Best Governance, Risk & Compliance tools by public signals

These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.

Use Case Rankings

Ordered by ToolVitals score, then health, shipping, confidence, GitHub stars, and name.

#ToolHealthShippingOpennessStarsScoreStatus
01Probo
Open source solutions for SOC 2, GDPR, and ISO27001.
9798OSI-approved OSS1.4k97Active
02The Open Lane
Open source compliance automation for SOC 2, GDPR, ISO27001, NIST 800-53, and more
9596OSI-approved OSS30395Active
03Claude GRC Engineering
Open-source GRC toolkit with Claude Code plugins for evidence collection and gap reports.
9187OSI-approved OSS39889Active
04Origin CLI
CLI for AI code attribution and governance.
8986OSI-approved OSS1288Active
05Comp AI
AI Native platform to get companies compliant - Vanta & Drata Alternative
8472OSI-approved OSS1.9k79Active
06OpenArchiver
An open-source platform for legally compliant email archiving.
7271OSI-approved OSS2.3k72Warning
07Torqa
Workflow validation and trust/risk enforcement tool.
4634OSI-approved OSS041Critical
08Ballerine
Open-source infrastructure and data orchestration platform for risk decisioning.
340OSI-approved OSS2.4k21Critical
09EUActAudit
Open-source AI governance and auditing platform for identifying compliance gaps in AI systems.
170OSI-approved OSS010Critical

Not Scored

Tracked for context, but excluded from rankings because comparable open/source-visible evidence is unavailable.