Security & Compliance
Governance, Risk & Compliance
Tools for GRC workflows including evidence collection, control mapping, compliance auditing, risk management, and gap analysis.
Best Governance, Risk & Compliance tools by public signals
These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.
Use Case Rankings
Ordered by ToolVitals score, health, shipping, confidence, and then adoption as a tie-breaker.
| # | Tool | Health | Shipping | Openness | Stars | Score | Status |
|---|---|---|---|---|---|---|---|
| 01 | CISO Assistant Community Open-source GRC platform for risk management, compliance, audit, TPRM, privacy, and reporting. | 98 | 100 | License unknown | 4.1k | 99 | Active |
| 02 | The Open Lane Open source compliance automation for SOC 2, GDPR, ISO27001, NIST 800-53, and more | 93 | 98 | OSI-approved OSS | 258 | 96 | Active |
| 03 | Comp AI AI Native platform to get companies compliant - Vanta & Drata Alternative | 92 | 95 | OSI-approved OSS | 1.6k | 95 | Active |
| 04 | VerifyWise AI governance and evaluation platform for policy and compliance frameworks. | 91 | 93 | License unknown | 300 | 94 | Active |
| 05 | Probo Open source solutions for SOC 2, GDPR, and ISO27001. | 87 | 95 | OSI-approved OSS | 1.1k | 93 | Active |
| 06 | Claude GRC Engineering Open-source GRC toolkit with Claude Code plugins for evidence collection and gap reports. | 80 | 75 | OSI-approved OSS | 292 | 81 | Active |
| 07 | Origin CLI CLI for AI code attribution and governance. | 66 | 72 | License unknown | 8 | 75 | Warning |
| 08 | Torqa Workflow validation and trust/risk enforcement tool. | 49 | 51 | OSI-approved OSS | 0 | 59 | Warning |
| 09 | EUActAudit Open-source AI governance and auditing platform for identifying compliance gaps in AI systems. | 62 | 11 | OSI-approved OSS | 0 | 52 | Warning |
| 10 | RAI Ops Open source platform for responsible AI operations with red teaming, control monitoring, and policy management. | 41 | 11 | License unknown | 0 | 41 | Critical |
| 11 | Admyral Continuous control monitoring platform for custom controls. | 24 | 0 | OSI-approved OSS | 340 | 30 | Critical |