policy and the audit logging. | Operate the substrate inside your authorization boundary. Enforce your identity provider at the platform edge. Isolate runners per environment. Stream audit logs to your SIEM. Apply hardening as policy-as-code. Patch on an upstream-matched cadence. |
| Customer authored | Decisions you own under the shared-responsibility model. You are the author here rather than the approver. | Your repositories and intellectual property. Code review policy, branch protection and push policy. The catalog of AI coding tools the organization sanctions. Which evaluators apply to which population. |
| Operating partner engagement | The work that needs a named engineer rather than a runbook, done with your team rather than to it. | Migration scoping and phased cut-over. Authoring the first set of evaluators. The periodic hardening review. The decisions that change the design rather than the configuration. |
The questions that arrive every time.
Where does the code actually live?
Does moving platform mean re-platforming the pipelines?
What happens to the AI coding tools our engineers already use?
Which deployment shapes can we have?
Can we see the controls before we commit to anything?
Tell us where your source control runs today.
Which platform, roughly which version, and what is forcing the question. We will come back with what we would operate, what stays with your team, and what we would leave alone.