A modern, extensible framework for defining and enforcing security policies across your digital infrastructure.
-
Updated
Jul 1, 2026 - Go
A modern, extensible framework for defining and enforcing security policies across your digital infrastructure.
A platform to automate and orchestrate security rules for governance, risk and compliance, and continuous assurance.
The GRC Companion turns vendor reviews, audit walkthroughs, questionnaires, policy work, control discussions, and terminal output into learning loops. It runs where you already use Claude or Codex, so your local work becomes the curriculum. Based on Ayoub Fandi's GRC Engineering corpus.
Create a domain specific (GRC) agent with the Claude Agent SDK
MCP Documentation Server Using the Official FedRAMP/docs Repo
Hands-on labs and tested reference workspaces for the CGE-P certification
A Rust-based diagramming-as-code API that allows you to turn your .tfstate file into details architecture boundary diagrams.
Collects current-state snapshots and time-windowed audit records from 200+ from AWS, Okta, Jira, Tenable, Jamf, and GitHub and writes them as CSV and JSON. Supports evidence artifacts for FedRAMP, SOC 2, HIPAA audits & etc, inventory and POA&M artifacts using FedRAMP-aligned templates.
Simple CLI script to assist GRC analysts with risk ranking vendors.
GRC Mapping Analyst is a NIST IR 8477-based toolkit for AI-assisted cybersecurity crosswalks, producing deterministic set-theory mappings (equal, subset_of, superset_of, intersects_with, not_related) and 12-column STRM CSV outputs across frameworks, regulations, and control catalogs.
BSides Orlando 2025 talk artifacts and a GCP FedRAMP 20x pilot-era collector demo.
Compliance-as-Code lab using AWS Config, EventBridge, and Lambda auto-remediation with CloudFormation.
GovSCH is an Open-Source Schema for Authoring Cybersecurity & AI Governance Documents
simple go tool for exporting evidence from Vanta
An end-to-end Compliance-as-Code pipeline built with Terraform, AWS Config, and Python. Automates compliance checks, Slack reporting, and audit evidence collection.
Lightweight Python CLI tool that scans AWS IAM policy JSON files for overly permissive statements and maps findings to CJIS v6.0, FedRAMP, and NIST 800-53 compliance controls.
Cloud security policy-as-code with AWS Config, Lambda remediation, and Terraform.
Simulated 6-week HIPAA GRC assessment engagement for a small private healthcare clinic. Structured, client-grade governance and risk documentation aligned to HIPAA and NIST CSF.
Automated AWS compliance guardrails using Service Control Policies and CloudFormation. Controls enforce audit log protection, encryption at rest, boundary protection, and least functionality, mapped to CJIS Security Policy v6.0, FedRAMP High baseline, and NIST 800-53 Rev. 5.
Add a description, image, and links to the grc-engineering topic page so that developers can more easily learn about it.
To associate your repository with the grc-engineering topic, visit your repo's landing page and select "manage topics."