TypeScript Compliance

Open-source TypeScript projects categorized as Compliance

Top 23 TypeScript Compliance Projects

  1. ThreatMapper

    Open Source Cloud Native Application Protection Platform (CNAPP)

  2. Puter.js

    Puter.js - The Backend for AI-Generated Apps. One-shot full-stack apps with your existing AI coding tool. Puter.js gives you Auth, Storage, DB, AI & more, with up to 90% fewer AI tokens than other backend platforms.

    Puter.js logo
  3. ballerine

    Open-source infrastructure and data orchestration platform for risk decisioning

  4. comp

    AI Native platform to get companies compliant - Vanta & Drata Alternative

  5. lunasec

    LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

  6. UTMStack

    Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.

  7. wazuh-dashboard-plugins

    Plugins for Wazuh Dashboard

  8. Kexa

    Kexa's simple rules (Open Source) make it easy to monitoring and manage alerting of your entire cloud. With various monitoring and alerting options, instant and detailed alerts, easy-to-deploy and low in infrastructure costs, in turns complexity into simplicity.

    Project mention: Show HN: Kexa.io – Open-Source IT Security, Compliance and AI-Powered | news.ycombinator.com | 2025-10-15

    Hi HN,

    We're building Kexa.io (https://github.com/kexa-io/Kexa), an open-source tool developed in France (incubated at Euratech Cyber Campus) to help teams automate the often tedious process of verifying IT security and compliance. Keeping track of configurations across diverse assets (servers, K8s, cloud resources) and ensuring they meet security baselines (like CIS benchmarks, etc.) manually is challenging and error-prone.

    Our goal with the open-source core is to provide a straightforward way to define checks, scan your assets, and get clear reports on your security posture. You can define your own rules or use common standards.

    We'd love for the HN community to check out the open-source project on GitHub. Feedback on the concept or the current tool is highly welcome, and a star if you find it interesting helps others discover the project!

    If you're interested check out website we also have an offer with dashboard, no-code rule builder,..

  9. AppSignal

    AppSignal knows why the f*#k it crashed. Stop vibe-debugging. Every exception, every backtrace, grouped so you see patterns, not noise.

    AppSignal logo
  10. verifywise

    Complete AI governance and LLM Evals platform with support for EU AI Act, ISO 42001, NIST AI RMF and 20+ more AI frameworks and regulations. Join our Discord channel: https://discord.com/invite/d3k3E4uEpR

  11. sls-mentor

    Analyze your AWS serverless app in one command! 30+ best practices to improve costs💰 security🛡 stability🧘‍♀️ speed🚀 and sustainability🌱

  12. EuConform

    EU AI Act Compliance Tool - Risk classification and bias testing

    Project mention: Show HN: EuConform – Offline-first EU AI Act compliance tool (open source) | news.ycombinator.com | 2026-01-09
  13. MakerChecker

    Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of duties, and cryptographically signed, offline-verifiable audit logs. (by makerchecker)

    Project mention: Show HN: Scan your AI agents for dangerous capabilities | news.ycombinator.com | 2026-07-06
  14. cmmc

    This application simplifies achieving CMMC NIST SP 800-171 Revision 2 and 3 compliance by providing a user-friendly interface to manage security controls, store data locally, and generate compliance summaries.

    Project mention: CMMC Compliance Application | news.ycombinator.com | 2025-10-27

    I built an open-source tool to make moving toward NIST SP 800-171 Rev-3 (and CMMC readiness) less painful. The app walks you through each control family, lets you mark implemented/non-implemented/partial, provide evidence, and then generates a ready-to-use Markdown SSP and a POAM CSV for unimplemented requirements.

    Everything is stored client-side using IndexedDB, so your assessment data stays in your browser unless you explicitly export or import it. No 3rd party trackers / analytics / servers. It's all a statically rendered web application with offline support (PWA).

    Code is at: https://github.com/JAKTOOL/cmmc

  15. grantex

    grantex is the identity, authorization, and audit infrastructure for AI agents — the "OAuth moment" for the agentic internet. We provide a universal SDK and cloud service that lets any AI agent act on behalf of a human with scoped, revocable permissions, cryptographic identity, and an immutable audit trail. Developers integrate in minutes.

    Project mention: Why AI Agents Need Their Own Authorization Protocol (and How We Built One) | dev.to | 2026-03-15
  16. cia-compliance-manager

    The CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security levels, providing real-time cost estimates, business impact assessments, and technical implementation details.

  17. Heron

    Open-source AI agent auditor. Know what your agents do before production. (by theonaai)

    Project mention: Show HN: Heron is open-source security auditor that interviews your AI agents | news.ycombinator.com | 2026-04-08
  18. platform

    The approval and accountability layer for agentic AI. Identity → Policy → Approval → Trace. Try: npx sidclaw-demo (by sidclawhq)

    Project mention: What is an MCP proxy and why does it need an approval layer? | dev.to | 2026-04-04

    SidClaw (what we built) wraps any stdio MCP server with policy evaluation, human approval workflows, and hash-chain audit trails. 18+ framework integrations. Apache 2.0 SDK.

