finds.dev← search

// the find

trycompai/comp

★ 2,004 · TypeScript · AGPL-3.0 · updated Sep 2026

AI Native platform to get companies compliant - Vanta & Drata Alternative

Comp AI is an open-core platform for automating SOC 2, ISO 27001, HIPAA and GDPR compliance work (evidence collection, policy management, control tracking), pitched as an open-source alternative to Vanta/Drata. It's aimed at startups and small compliance/security teams who want to self-host rather than pay for a SaaS audit-prep tool.

It's a real multi-app monorepo (Next.js app + portal + a separate NestJS API) with background jobs via Trigger.dev, Prisma/Postgres, and Redis via Upstash, not a toy demo. The repo has genuine infrastructure around it: CI workflows for type-checking, migrations, SBOM generation, and even scripted security-review and RBAC-audit skills for AI coding agents, which suggests the team is actually dogfooding the compliance tooling on their own codebase. The AGPLv3 core with a clearly scoped commercial EE carve-out is an honest and fairly rare way to do open-core licensing.

Local setup is heavier than the README lets on: three separate .env files, a paid Trigger.dev cloud account, Google OAuth client, and Upstash Redis are all required just to run it, and the README's fallback advice for failed env vars is to hardcode secrets directly into auth.ts and the kv package source — a bad practice to suggest in a product whose whole pitch is security compliance. The Docker and Vercel deployment sections literally say 'coming soon,' so despite the self-hosting pitch there's no documented production deployment path. The README also has a stray unrendered HTML entity in a badge string, a small but telling sign of low doc polish for a 2k-star repo.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →