Open Source Compliance Automation

Cloud Native Compliance. Reimagined.

From Code to Compliance, Intelligently. An open source compliance runtime that pulls policies from OCI registries, dispatches scans to evaluator plugins, and produces control-mapped evidence in OSCAL, SARIF, and Markdown.

Engineering-First Compliance

Compliance assessment at scale breaks down

  • Requirements lose meaning as they cross team boundaries.
  • Verification logic is often locked to individual tools.
  • Evidence lands in different formats across different systems.
  • Fragmented evidence traceability back to requirements.

Evaluator Independence

Swap assessment tools without rewriting compliance content. OpenSCAP, OPA, and AMPEL run as provider plugins behind a common interface.

Control-Mapped Evidence

Scan output maps findings to the specific controls being assessed. Produce OSCAL assessment-results, SARIF, or Markdown reports.

OCI Distribution

Policies are packaged as OCI artifacts and distributed through standard container registries. The same infrastructure that moves images moves compliance content.

Multi-Framework Assessment

Assess against NIST 800-53, CIS Benchmarks, STIG, HIPAA, and custom OPA policies from a single tool.

OSCAL Native

Built on NIST's Open Security Controls Assessment Language. Compliance data is structured and machine-readable from the start.

Open Source

Apache 2.0 licensed. The compliance content, assessment logic, and runtime are all open source.

Our Projects

A suite of tools designed to streamline compliance workflows from code to audit.

Built for Compliance Engineers and Platform Teams

Platform engineers, compliance engineers, and DevSecOps teams who need machine-readable, control-mapped compliance evidence -- whether for internal audit, continuous monitoring, or regulatory frameworks like FedRAMP and FISMA.

Start building with ComplyTime today

Pull policies from OCI registries. Scan with multiple evaluators. Produce control-mapped evidence.

Get Started