# strongdm/comply

Compliance automation framework, focused on SOC2

Repository: https://github.com/strongdm/comply
Canonical: https://ross.abutalabs.com/products/comply
Homepage: https://comply.strongdm.com
Language: Go
License: Apache-2.0
License Family: permissive
Topics: soc2, grc, compliance, templates, documentation-toolchain, go, golang, pdf-generation, gdpr, hipaa, iso27001
Last push: 2022-07-21T08:02:53+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3102, "days_push": 1504, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1576, forks 285 (observed 2026-08-28T04:05:06.022998+00:00)

## What it is
Comply is an open-source SOC2-focused compliance automation CLI written in Go. It generates auditor-friendly policy documents from Markdown templates, builds a static compliance dashboard website, and automates compliance tasks through integrations with existing ticketing systems.

## Use cases
- generate SOC2 policy documents from markdown templates
- prepare for a SOC2 audit with pre-authored policy boilerplate
- track which compliance controls are declared vs satisfied
- automate recurring compliance tickets via existing ticketing system
- publish a static website summarizing the compliance program
- produce auditor-friendly PDF policy documents
- bootstrap a compliance-as-code repository with comply init

## When to choose
- you need to prepare policy documentation for a SOC2 audit
- you want compliance-as-code with policies versioned in git
- your team already works in ticketing systems like Jira or GitHub and wants compliance tasks automated
- you want free, open-source policy templates for SOC2, GDPR, HIPAA, or ISO27001

## When to avoid
- you need automated evidence collection from infrastructure (that is StrongDM's commercial product, not Comply)
- you need a full GRC platform with continuous control monitoring
- you run Windows natively without Docker
- you need actively maintained software with recent releases

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: documentation, templating, workflow-automation, pdf, developer-tools
- domain: security, legal, developer-tools, documentation
- platform: cli, go
- tags: soc2, grc, policy-templates, audit, gdpr, hipaa, iso27001, markdown, pandoc, ticketing-integration, automation, linux, macos, docker

## Member repositories
- strongdm/comply (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:06.022998+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:57:25.792024+00:00, confidence not recorded.
  - readme: https://github.com/strongdm/comply (fetched 2026-08-28T04:05:06.022998+00:00, sha c196a2ab9015)
  - homepage: https://comply.strongdm.com (fetched 2026-08-29T11:27:40.310586+00:00, sha b5531f194556)
  - site_page: https://www.strongdm.com/docs (fetched 2026-08-29T11:27:40.321333+00:00, sha 17b7fb9d8c45)
  - site_page: https://www.strongdm.com/docs/desktop (fetched 2026-08-29T11:27:40.323000+00:00, sha 21985fedbbe2)
  - site_page: https://www.strongdm.com/docs/admin (fetched 2026-08-29T11:27:40.325223+00:00, sha 19114fab890b)
  - site_page: https://www.strongdm.com/docs/api (fetched 2026-08-29T11:27:40.327068+00:00, sha 4c2d14a60087)
  - site_page: https://www.strongdm.com/about (fetched 2026-08-29T11:27:40.328979+00:00, sha ee2eb14fdd10)
  - site_page: https://www.strongdm.com/pricing (fetched 2026-08-29T11:27:40.319418+00:00, sha d140d40b0420)
  - site_page: https://www.strongdm.com/ (fetched 2026-08-29T11:27:40.330592+00:00, sha a1ca7e53d760)
- Data as of 2026-08-30T08:39:29.467469+00:00.
