Comp AI
Compliance platform that automates evidence collection, policy management and controls for teams pursuing SOC 2, ISO 27001, HIPAA or GDPR.
Open Source Alternative to:

Getting audit ready is mostly clerical work, and that is the work Comp AI takes over. It automates evidence collection, policy management and control implementation for SOC 2, ISO 27001, HIPAA and GDPR, while the data and the infrastructure holding it stay yours.
The codebase is a Bun monorepo built on Next.js, with Prisma over PostgreSQL, Trigger.dev running background jobs, Tailwind CSS in the interface and Upstash Redis behind the key value store. It splits into the main application, a portal and an API, with shared packages for database access, email templates, key value access and UI components that are published to npm.
Running a local instance is a fairly involved setup.
- Runtimes: Node.js 20 or newer, Bun 1.1.36 or newer and PostgreSQL 15 or newer.
- Database: a Docker container, then Prisma generate, push or migrate, and an optional seed.
- Background jobs: a Trigger.dev project id wired into the trigger configuration file.
- Authentication: Google OAuth credentials with redirect URIs for both the app and the portal.
- Email and cache: a Resend API key for mail and an Upstash Redis database for key value storage.
Deployment guides for Docker and Vercel are both listed as coming soon, so self-hosters are currently ahead of the documentation. The company describes the project as open core, with the core under AGPLv3 and a small enterprise directory under a commercial license, and it invites discussion about where that line should sit. A hosted version is sold for anyone who would rather not run it.
Stars
1,942Forks
409Last commit
1 month agoRepository age
2 yearsLicense
AGPL-3.0Version
3.111.1Repository
trycompai/comp
Auto-fetched from GitHub .
Open source alternatives similar to Comp AI:
Stars
Forks
Last commit
Stars
Forks
Last commit
Stars
Forks
Last commit