  19. openclaw-gatewaystack-governance

    GatewayStack governance layer for OpenClaw — identity, scope, rate limiting, injection detection, and audit logging for every tool call

    Project mention: Show HN: GatewayStack – Deny-by-default security for OpenClaw tool calls | news.ycombinator.com | 2026-02-15
  20. open-isms

    Open-source NIS 2 / GRC ISMS platform. Self-hostable. Mirror of the OSS slice of the nisd2.eu monorepo.

    Project mention: Open ISMS platform for GDPR and NIS-2 | news.ycombinator.com | 2026-07-08
  21. standdown

    Affiliate stand-down, done right, for browser extensions. Client-side detection, session state machine, activation guard, cited per-network policy packs.

    Project mention: Show HN: Standdown, open-source affiliate stand-down for browser extensions | news.ycombinator.com | 2026-07-14
  22. wasmagent-js

    Embedded agent runtime compliance layer — WASM sandbox, MCP firewall, capability manifests, verifiable rollouts, and trace-to-training export

    Project mention: MCP Trust Pack: a security layer for MCP tool calls | dev.to | 2026-06-25

    Code: packages/mcp-firewall · packages/mcp-gateway

  23. traceprompt-node

    Traceprompt is an open-source SDK that seals every LLM call and exports write-once, read-many (WORM) logs auditors trust.

    Project mention: Show HN: Traceprompt – open-source SDK for tamper-proof LLM audit trails | news.ycombinator.com | 2025-08-22
  24. trailkit

    Lightweight, zero-infrastructure audit logging for TypeScript. AsyncLocalStorage context propagation, SHA-256 hash chaining, SQLite/PostgreSQL adapters.

    Project mention: I built a zero-infrastructure audit logging SDK for TypeScript -> here's what I learned | dev.to | 2026-03-26

    The full source is on GitHub, including Express and Next.js examples. If you've ever had to build audit logging from scratch, I'd love to hear what you think — especially what's missing.

  25. revdoku

    Revdoku: Open-source AI document review. Self-host or use the cloud. Compatible with local and cloud LLMs.

    Project mention: Show HN: Revdoku – visual document review with AI (open-source) | news.ycombinator.com | 2026-05-01
  26. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

TypeScript Compliance discussion

Log in or Post with

TypeScript Compliance related posts

  • MCP Trust Pack: a security layer for MCP tool calls

    1 project | dev.to | 25 Jun 2026
  • Trace-to-Training: how agent runs become learning data

    1 project | dev.to | 25 Jun 2026
  • Show HN: Get your agents into regulated industries

    1 project | news.ycombinator.com | 24 Jun 2026
  • Microsoft Just Shipped MCP Governance for .NET. Here's What It Actually Enforces.

    2 projects | dev.to | 22 May 2026
  • Show HN: Heron is open-source security auditor that interviews your AI agents

    1 project | news.ycombinator.com | 8 Apr 2026
  • Why AI Agents Need Their Own Authorization Protocol (and How We Built One)

    1 project | dev.to | 15 Mar 2026
  • Show HN: Grantex–Open authorization protocol for AI agents-like OAuth for agents

    1 project | news.ycombinator.com | 15 Mar 2026
  • A note from our sponsor - Puter.js
    developer.puter.com | 8 Aug 2026
    One-shot full-stack apps with your existing AI coding tool. Puter.js gives you Auth, Storage, DB, AI & more, with up to 90% fewer AI tokens than other backend platforms. Learn more →

Index

What are some of the best open-source Compliance projects in TypeScript? This list will help you:

# Project Stars
1 ThreatMapper 5,307
2 ballerine 2,414
3 comp 1,730
4 lunasec 1,469
5 UTMStack 580
6 wazuh-dashboard-plugins 518
7 Kexa 351
8 verifywise 330
9 sls-mentor 201
10 EuConform 123
11 MakerChecker 51
12 cmmc 43
13 grantex 31
14 cia-compliance-manager 20
15 Heron 21
16 platform 13
17 openclaw-gatewaystack-governance 7
18 open-isms 7
19 standdown 5
20 wasmagent-js 5
21 traceprompt-node 4
22 trailkit 4
23 revdoku 3

Sponsored
Puter.js - The Backend for AI-Generated Apps
One-shot full-stack apps with your existing AI coding tool. Puter.js gives you Auth, Storage, DB, AI & more, with up to 90% fewer AI tokens than other backend platforms.
developer.puter.com

Did you know that TypeScript is
the 2nd most popular programming language
based on number of references?