Self-host in minutes.
Deploy ComplianceOS on your infrastructure. Docker or Node.js + PostgreSQL. No license, no calls, no lock-in.
Prerequisites
- • Node.js 18+ and npm
- • PostgreSQL 15+
- • Git
- • Optional: Docker and docker-compose
Option A: Docker (fastest)
- Clone the repo
- Copy
.env.exampleto.envand add your database credentials - Run
docker compose up -d - Initialize the database:
npm run db:push - Start the app:
npm run dev
Visit http://localhost:5173.
Option B: Manual (Node.js)
1. Clone and install
git clone https://github.com/Sectutor/ComplianceOS-Core.git cd ComplianceOS cp .env.example .env npm install
2. Configure database
# Edit .env with your PostgreSQL connection string # DATABASE_URL=postgres://user:pass@localhost:5432/complianceos npm run db:push
3. Start backend + frontend
# Terminal 1 npm run server # Terminal 2 npm run dev
Local URL: http://localhost:5173
Bring-your-own AI
ComplianceOS routes AI tasks to OpenAI, Anthropic, Google Gemini, DeepSeek, or any OpenAI-compatible endpoint (vLLM, Ollama). Set one or more providers in your .env.
# Example .env entries OPENAI_API_KEY=sk-... ANTHROPIC_API_KEY=sk-ant-... GOOGLE_GENERATIVE_AI_API_KEY=... DEEPSEEK_API_KEY=... OPENAI_BASE_URL=http://localhost:11434/v1 # Ollama
What you get in core
- • ISO 27001, SOC 2, HIPAA, GDPR, NIST 800-53, PCI-DSS
- • Evidence collection, policy generation, gap questionnaires
- • Risk register, heatmaps, treatment plans
- • Vendor management, vendor assessments
- • Auditor-friendly exports and snapshots
When you outgrow self-hosted
Move to managed SaaS when you need multi-tenancy, AI advisor, threat intel (NVD/CISA ingestion), SSO/SCIM, or an SLA. Same platform, we run it.