SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Python Audit Projects
-
Amphion
Amphion (/æmˈfaɪən/) is a toolkit for Audio, Music, and Speech Generation. Its purpose is to support reproducible research and help junior researchers and engineers get started in the field of audio, music, and speech generation research and development.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Project mention: CISO Assistant, the open-source GRC platform introduces CRQ | news.ycombinator.com | 2025-09-15 -
SysReptor
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
-
masvs
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
-
-
-
hubble
Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event notifications, alerting, and reporting. (by hubblestack)
-
-
-
Project mention: Show HN: Cloud-audit – AWS scanner that chains findings into attack paths | news.ycombinator.com | 2026-04-01
-
-
-
openclaw-contained
TaskForge runs AI agents in sandboxed Docker containers with capability-based security. Agents start with minimal permissions and must request new capabilities (packages, network access, tools) through a human-in-the-loop approval process. Every approval triggers a container image rebuild, and every LLM interaction is logged for audit.
Project mention: TaskForge – immutable, orchiestration for OpenClaw bots | news.ycombinator.com | 2026-02-27 -
Project mention: Milla Jovovich just released an AI memory system. It reached over 1.5 million people and 5,400 GitHub stars in less than 24 hours. | dev.to | 2026-04-07
We maintain a public LoCoMo ground-truth audit at github.com/dial481/locomo-audit, with per-conversation error files documenting hallucinations, attribution errors, ambiguous questions, and incomplete answers across all ten conversations. The audit is open for contribution. We believe a new and improved version of LoCoMo would benefit every group working on conversational memory, including the MemPalace maintainers and including ourselves. The goal is better benchmarks, not a kill shot on any individual project.
-
airblackbox
Open-source EU AI Act compliance scanner. 51 checks across Articles 9-15. Drop-in trust layers for LangChain, CrewAI, AutoGen, OpenAI. Local-first, no data leaves your machine.
Project mention: Meta's Rogue AI Agent Just Proved Why AI Governance Can't Wait | dev.to | 2026-03-25Site: airblackbox.ai
-
Project mention: FinLang – A deterministic, auditable rules engine for finance (AGPL) | news.ycombinator.com | 2025-11-16
-
air-platform
One command to run the full AI audit stack: Gateway + Policy Engine + Episode Store + Jaeger + Prometheus. Make up. 8 seconds.
git clone https://github.com/airblackbox/air-platform.git cd air-platform cp .env.example .env
-
-
unworldly
The flight recorder for AI agents. Tamper-proof, ISO 42001 + HIPAA-compliant audit trails for everything AI agents do on your system. File changes + shell commands + PHI detection + agent identity.
Project mention: Show HN: Unworldly – A flight recorder for AI agents (tamper-proof, HIPAA) | news.ycombinator.com | 2026-02-25 -
aiir
AI Integrity Receipts — generate, verify, and attest cryptographic receipts for commits with declared AI involvement. Release verification with SLSA-compatible VSA. Zero dependencies. Apache 2.0.
Project mention: Show HN: AIIR: track AI-assisted Git commits with cryptographic receipts | news.ycombinator.com | 2026-03-19 -
casa-runtime
Deterministic execution control plane for autonomous agent systems - pre-execution governance with audit-grade traces.
Project mention: AI Governance That Runs: Building a Deterministic Execution Gate | news.ycombinator.com | 2026-03-16 -
piqrypt
AI agent governance layer — sign, monitor and control every agent action. EU AI Act · ANSSI · NIST ready.
Full demo code: github.com/piqrypt/piqrypt/demos
-
Project mention: I scanned 30 popular AI projects for tamper-evident LLM evidence. 0 had it | news.ycombinator.com | 2026-02-21
Python Audit discussion
Python Audit related posts
-
Show HN: AERF, signed control events for AI agent actions
-
GateGraph – a gate that decides if an AI agent action may proceed before it runs
-
I Built a Runtime Governance Tool for AI Agents — Here's Why Your Agents Need It
-
Watch your CrewAI agents in real-time with PiQrypt Vigil
-
Show HN: Cloud-audit – AWS scanner that chains findings into attack paths
-
Meta's Rogue AI Agent Just Proved Why AI Governance Can't Wait
-
Show HN: AI agents have no memory – PiQrypt makes their actions verifiable
-
A note from our sponsor - SaaSHub
www.saashub.com | 14 Jun 2026
Index
What are some of the best open-source Audit projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | Amphion | 9,839 |
| 2 | ciso-assistant-community | 4,127 |
| 3 | SysReptor | 2,491 |
| 4 | masvs | 2,390 |
| 5 | XSRFProbe | 1,286 |
| 6 | django-easy-audit | 842 |
| 7 | hubble | 385 |
| 8 | arch-security-tracker | 130 |
| 9 | panoptisch | 70 |
| 10 | cloud-audit | 59 |
| 11 | codeaudit | 40 |
| 12 | masscan_as_a_service | 29 |
| 13 | openclaw-contained | 28 |
| 14 | locomo-audit | 17 |
| 15 | airblackbox | 17 |
| 16 | finlang | 13 |
| 17 | air-platform | 9 |
| 18 | revy | 8 |
| 19 | unworldly | 8 |
| 20 | aiir | 5 |
| 21 | casa-runtime | 4 |
| 22 | piqrypt | 3 |
| 23 | assay | 3 |