Open source compliance projects
Every project in the registry tagged compliance, ranked by real GitHub adoption.
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentles
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by
Unified Policy as Code
Tfsec is now part of Trivy
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10
Open Source Cloud Native Application Protection Platform (CNAPP)
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-ti
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows
Open-source, self-hosted file-processing tool. Convert, compress, OCR, transcribe & run local AI across image, video, audio, PDF & documents, via UI, REST API &
HardeningKitty and Windows Hardening Settings
AI agents that transform merchant risk decisions at scale
Pre-submission compliance scanner for the Apple App Store and Google Play. Scans code, privacy manifests, Android manifests, and IPA/APK/AAB binaries against th
A suite of tools to automate software compliance checks.
Get audit-ready for SOC 2, ISO 27001, HIPAA, and GDPR
NIST Certified SCAP 1.2 toolkit
Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.
🧵 CLI tool for directly patching container images!
Secure Vault for Customer PII/PHI/PCI/KYC Records
Decision audit trail + persistent memory for AI trading agents. Outcome-weighted recall, tamper-evident SHA-256 chain with RFC 3161 anchoring, 20 MCP tools.
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. B
Real-time fraud detection and AML compliance engine
AI governance made simple, secure, and compliant
Related tags
Frequently asked questions
How many open source compliance projects are there?
This registry tracks 25 projects tagged compliance, with 115,077 GitHub stars between them. The most-adopted is lynis at 16,355 stars.
Are these compliance projects free to use?
Yes — 22 of the 25 carry an explicit open-source licence across 6 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which compliance project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these compliance projects still maintained?
23 of the 25 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.