Best Compliance Automation & GRC Tools

Explore leading tools in the Compliance Automation & GRC category, including open-source options and SaaS products. Compare features, use cases, and find the best fit for your workflow.

8 open-source projects · 10+ SaaS products

Top open-source Compliance Automation & GRC

These projects are active, self-hostable choices for knowledge management teams evaluating alternatives to SaaS tools.

View all 8 open-source options
Lynis logo

Lynis

In-depth security auditing and hardening for UNIX-based systems

Stars
15,142
License
GPL-3.0
Last commit
1 month ago
ShellActive
Prowler logo

Prowler

Unified cloud security platform for automated compliance across providers

Stars
12,718
License
Apache-2.0
Last commit
2 hours ago
PythonActive
Steampipe logo

Steampipe

Query any API in real‑time with SQL, no ETL required

Stars
7,653
License
AGPL-3.0
Last commit
1 month ago
GoActive
CISO Assistant logo

CISO Assistant

Unified GRC platform decoupling compliance from cybersecurity controls

Stars
3,520
License
Last commit
3 hours ago
PythonActive
Comply logo

Comply

Automate SOC2 compliance with markdown policies and ticketing integration

Stars
1,461
License
Apache-2.0
Last commit
3 years ago
GoDormant
Comp AI logo

Comp AI

AI‑powered platform that automates compliance for SOC 2, ISO 27001, HIPAA, GDPR

Stars
1,328
License
AGPL-3.0
Last commit
2 hours ago
TypeScriptActive
Most starred project
15,142★

In-depth security auditing and hardening for UNIX-based systems

Recently updated
2 hours ago

Comp AI accelerates compliance by automating evidence collection, policy management, and control implementation for SOC 2, ISO 27001, HIPAA, and GDPR, while keeping your data under your own infrastructure.

Dominant language
Go • 3 projects

Expect a strong Go presence among maintained projects.

Popular SaaS Platforms to Replace

Understand the commercial incumbents teams migrate from and how many open-source alternatives exist for each product.

View all 10+ SaaS options
Delve logo

Delve

AI-native compliance automation with agent-based evidence collection

Compliance Automation & GRC
Alternatives tracked
7 alternatives
Drata logo

Drata

Automated security compliance for SOC 2, ISO 27001, and more

Compliance Automation & GRC
Alternatives tracked
7 alternatives
Oneleet logo

Oneleet

Unified security & compliance platform with pentesting and continuous monitoring

Compliance Automation & GRC
Alternatives tracked
7 alternatives
OneTrust logo

OneTrust

Unified trust platform for privacy, consent, data governance, and compliance automation.

Compliance Automation & GRCData Discovery & Classification
Alternatives tracked
5 alternatives
Scrut.io logo

Scrut.io

Compliance automation for SOC 2/ISO 27001 with continuous control monitoring

Compliance Automation & GRC
Alternatives tracked
7 alternatives
Secureframe logo

Secureframe

Automated SOC 2 and ISO 27001 compliance platform

Compliance Automation & GRC
Alternatives tracked
7 alternatives
Most compared product
7 open-source alternatives

Delve streamlines SOC 2, ISO 27001, HIPAA and more by using AI agents to auto-collect evidence, generate and map controls/policies, track tasks, and run continuous monitoring. It includes risk and vendor management, auditor collaboration, and dashboards to go audit-ready faster.

Leading hosted platforms

Frequently replaced when teams want private deployments and lower TCO.

Explore related categories

Browse neighbouring categories in Security to widen your evaluation.