#compliance (30 Repositories)
Ranked open-source repositories tagged with #compliance, scored by pull request acceptance likelihood and maintainer engagement velocity.
62.6%
50.7h
30 repositories tagged #compliance
open-policy-agent/opa-envoy-plugin
A plugin to enforce OPA policies with Envoy
anchore/grant
A license scanner for container images and filesystems.
verifywise-ai/verifywise
Complete AI governance and LLM Evals platform with support for EU AI Act, ISO 42001, NIST AI RMF and 20+ more AI frameworks and regulations. Join our Discord channel: https://discord.com/invite/d3k3E4uEpR
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Cogeto/cogeto
Verified institutional memory for your documents: reads document sets, verifies every fact against its source, reports contradictions between documents, and produces a signed findings report. EU hosted, self hosted, or fully offline. AGPLv3.
WhitzardAgent/AgentGuard
AgentGuard: Zero-Trust Security Foundation for AI Agents
zeweihan/aiworkdeck
AI-native IDE workspace for legal and document-heavy workflows: files, agents, plugins, WPS editing, OCR, evidence chains. VS Code for lawyers.
mondoohq/cnspec
An open source, cloud-native security to protect everything from build to runtime
Normation/rudder
Rudder is a configuration and security automation platform. Manage your Cloud, hybrid or on-premises infrastructure in a simple, scalable and dynamic way.
wazuh/wazuh-docker
Wazuh - Docker containers
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
wazuh/wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
tractorjuice/arc-kit
The Enterprise Architecture Governance Harness — strategy, architecture, delivery, and assurance using AI coding assistants
getprobo/probo
Open source solutions for SOC2, GDPR, and ISO27001
ComplianceAsCode/content
Security automation content in SCAP, Bash, Ansible, and other formats
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
open-policy-agent/opa
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
inspec/inspec
InSpec: Auditing and Testing Framework
StackGuardian/tirith
Plugin IaC Governance for any pipeline, running anywhere. Evaluate plans with Tirith, protect sensitive values, enforce centralised governance, and surface actionable results before infrastructure changes are applied.
project-copacetic/copacetic
🧵 CLI tool for directly patching container images!
kyverno/kyverno
Unified Policy as Code
CISOfy/lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
risuorg/risu
Automation Troubleshooting Framework to validate and report configuration, software installed, etc with bash, python, and your language of choice.
hashicorp/copywrite
Automate copyright headers and license files at scale
todogroup/todogroup.org
Official TODO Website that contains TODO Guides, OSPO use cases and more resources to advance in the OSPO journey
gensecaihq/Wazuh-MCP-Server
Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PCI DSS, GDPR, HIPAA, NIST CSF, ISO 27001) and active response. Connect Claude or any LLM to your SOC. OAuth 2.1, RBAC, multi-cluster, air-gap ready.
Ali-Marandi/finsight-pro
AI-Powered Financial Analysis Desktop App — 7 Engines, 17+ Ratios, Bankruptcy Prediction, TSETMC Live, 100% Offline