VerifyWise is a free, open source ai security & privacy project written in TypeScript and released under a custom open-source licence. It has 352 GitHub stars, 116 forks and 59 open issues, and was last pushed 3 hours ago. On this registry it ranks #34 of 34 tracked projects in AI Security & Privacy, with 5 head-to-head comparisons available. It gained 2 stars over the last 6 tracked days.

What is VerifyWise?

VerifyWise is a source-available AI governance platform that helps businesses use AI safely and responsibly, aimed at compliance, risk, security, and audit teams that must satisfy frameworks such as the EU AI Act, ISO 42001, NIST AI RMF, or ISO 27001 and want that work hosted on their own infrastructure.

What it is

VerifyWise is an AI governance platform written in TypeScript and published by Bluewave Labs under a source-available licence. It gives an organisation one place to inventory AI models, register AI use cases and their risks, manage policies from templates, track AI vendors and vendor risks, log AI incidents, and produce reports. It also includes LLM Evals and automations, with a dashboard split into an executive view and an operating view so leadership and day-to-day operators see different cuts of the same data. The project markets itself around a single idea: compliance and AI management without giving up control over where the data lives.

The concrete problem it solves is the manual work of assembling AI governance evidence. Instead of maintaining audits, risk registers, and assessment answers in spreadsheets across several teams, VerifyWise centralises them and generates AI answers for compliance and assessment questions, which shortens audits. It replaces the ad hoc mix of GRC spreadsheets and disconnected documents that organisations otherwise build when a framework such as the EU AI Act or ISO 42001 begins to apply to them.

Key capabilities

  • On-premises or private cloud hosting, with deployment via Docker and Kubernetes and support for platforms such as render.com.
  • Support for four frameworks in one system: EU AI Act, ISO 42001, NIST AI RMF, and ISO 27001.
  • AI-generated answers for compliance and assessment questions, intended to shorten audit cycles.
  • AI model inventory plus separate views for AI model risks and AI use case risks.
  • AI policy manager with policy templates for drafting and maintaining governance policies.
  • AI vendor and vendor risk tracking alongside AI incident management.
  • User registration, authentication, and role-based access control, with an AI Trust Center and reporting module.

Who uses it and how

  • Compliance and GRC teams mapping their AI estate against the EU AI Act, using the EU AI Act project view to organise that work.
  • Risk and security functions registering AI use cases and models, then tracking the risks attached to each.
  • Organisations required to keep AI data inside their own perimeter, using the on-premises or private cloud deployment path rather than a vendor-hosted service.
  • Audit and assurance teams using the reporting module and AI-generated compliance answers as the evidence base for assessments.
  • Platform teams deploying the stack to Docker, Kubernetes, or a PaaS such as render.com with RBAC configured per role.

Getting started

The README describes deployment through Docker and Kubernetes, optionally on render.com or a similar platform, with a hosted demo available at app.verifywise.ai. Documentation lives at verifywise.ai/user-guide, and the project runs a Discord channel for questions.

How it compares

No comparable products are named in the material provided for this entry, so VerifyWise stands alone in this registry on that basis. Comparisons should therefore be drawn from its own licensing and hosting model rather than from any set of paid alternatives described here.

When to use it — and when not to

Choose it if you need an AI governance system you can host yourself and you are willing to operate the deployment, its datastore, and its authentication stack, since the README does not spell out the supporting infrastructure you will have to run. The licensing needs checking before adoption: the repository metadata reports the licence as NOASSERTION while the README states BSL 1.1 with dual licensing available for enterprises, and the feature list in the README is truncated, so some advertised capability is described only in the linked user guide. Teams with 59 open issues to weigh and no appetite for self-hosting, or those wanting a conventional open-source licence, should look elsewhere.

project readme (upstream, from github) — read inline

Ask DeepWiki

github

VerifyWise is a source available AI governance platform designed to help businesses use the power of AI safely and responsibly. Our platform ensures compliance and robust AI management without compromising on security.

We are democratizing AI best practices with a solution that can be hosted on-premises, giving you complete control over your AI governance.

Quick links

Screenshots

The main dashboard LLM Evals
image image
EU AI Act project view AI Use case risks
image image
AI Risk management AI Model inventory
image image
AI Model risks AI Policy manager and policy templates
image image
AI vendors and vendor risks AI Incident management (with filter example)
image image
AI Trust Center Automations
image image
Reporting
image

Features

VerifyWise platform

  • Option to host the application on-premises or in a private cloud
  • Source available license (BSL 1.1). Dual licensing is also available for enterprises
  • Faster audits using AI-generated answers for compliance and assessment questions
  • Full access to the source code for transparency, security audits, and customization
  • Docker and Kubernetes deployment (also deployable on render.com and similar platforms)
  • User registration, authentication, and role-based access control (RBAC) support
  • Major features:
    • Support for EU AI Act, ISO 42001, NIST AI RMF and ISO 27001
    • Dashboard: executive view & operating view
    • Vendors & vendor risks
    • AI use cases and risks
    • Global tasks with timeline view
    • Complete LLM Evals and LLM Arena
    • Evidence center with folder structure
    • AI trust center for public view
    • AI literacy training registery
    • AI Advisor, AI-powered chat interface providing governance recommendations
    • AI Detection Module, which scans code repositories to identify AI-generated content.
    • Shadow AI detection and risk management
    • AI agent discovery
    • Activity history for each entity
    • Integration with MIT and IBM AI risk repository
    • Model inventory and model risks that keeps a list of models used and risks
    • Policy manager to create and manage internal company AI policies
    • Risk and control mappings for EU AI Act, ISO 42001, NIST AI RMF and ISO 27001
    • CE Marking registry
    • Dataset registry
    • Desktop notifications
    • Approval workflows & approval requests
    • Detailed reports with PDF and DOCX export
    • Event logs (audits) for enterprise organizations
    • AI incident management
    • Plugins support with more than 15+ plugins (and counting)
    • Automations (when an entity changes, do this, or send period reports, or send webhooks)
    • Google OAuth2 and Entra ID (enterprise edition) support for authentication

Installation

The VerifyWise application has two components: a frontend built

readme truncated — read the full docs on github

Frequently asked questions

Is VerifyWise free to use?

VerifyWise is open source. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does VerifyWise do?

AI governance made simple, secure, and compliant

What is VerifyWise written in?

VerifyWise is primarily written in TypeScript. Its source is publicly available at https://github.com/bluewave-labs/verifywise, and it has 352 GitHub stars.