Open Source · OpenComp

OpenComp

An open-source compliance assessment portal for SOC 2, ISO 27001, and a growing list of other frameworks — evidence collection, policy management, and control implementation. Self-host it, or get it included with a Gideon paid plan.

What it does

Keep compliance work moving

Automate the evidence work

Collect and organize the evidence auditors ask for instead of chasing screenshots and spreadsheets manually.

  • Track controls against the frameworks you are pursuing
  • Keep evidence current instead of scrambling before an audit

Manage policy in one place

Write, version, and publish the policies your framework requires without a separate document tool.

  • Use policy templates mapped to common frameworks
  • Give your team and auditors a single source of truth

Track control implementation

See which controls are in place, which are in progress, and which still need owners.

  • Assign and track control ownership
  • See audit readiness clearly at any point

Frameworks supported

Start with the standards your team needs

SOC 2ISO 27001HIPAAGDPRCCPANISTPCI DSSNIS 2HITRUST

More added regularly.

Fully open source

Audit, modify, and self-host the entire product

OpenComp is fully open source under AGPLv3. Every product feature is available in the public repository, so you can self-host it, audit the complete codebase, and modify it freely.

Get started

Choose self-hosted or Gideon-managed

Run it yourself

Clone the repository and start OpenComp with Docker Compose. Full setup, environment variables, and cloud and authentication configuration are in the self-hosting guide.

git clone https://github.com/gideon-security/opencomp.git
cd opencomp
docker-compose up -d --build
Read the self-hosting guide

Included with paid plans

The hosted version of OpenComp is included with Starter Plus, Business, and Enterprise. It is not included on the free Starter plan for up to 10 users and is not available as a standalone purchase.

See pricing

Built with

A familiar, inspectable stack

Next.jsPrismaPostgreSQLTailwind CSS

Community

Shape OpenComp in the open

OpenComp is built in the open and shaped by feedback. Report bugs or request features in GitHub Issues, and use the contributing guide to propose code changes.

OpenComp

Self-host or use Gideon's hosted version

Review the source on GitHub, then choose the operating model that fits your team.