v0.1.0-alpha :: zero-trust compliance
The Non-Custodial Compliance Engine
Open-source, zero-trust, developer-friendly compliance. Evidence without Access. Security-first alternative to centralized platforms.
$ Free forever for CLI + Git storage | No credit card required
Open Policy Agent checks run locally. Compliance as code that you can audit and modify.
SHA-256 hashes prove evidence integrity. Auditors verify raw files against immutable ledger.
Evidence in your private S3/storage. SigComply never sees or touches your raw data.
Generate PDF/CSV exports mapped to CCF requirements. Make auditors happy.
Automated alerts when evidence collection fails or compliance drifts.
Community-driven connectors. Add support for your custom stack easily.
Runs OPA policies locally in your CI/CD
$ sigcomply check✓ OPA policies pass✓ Hashing evidence...
Your encrypted S3 bucket or private storage
s3://your-vault/├── logs/├── configs/└── screenshots/
Cryptographic hashes + metadata only
hash: sha256...timestamp: 2025-01-10status: compliant
Collect evidence from the tools you already use
// More integrations coming soon | Community contributions welcome
No credit card required • Cancel anytime
For teams getting started
For compliance-ready teams
Everything in Free, plus:
$99/mo vs $20,000+/year for tools like Vanta
Start collecting evidence today. No credit card required.