A favicon of Openlane

Openlane

Compliance automation platform that holds policies, controls, evidence and vendors in one system of record for SOC 2 and ISO 27001 programs.

Open Source Alternative to:

Screenshot of Openlane websiteVisit Openlane

Compliance programs usually live in a spreadsheet beside the systems they describe. Openlane is a platform meant to be the system of record instead, holding the people, systems and vendors in scope, the policies and controls that govern them, and the evidence that proves it.

This repository is the core server and orchestration services behind the hosted product, written in Go. The stack is assembled from open source pieces so an operator does not need a dozen subscriptions to run it, among them PostgreSQL, Redis, S3 compatible storage, ent, gqlgen and OpenFGA.

The platform is organized into areas that build on each other.

  • Compliance management: policies, controls, evidence and programs with approvals, comments and full history on every object.
  • Frameworks: importable control sets for SOC 2, ISO 27001 and NIST 800-53, where one control can satisfy several frameworks.
  • Registry: personnel, vendors and assets imported from a directory, a CRM, a CMDB or spreadsheets.
  • Exposure: domain scanning and vulnerability feeds from GitHub, AWS Security Hub and GCP Security Command Center, with remediation tracking.
  • Trust Center: a branded portal on your own domain publishing certifications, security documents and subprocessors.
  • Access control: granular RBAC, organization wide SSO, 2FA enforcement and auditor views, none of it behind a paywall.

Running it yourself needs Go, Task and Docker and two commands, with container images published to the GitHub container registry, though Helm charts are not available yet. The code is Apache 2.0 while the cloud service and trademarks stay with the company.

Share:
Details:

Auto-fetched from GitHub .

Ad

 

 
 
 
 

Open source alternatives similar to Openlane:

 

 
 
  • Stars


  • Forks


  • Last commit


 

 
 
  • Stars


  • Forks


  • Last commit


 

 
 
  • Stars


  • Forks


  • Last commit