nowfound

Alternatives

Products that do what Ex-Deloitte auditor open-sourced the whole SOC 2 method for your AI does

  1. 1
    Comp AI610

    The open source Vanta & Drata alternative

    2025

  2. 2
    Comply105

    Everything you need to complete SOC2 (Open Source)

    2018

  3. 3
    Control168

    Accelerate and automate security & SOC2 compliance for free

    2021

  4. 4

    SOC 2 & ISO 27001 with AI, not consultants

    Jul 2026 · auditbadger.com

  5. 5

    Open-source evaluations and observability for LLM apps

    2024

  6. 6

    Runtime governance for AI agents. Allow, warn, or block every model and tool call before it commits. Hash-chained audit for every decision. Compliance packs for SOC 2, HIPAA, PCI DSS, EU AI Act, SR 11-7, and FDA CSA. Apache 2.0. - sseshachala/conductai

    9d ago · github.com

  7. 7
    DSALTA48

    AI Agents for SOC2/ISO27001/GDPR — Vanta & Drata alternative

    Nov 2025

  8. 8EO

    I built this as a personal open-source project to explore how EU AI Act requirements can be translated into concrete, inspectable technical checks. The core idea is local-first compliance: – risk classification (Articles 5–15, incl. prohibited use cases) – bias evaluation using CrowS-Pairs – automatic Annex IV–oriented PDF reports – no cloud services or external APIs (browser-based + Ollama) I’m especially interested in feedback on whether this kind of technical framing of AI regulation makes sense in real-world projects.

    Jan 2026 · github.com

  9. 9
    AskCodi230

    Custom LLMs, without training. Use via openai compatible api

    Nov 2025

  10. 10AS

    Hi, Wanted to share something I've been working on for over a year. AuditBadger is a compliance management platform that uses AI to write policies (there are underlying "templates" with basic requirements), rewrite controls (or trust service criterions) to match the company context, help figure out your own controls, does initial risk assessment, and business continuity planning (which at least gives you an example of how the process should look like). Fun fact - I wanted to share this a year ago, but then I spotted something similar here. The most common comment was about lacking the SOC 2…

    Aug 2026 · auditbadger.com

  11. 11HO

    Hi HN, I'm Brian, I spent the last few years at Vanta (YC W18), helping startups and enterprises become compliant and I recently started exploring what that might look like in a post-agentic world. The problem Halo solves is: when a company buys an AI agent from a vendor and gives it access to their data, they have no way to check what the agent did with that data. Vendors may have built observability dashboards and audit logs, but those are editable and partisan. SOC 2 and ISO 27001 audit a company's controls, but controls are less predictive when the software is agentic. TLDR: give an…

    Jul 2026 · github.com

  12. 12

    The modern standard in AML compliance through AI agents

    2023

  13. 13

    Open standard for AI Agent2Agent collaboration

    2025

  14. 14CC
  15. 15OS

    Hi everyone, we’re a small team, supported by Mozilla, who are working on re-imagining a UI for training, tuning and testing local LLMs. Everything is open source. If you’ve been training your own LLMs or have always wanted to, we’d love for you to play with the tool and give feedback on what the future development experience for LLM engineering could look like.

    2025 · github.com

  16. 16FU

    Hi HN! We're open-sourcing our collection of SOC 2 controls as the first step in building an open source compliance automation platform. Github: https://github.com/getprobo/probo The current SOC 2 experience: 1. Pay a random $10k+ for compliance software 2. Get hundreds of tasks with no context on what's optional and how much time it will take 3. Realize you need to pay an external auditor 4. End up with checkboxes, not better security Why we think open source matters: - Never speak with a sales guy who doesn’t understand your needs. - You should never pay for templates.…

    2025 · github.com

  17. 17

    AI audit reports for SOX, SOC 2, and ISO 27001

    Jun 2026 · compliance.cyberglobal.ai

  18. 18CL

    We're excited to launch compliant-llm: an open-source toolkit that helps infosec and compliance teams audit AI agents against regulatory frameworks like NIST AI RMF, ISO 42001, and OWASP Top 10. Infosec and compliance teams are now responsible for tracking security and compliance risks of a growing number of AI agents across external and internal apps and third-party vendors. compliant-llm gives you a way to: - Define and run comprehensive red-teaming tests for AI agents - Maps test outcomes to compliance frameworks like NIST AI RMF - Generate detailed audit logs and documentation -…

    2025 · github.com

  19. 19

    AI contract compliance analyzer for GDPR, SOC2, and CCPA

    Feb 2026

  20. 20OS

    We recently open-sourced Hive after using it internally to support real production workflows tied to contracts totaling over $500k. Instead of manually wiring workflows or building brittle automations, Hive is designed to let developers define a goal in natural language and generate an initial agent that can execute real tasks. Today, Hive supports goal-driven agent generation, multi-agent coordination, and production-oriented execution with observability and guardrails. We are actively building toward a system that can capture failure context, evolve agent logic, and continuously improve…

    Feb 2026 · github.com

  21. 21OS
  22. 22OS

    We’re building an open-source tool that makes it easy to expose secure, LLM-optimized APIs on top of your structured data—without manually designing endpoints or worrying about compliance. AI agents and LLM-powered applications need structured access to data, but traditional APIs and databases weren’t built with AI workloads in mind. Our tool automatically generates APIs that: - Filter out PII & sensitive data to comply with GDPR, CPRA, SOC 2, and other regulations. - Provide traceability & auditing, so AI apps aren’t black boxes, and security teams stay in control. - Optimize for AI…

    2025 · github.com

  23. 23OS

    EU legislation (which affects UK and US companies in many cases) requires being able to truly reconstruct agentic events. I've worked in a number of regulated industries off & on for years, and recently hit this gap. We already had strong observability, but if someone asked me to prove exactly what happened for a specific AI decision X months ago (and demonstrate that the log trail had not been altered), I could not. The EU AI Act has already entered force, and its Article 12 kicks-in in August this year, requiring automatic event recording and six-month retention for high-risk systems,…

    Mar 2026

  24. 24

    Score yourself against 200+ SOC 2 controls across 12 domains

    Jun 2026 · securitywall.co

Ranked by how close each launch is in meaning, then by votes. Refine with a description →