Projects with this topic
-
The conformance contract for projects under gitlab-com/public-sector.
Updated -
EU AI Act compliance scanner for GitLab CI/CD pipelines — detects AI/ML libraries and posts risk classification as MR comments.
Updated -
Singapore PDPA compliance toolkit — static-analysis scanner, PII redactor, and CI gate. Parses regulatory checklists, detects NRICs/secrets, and produces machine-readable compliance data. Written in Babashka/Clojure.
Updated -
A suite of tools to assist with reviewing Open Source Software dependencies. (Mirrored from https://github.com/oss-review-toolkit/ort)
Updated -
The driver. One tool that provisions the group, applies the NIST 800-53 framework, pushes control evidence, and exports OSCAL artifacts.
Updated -
Landing page for the Evidence Factory group. Start here for the guided walk through the six projects.
Updated -
Consumer workload: a reusable CI/CD Catalog component. Adoption phase enforce, so an off-catalog include is blocked.
Updated -
Consumer workload: a container image. Adoption phase cutover, so the regulatory baseline blocks an unsigned image.
Updated -
Consumer workload: a Go binary. Adoption phase report, so conformance runs advisory and merge requests stay green.
Updated -
The policy plane. Pipeline Execution Policy, security policies, and external compliance controls that assess and gate every consumer.
Updated -
The evidence line and the published CI/CD Catalog. Governed, reusable pipeline components every workload builds from.
Updated -
Compliance service enforcing rules defined in the TrustFramework - Architecture Document/Compliance Document
Updated -
Agility Copilot is a modular, rule-based agility course design system that enables users to create, validate, and optimize competition-ready courses within real-world space constraints. It supports multiple federation rule sets through a plugin architecture, combining constraint validation, spatial optimization, and interactive 3D visualization. Users can design and modify courses using text or voice input while ensuring full compliance with selected agility standards. https://roxanneardary.com/agility-copilot/
Updated -
PHITrack is an open-source platform that monitors, analyzes, and visualizes PHI (Protected Health Information) transmissions using AI-driven insights while maintaining human-in-the-loop oversight. It provides dashboards, alerts, predictive risk scoring, and synthetic dataset simulations to ensure HIPAA-safe compliance, training, and reporting. https://roxanneardary.com/phitrack/
Updated -
SharedRail is an open-source, federated payment infrastructure designed to enable secure, instant, and identity-based value transfer across currencies and borders. Built on a modular architecture with mandatory encryption, KYC, and AI-assisted human intent verification, SharedRail allows users and institutions to send and receive payments using verified email identities while maintaining full transparency, auditability, and compliance through open standards. https://roxanneardary.com/sharedrail/
Updated -
BalanceSeal is an AGPL 3.0+ cryptographic audit module for cryptocurrency exchanges and digital wallets that generates a verifiable, time-frozen snapshot of all user assets at the moment an account is terminated. It aggregates on-chain and off-chain balances, reconciles holdings across systems, locks market pricing at the termination timestamp, and produces tamper-evident reports for compliance, auditing, and transparency. https://roxanneardary.com/balanceseal/
Updated -
Source of truth for the Compliance engine, validating certificate are conforming to rules, providing shapes, schemas and trusted sources
Updated -
CLI tool for GitLab automation: sync groups to local filesystem and audit projects against security & OpenSSF best practices with automated scoring
Updated -
GitPatrol is an open-source AI platform that automatically enforces license compliance, tracks contributor attribution, and generates minimal, token-efficient files for Git repositories. It scans code, documentation, and dependencies for violations, suggests safe fixes, and integrates with CI/CD pipelines to keep projects legally safe and fully compliant.
Updated -
AI-powered security orchestration for GitLab CI/CD. Automated vulnerability patching, threat modeling, and compliance scoring with GPT-4 and Claude AI agents.
Updated