Open Source Thoropass Alternatives
A curated collection of the 1 best open source alternatives to Thoropass.
The best open source alternative to Thoropass is Probo. If that doesn't suit you, we've compiled a ranked list of other open source Thoropass alternatives to help you find a suitable replacement.
Thoropass alternatives are mainly Compliance & Risk Management. Browse these if you want a narrower list of alternatives or looking for a specific functionality of Thoropass.
Self-hostable GRC platform covering risk, controls, vendor risk, data privacy and audits, aimed at engineering and security teams.

Compliance work usually lives in spreadsheets and a vendor portal nobody wants to open. Probo is a self-hostable governance, risk and compliance platform built for engineering and security teams, covering the lifecycle from risk identification through control tracking, vendor risk, data privacy, access reviews and audit programs.
The backend is Go on PostgreSQL, the frontend is React with TypeScript, Relay and Tailwind CSS, and observability runs on OpenTelemetry with Grafana, Prometheus, Loki and Tempo. Every entity is reachable through more than one interface, which is what makes the automation possible.
Access to that data model comes in several shapes.
- Web console: the primary surface for day-to-day GRC work.
- prb CLI: over 44 command groups for scripting, automation and CI/CD integration.
- MCP API: more than 270 tools let any MCP-compatible agent read and write compliance data, draft policies and generate evidence packs.
- GraphQL API: the same model exposed for custom integrations, with an n8n community node for no-code workflows.
- Audit trail: policy-based RBAC, immutable logs and electronic sign-off with approval quorums.
Domain coverage includes a risk register with inherent and residual scoring, a control library with maturity levels and Statement of Applicability export, DPIAs and transfer impact assessments, vendor inventory with DPA and BAA tracking, and a public compliance portal on a custom domain. Running it locally needs Go, Node.js, Docker and mkcert. Probo is MIT licensed and Docker is the supported way to run it on your own infrastructure.