One-shot full-stack apps with your existing AI coding tool. Puter.js gives you Auth, Storage, DB, AI & more, with up to 90% fewer AI tokens than other backend platforms. Learn more →
Top 23 TypeScript Compliance Projects
-
-
Puter.js
Puter.js - The Backend for AI-Generated Apps. One-shot full-stack apps with your existing AI coding tool. Puter.js gives you Auth, Storage, DB, AI & more, with up to 90% fewer AI tokens than other backend platforms.
-
-
-
lunasec
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
-
UTMStack
Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.
-
-
Kexa
Kexa's simple rules (Open Source) make it easy to monitoring and manage alerting of your entire cloud. With various monitoring and alerting options, instant and detailed alerts, easy-to-deploy and low in infrastructure costs, in turns complexity into simplicity.
Project mention: Show HN: Kexa.io – Open-Source IT Security, Compliance and AI-Powered | news.ycombinator.com | 2025-10-15Hi HN,
We're building Kexa.io (https://github.com/kexa-io/Kexa), an open-source tool developed in France (incubated at Euratech Cyber Campus) to help teams automate the often tedious process of verifying IT security and compliance. Keeping track of configurations across diverse assets (servers, K8s, cloud resources) and ensuring they meet security baselines (like CIS benchmarks, etc.) manually is challenging and error-prone.
Our goal with the open-source core is to provide a straightforward way to define checks, scan your assets, and get clear reports on your security posture. You can define your own rules or use common standards.
We'd love for the HN community to check out the open-source project on GitHub. Feedback on the concept or the current tool is highly welcome, and a star if you find it interesting helps others discover the project!
If you're interested check out website we also have an offer with dashboard, no-code rule builder,..
-
AppSignal
AppSignal knows why the f*#k it crashed. Stop vibe-debugging. Every exception, every backtrace, grouped so you see patterns, not noise.
-
verifywise
Complete AI governance and LLM Evals platform with support for EU AI Act, ISO 42001, NIST AI RMF and 20+ more AI frameworks and regulations. Join our Discord channel: https://discord.com/invite/d3k3E4uEpR
-
sls-mentor
Analyze your AWS serverless app in one command! 30+ best practices to improve costs💰 security🛡 stability🧘♀️ speed🚀 and sustainability🌱
-
Project mention: Show HN: EuConform – Offline-first EU AI Act compliance tool (open source) | news.ycombinator.com | 2026-01-09
-
MakerChecker
Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of duties, and cryptographically signed, offline-verifiable audit logs. (by makerchecker)
Project mention: Show HN: Scan your AI agents for dangerous capabilities | news.ycombinator.com | 2026-07-06 -
cmmc
This application simplifies achieving CMMC NIST SP 800-171 Revision 2 and 3 compliance by providing a user-friendly interface to manage security controls, store data locally, and generate compliance summaries.
I built an open-source tool to make moving toward NIST SP 800-171 Rev-3 (and CMMC readiness) less painful. The app walks you through each control family, lets you mark implemented/non-implemented/partial, provide evidence, and then generates a ready-to-use Markdown SSP and a POAM CSV for unimplemented requirements.
Everything is stored client-side using IndexedDB, so your assessment data stays in your browser unless you explicitly export or import it. No 3rd party trackers / analytics / servers. It's all a statically rendered web application with offline support (PWA).
Code is at: https://github.com/JAKTOOL/cmmc
-
grantex
grantex is the identity, authorization, and audit infrastructure for AI agents — the "OAuth moment" for the agentic internet. We provide a universal SDK and cloud service that lets any AI agent act on behalf of a human with scoped, revocable permissions, cryptographic identity, and an immutable audit trail. Developers integrate in minutes.
Project mention: Why AI Agents Need Their Own Authorization Protocol (and How We Built One) | dev.to | 2026-03-15 -
cia-compliance-manager
The CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security levels, providing real-time cost estimates, business impact assessments, and technical implementation details.
