You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Collects current-state snapshots and time-windowed audit records from 200+ from AWS, Okta, Jira, Tenable, Jamf, and GitHub and writes them as CSV and JSON. Supports evidence artifacts for FedRAMP, SOC 2, HIPAA audits & etc, inventory and POA&M artifacts using FedRAMP-aligned templates.
TenableTrawler (Cloud OR FedCloud) is a Python project that pulls scan results via the Tenable API, laying them into organized, POAM-ready outputs. It supports various scans and exports in formats like CSV, JSON, and YAML.
The POAM Pilot is a application designed to streamline the tracking, management, and reporting of security vulnerabilities and compliance requirements.
This repository automates the collection and management of evidence from various tools and sources, committing the data for transparency and traceability. It's designed to gather evidence that tools like Vanta and others aren't built to collect.
Beta. Deterministic, offline structural validator for OSCAL documents: checks structure, identifier format and uniqueness, and whether references resolve, against NIST's published JSON Schema and Metaschema constraint layer, citing the rule behind every finding. Structural conformance only; it does not assess whether a control is implemented.