- Stars
- 14,917
- License
- GPL-3.0
- Last commit
- 10 days ago
Best Compliance Automation & GRC Tools
Explore leading tools in the Compliance Automation & GRC category, including open-source options and SaaS products. Compare features, use cases, and find the best fit for your workflow.
8 open-source projects · 10+ SaaS products
Top open-source Compliance Automation & GRC
These projects are active, self-hostable choices for knowledge management teams evaluating alternatives to SaaS tools.

Prowler
Unified cloud security platform for automated compliance across providers
- Stars
- 12,398
- License
- Apache-2.0
- Last commit
- 3 days ago
- Stars
- 7,607
- License
- AGPL-3.0
- Last commit
- 12 days ago

CISO Assistant
Unified GRC platform decoupling compliance from cybersecurity controls
- Stars
- 3,385
- License
- Unknown
- Last commit
- 3 days ago

Comply
Automate SOC2 compliance with markdown policies and ticketing integration
- Stars
- 1,446
- License
- Apache-2.0
- Last commit
- 3 years ago

Comp AI
AI‑powered platform that automates compliance for SOC 2, ISO 27001, HIPAA, GDPR
- Stars
- 1,257
- License
- AGPL-3.0
- Last commit
- 3 days ago
Prowler automates security audits and continuous compliance for AWS, Azure, GCP, Kubernetes and more, offering hundreds of built‑in checks, customizable frameworks, and a web UI for real‑time monitoring.
Popular SaaS Platforms to Replace
Understand the commercial incumbents teams migrate from and how many open-source alternatives exist for each product.
Delve
AI-native compliance automation with agent-based evidence collection
Drata
Automated security compliance for SOC 2, ISO 27001, and more
Oneleet
Unified security & compliance platform with pentesting and continuous monitoring
OneTrust
Unified trust platform for privacy, consent, data governance, and compliance automation.
Scrut.io
Compliance automation for SOC 2/ISO 27001 with continuous control monitoring
Secureframe
Automated SOC 2 and ISO 27001 compliance platform
Delve streamlines SOC 2, ISO 27001, HIPAA and more by using AI agents to auto-collect evidence, generate and map controls/policies, track tasks, and run continuous monitoring. It includes risk and vendor management, auditor collaboration, and dashboards to go audit-ready faster.
Explore related categories
Browse neighbouring categories in Security to widen your evaluation.
- Application Security Testing (SAST/DAST/SCA)Static/dynamic analysis and dependency (SCA) scanning for application vulnerabilities.
- Container SecurityContainer image scanning and Kubernetes security tools for supply chain protection.
- Data Discovery & ClassificationSensitive data discovery, classification and privacy compliance across data stores.
- Identity & SSOIdentity and single sign-on (SSO) servers for authentication and user management.
- Secrets ManagementVaults and key management systems for secure storage of credentials and secrets.
- SIEM & Threat DetectionSecurity information and event management platforms for threat monitoring and analysis.

