- Stars
- 15,142
- License
- GPL-3.0
- Last commit
- 1 month ago
Best Compliance Automation & GRC Tools
Explore leading tools in the Compliance Automation & GRC category, including open-source options and SaaS products. Compare features, use cases, and find the best fit for your workflow.
8 open-source projects · 10+ SaaS products
Top open-source Compliance Automation & GRC
These projects are active, self-hostable choices for knowledge management teams evaluating alternatives to SaaS tools.

Prowler
Unified cloud security platform for automated compliance across providers
- Stars
- 12,703
- License
- Apache-2.0
- Last commit
- 21 hours ago
- Stars
- 7,652
- License
- AGPL-3.0
- Last commit
- 1 month ago

CISO Assistant
Unified GRC platform decoupling compliance from cybersecurity controls
- Stars
- 3,514
- License
- —
- Last commit
- 16 hours ago

Comply
Automate SOC2 compliance with markdown policies and ticketing integration
- Stars
- 1,461
- License
- Apache-2.0
- Last commit
- 3 years ago

Comp AI
AI‑powered platform that automates compliance for SOC 2, ISO 27001, HIPAA, GDPR
- Stars
- 1,328
- License
- AGPL-3.0
- Last commit
- 13 hours ago
Comp AI accelerates compliance by automating evidence collection, policy management, and control implementation for SOC 2, ISO 27001, HIPAA, and GDPR, while keeping your data under your own infrastructure.
Popular SaaS Platforms to Replace
Understand the commercial incumbents teams migrate from and how many open-source alternatives exist for each product.
Delve
AI-native compliance automation with agent-based evidence collection
Drata
Automated security compliance for SOC 2, ISO 27001, and more
Oneleet
Unified security & compliance platform with pentesting and continuous monitoring
OneTrust
Unified trust platform for privacy, consent, data governance, and compliance automation.
Scrut.io
Compliance automation for SOC 2/ISO 27001 with continuous control monitoring
Secureframe
Automated SOC 2 and ISO 27001 compliance platform
Delve streamlines SOC 2, ISO 27001, HIPAA and more by using AI agents to auto-collect evidence, generate and map controls/policies, track tasks, and run continuous monitoring. It includes risk and vendor management, auditor collaboration, and dashboards to go audit-ready faster.
Explore related categories
Browse neighbouring categories in Security to widen your evaluation.
- Application Security Testing (SAST/DAST/SCA)Static/dynamic analysis and dependency (SCA) scanning for application vulnerabilities.
- Container SecurityContainer image scanning and Kubernetes security tools for supply chain protection.
- Data Discovery & ClassificationSensitive data discovery, classification and privacy compliance across data stores.
- Identity & SSOIdentity and single sign-on (SSO) servers for authentication and user management.
- Secrets ManagementVaults and key management systems for secure storage of credentials and secrets.
- SIEM & Threat DetectionSecurity information and event management platforms for threat monitoring and analysis.

