Skip to content
Change the repository type filter

All

    Repositories list

    • Daily Findings is a desktop GRC learning app with guided sessions, quizzes, progress tracking, and curated GRC news.
      TypeScript
      11101Updated Apr 18, 2026Apr 18, 2026
    • Open-source GRC platform for modern security teams. Manage compliance (SOC 2, ISO 27001, HIPAA), risk registers, vendor assessments, and audits—all in one place…
      TypeScript
      Other
      3411200Updated Apr 18, 2026Apr 18, 2026
    • HCL
      MIT License
      11413Updated Apr 17, 2026Apr 17, 2026
    • cheatsheet

      Public
      The GRC Engineering Cheat Sheet — cheatsheet.grc.engineering
      HTML
      0000Updated Apr 14, 2026Apr 14, 2026
    • HTML
      658123Updated Apr 12, 2026Apr 12, 2026
    • cvm

      Public
      Credential Vending Machine — an STS broker that vends short-lived, scoped API credentials for platforms lacking native OIDC federation
      Rust
      0005Updated Apr 4, 2026Apr 4, 2026
    • Go
      1301Updated Apr 2, 2026Apr 2, 2026
    • risk-register-templates

      Public
      Scripts for creating opinionated Risk Register structures in commonly used work management tools (Jira, Asana, etc.)
      0201Updated Apr 2, 2026Apr 2, 2026
    • Interactive web-based cybersecurity and privacy training modules with SCORM support. Deployable as standalone HTML or LMS-integrated content.
      HTML
      9501Updated Apr 2, 2026Apr 2, 2026
    • Open source security policies and standards templates and GitOps workflows
      The Unlicense
      0401Updated Apr 2, 2026Apr 2, 2026
    • OCEAN

      Public
      Rust
      11294Updated Apr 2, 2026Apr 2, 2026
    • A fully customisable and personalised lab builder which is tailored to your context, experience, current technical literacy, objectives and time allocation. You…
      MIT License
      41701Updated Apr 2, 2026Apr 2, 2026
    • gnophish

      Public
      GnoPhish (NOH-phish) is a tool meant to raise awareness among people at an organization about phishing features and techniques so they can better spot, avoid, a…
      The Unlicense
      1201Updated Apr 2, 2026Apr 2, 2026
    • conduit

      Public
      Framework-agnostic evidence exchange protocol for third-party risk management. Inspired by STIX/TAXII and leveraging ASSURE controls for the Proof of Concept.
      Python
      0502Updated Apr 2, 2026Apr 2, 2026
    • An open source repository of community-maintained information security controls. Contains controls mapped to other frameworks as well as community best practice…
      The Unlicense
      0961Updated Apr 2, 2026Apr 2, 2026
    • assets

      Public
      Used for tracking assets in use for GRC Engineering's internet presence and other things
      0001Updated Apr 2, 2026Apr 2, 2026
    • Everyone is invited!
      Rust
      0102Updated Mar 29, 2026Mar 29, 2026
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.