GRC review on Origin pull requests.
The same GRC review, on Origin-hosted pull requests. Same findings, same free public-repo rule, same claim-to-trial. GitHub-synced copies stay on the GitHub App.
Cursor Origin launched as a git host on 17 August 2026. heyGRC is the same PR compliance reviewer you already run on GitHub, pointed at Origin-hosted repositories.
Origin apps cannot see repositories that Origin only mirrors in from GitHub. If GitHub is still the source of truth, keep the GitHub App. If the repository lives on Origin, install heyGRC there.
Install-via-URL, not a first-party tile
Origin's Apps tab currently lists Vercel, Depot, and Buildkite. heyGRC installs from a URL, the same way a GitHub App install link works. You pick all repositories or a selected set. Reviews run install-first: no console account required for the first reviews.
Findings land as an Origin review body plus a heyGRC check. Origin's partner API does not support line-anchored comments yet, so the summary is the source of truth. Public repos stay free; private repos use the same 25/month free cap and claim-only trial.
Control-relevant changes, named in the review.
A few of the control-relevant changes heyGRC is built to flag, each cited to the clause it touches.
An IAM role widens to a wildcard
SOC 2 CC6.1A privileged-action audit log is removed
ISO 27001:2022 A.8.15A new email or phone column lands with no retention plan
GDPR Art. 5(1)(e)
heyGRC flags control-relevant changes and cites the clause so the issue can be handled in the pull request. It does not certify you, run your audit, or replace your own judgment.