Ross ROSS = Recommend OSS · open-source software intelligence for agents

strongdm/comply

Compliance automation framework, focused on SOC2 observed · 2026-08-28

github.com/strongdm/comply · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3102
  • days_rel: n/a
  • days_push: 1504
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1576 stars · 285 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Comply is an open-source SOC2-focused compliance automation CLI written in Go. It generates auditor-friendly policy documents from Markdown templates, builds a static compliance dashboard website, and automates compliance tasks through integrations with existing ticketing systems.

Use cases

  • generate SOC2 policy documents from markdown templates
  • prepare for a SOC2 audit with pre-authored policy boilerplate
  • track which compliance controls are declared vs satisfied
  • automate recurring compliance tickets via existing ticketing system
  • publish a static website summarizing the compliance program
  • produce auditor-friendly PDF policy documents
  • bootstrap a compliance-as-code repository with comply init

When to choose

  • you need to prepare policy documentation for a SOC2 audit
  • you want compliance-as-code with policies versioned in git
  • your team already works in ticketing systems like Jira or GitHub and wants compliance tasks automated
  • you want free, open-source policy templates for SOC2, GDPR, HIPAA, or ISO27001

When to avoid

  • you need automated evidence collection from infrastructure (that is StrongDM's commercial product, not Comply)
  • you need a full GRC platform with continuous control monitoring
  • you run Windows natively without Docker
  • you need actively maintained software with recent releases

Facets

cli-tool · maturity maintenance

documentation templating workflow-automation pdf developer-tools security legal developer-tools documentation cli go soc2 grc policy-templates audit gdpr hipaa iso27001 markdown pandoc ticketing-integration automation linux macos docker

9 sources

Member repositories

RepositoryRoleHealth v2
strongdm/complymain23

For agents

markdown · JSON · MCP: product_card(name="strongdm/comply")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem