Commit → merge request → who approved → deployed to production. Exportable, per project and date range.
SOX, ITGC, ISO 27001 and banking audits converge on one question: which change reached production, who approved it, and can you prove nobody edited the record afterwards? Screenshots of a Git UI do not answer it, and neither does a spreadsheet assembled by hand at audit time.
Your Git server knows what happened to the code; Jira knows what the business asked for. The evidence lives in the join — and that join is exactly what breaks when the connector cannot reach a self-hosted Git server. BastionTrail is push-based, so it works behind the firewall, and it records the join as it happens instead of reconstructing it later.
The connector is free; audit trail reports are the paid plan. Billed by Atlassian on your existing invoice — no new vendor to onboard through procurement. Security overview