v0.1.0-alpha :: zero-trust compliance
The Non-Custodial Compliance Engine
Open-source, zero-trust, developer-friendly compliance. Evidence without Access. Security-first alternative to centralized platforms.
$ Free forever for CLI + Git storage | No credit card required
Open Policy Agent checks run locally. Compliance as code that you can audit and modify.
SHA-256 hashes prove evidence integrity. Auditors verify raw files against immutable ledger.
Evidence in your private S3/storage. SigComply never sees or touches your raw data.
Generate PDF/CSV exports mapped to CCF requirements. Make auditors happy.
Automated alerts when evidence collection fails or compliance drifts.
Community-driven connectors. Add support for your custom stack easily.
Runs OPA policies locally in your CI/CD
$ sigcomply check✓ OPA policies pass✓ Signing evidence files...
Your encrypted S3 bucket — evidence never leaves your infrastructure
soc2/aws-mfa/├── evidence/│ └── iam-users.json└── result.json
Aggregated scores only — no raw evidence, no resource IDs
score: 87%passed: 14 / 16status: compliant
Collect evidence from the tools you already use
// More integrations coming soon | Community contributions welcome
No credit card required • Cancel anytime
For teams getting started
For compliance-ready teams
Everything in Free, plus:
$99/mo vs $20,000+/year for tools like Vanta
Start collecting evidence today. No credit card required.