- Interested in some form of partnership or new license? Contact me on discord
- Stay up to date on changes: https://forms.gle/EXigxbcWTSXcPnjw7
- Discord: https://discord.gg/9unhWAqadg
- NIST CSF, NIST-800-53, CMMC, HIPAA, ASVS and ISO27001 have been added! That makes 7 total frameworks
- Total revamp of the UI
- Multi-tenancy is now supported!
- Control automation?
- Endpoint agents for compliance?
- More frameworks?
- Take a look at the current roadmap or submit a issue
Gapps is an Security compliance platform that makes it easy to track your progress against various security frameworks. Gapps is currently in Alpha mode - while it works great, there may be some breaking changes as it evolves. Please do not use this in production.... yet!.
- Supports 7 security compliance frameworks (more coming)
- 1500+ controls and 25+ policies out of the box for the frameworks (majority of policies are sourced from strongdm/comply)
- Track the status of each control
- Add custom controls/policies
- WYSIWYG content editor
Gapps-3.1.mp4
Home Dashboard |
---|
Project Controls |
---|
Track Progress |
---|
The following instructions are to get you started very quickly. The image will be pulled from Docker Hub
$ git clone https://github.com/bmarsh9/gapps.git; cd gapps
$ export SETUP_DB=yes;docker-compose up -d
The server should be running on http://<your-ip>:5000
The default email/password is [email protected]:admin
Next, create a project and select the framework (SOC2). Based on the selected criteria, controls and policies will be automatically added to your project. You can also go to the Controls and Policies page and add them to your project.
You can setup email (for sending user invites) as well by setting the following environment variables (docker-compose file or elsewhere)
MAIL_USERNAME="[email protected]"
MAIL_PASSWORD="app password" # https://support.google.com/accounts/answer/185833?hl=en