From Code to Compliance, Intelligently. An open source compliance runtime that pulls policies from OCI registries, dispatches scans to evaluator plugins, and produces control-mapped evidence in OSCAL, SARIF, and Markdown.
Compliance assessment at scale breaks down
Swap assessment tools without rewriting compliance content. OpenSCAP, OPA, and AMPEL run as provider plugins behind a common interface.
Scan output maps findings to the specific controls being assessed. Produce OSCAL assessment-results, SARIF, or Markdown reports.
Policies are packaged as OCI artifacts and distributed through standard container registries. The same infrastructure that moves images moves compliance content.
Assess against NIST 800-53, CIS Benchmarks, STIG, HIPAA, and custom OPA policies from a single tool.
Built on NIST's Open Security Controls Assessment Language. Compliance data is structured and machine-readable from the start.
Apache 2.0 licensed. The compliance content, assessment logic, and runtime are all open source.
A suite of tools designed to streamline compliance workflows from code to audit.
Platform engineers, compliance engineers, and DevSecOps teams who need machine-readable, control-mapped compliance evidence -- whether for internal audit, continuous monitoring, or regulatory frameworks like FedRAMP and FISMA.
Pull policies from OCI registries. Scan with multiple evaluators. Produce control-mapped evidence.
Get Started