-
Project mention: Show HN: Heron is open-source security auditor that interviews your AI agents | news.ycombinator.com | 2026-04-08
-
platform
The approval and accountability layer for agentic AI. Identity → Policy → Approval → Trace. Try: npx sidclaw-demo (by sidclawhq)
SidClaw (what we built) wraps any stdio MCP server with policy evaluation, human approval workflows, and hash-chain audit trails. 18+ framework integrations. Apache 2.0 SDK.
-
openclaw-gatewaystack-governance
GatewayStack governance layer for OpenClaw — identity, scope, rate limiting, injection detection, and audit logging for every tool call
Project mention: Show HN: GatewayStack – Deny-by-default security for OpenClaw tool calls | news.ycombinator.com | 2026-02-15 -
open-isms
Open-source NIS 2 / GRC ISMS platform. Self-hostable. Mirror of the OSS slice of the nisd2.eu monorepo.
-
standdown
Affiliate stand-down, done right, for browser extensions. Client-side detection, session state machine, activation guard, cited per-network policy packs.
Project mention: Show HN: Standdown, open-source affiliate stand-down for browser extensions | news.ycombinator.com | 2026-07-14 -
wasmagent-js
Embedded agent runtime compliance layer — WASM sandbox, MCP firewall, capability manifests, verifiable rollouts, and trace-to-training export
Code: packages/mcp-firewall · packages/mcp-gateway
-
traceprompt-node
Traceprompt is an open-source SDK that seals every LLM call and exports write-once, read-many (WORM) logs auditors trust.
Project mention: Show HN: Traceprompt – open-source SDK for tamper-proof LLM audit trails | news.ycombinator.com | 2025-08-22 -
trailkit
Lightweight, zero-infrastructure audit logging for TypeScript. AsyncLocalStorage context propagation, SHA-256 hash chaining, SQLite/PostgreSQL adapters.
Project mention: I built a zero-infrastructure audit logging SDK for TypeScript -> here's what I learned | dev.to | 2026-03-26The full source is on GitHub, including Express and Next.js examples. If you've ever had to build audit logging from scratch, I'd love to hear what you think — especially what's missing.
-
revdoku
Revdoku: Open-source AI document review. Self-host or use the cloud. Compatible with local and cloud LLMs.
Project mention: Show HN: Revdoku – visual document review with AI (open-source) | news.ycombinator.com | 2026-05-01 -
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
TypeScript Compliance discussion
TypeScript Compliance related posts
-
MCP Trust Pack: a security layer for MCP tool calls
-
Trace-to-Training: how agent runs become learning data
-
Show HN: Get your agents into regulated industries
-
Microsoft Just Shipped MCP Governance for .NET. Here's What It Actually Enforces.
-
Show HN: Heron is open-source security auditor that interviews your AI agents
-
Why AI Agents Need Their Own Authorization Protocol (and How We Built One)
-
Show HN: Grantex–Open authorization protocol for AI agents-like OAuth for agents
-
A note from our sponsor - Puter.js
developer.puter.com | 8 Aug 2026
Index
What are some of the best open-source Compliance projects in TypeScript? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | ThreatMapper | 5,307 |
| 2 | ballerine | 2,414 |
| 3 | comp | 1,730 |
| 4 | lunasec | 1,469 |
| 5 | UTMStack | 580 |
| 6 | wazuh-dashboard-plugins | 518 |
| 7 | Kexa | 351 |
| 8 | verifywise | 330 |
| 9 | sls-mentor | 201 |
| 10 | EuConform | 123 |
| 11 | MakerChecker | 51 |
| 12 | cmmc | 43 |
| 13 | grantex | 31 |
| 14 | cia-compliance-manager | 20 |
| 15 | Heron | 21 |
| 16 | platform | 13 |
| 17 | openclaw-gatewaystack-governance | 7 |
| 18 | open-isms | 7 |
| 19 | standdown | 5 |
| 20 | wasmagent-js | 5 |
| 21 | traceprompt-node | 4 |
| 22 | trailkit | 4 |
| 23 | revdoku | 3 |