zero-trust compliance :: public beta
The Non-Custodial Compliance Engine
Open-source, zero-trust, developer-friendly compliance. Evidence without Access. Security-first alternative to centralized platforms.
$ Free forever for CLI + Git storage | No credit card required
Declarative policy checks run locally in your CI. Compliance as code that you can read, audit, and extend.
Every evidence file is Ed25519-signed and hashed. Auditors verify raw files against a signed manifest.
Evidence in your private S3/storage. SigComply never sees or touches your raw data.
Generate PDF/CSV exports mapped to SOC 2, ISO 27001 & HIPAA controls. Make auditors happy.
Automated alerts when evidence collection fails or compliance drifts.
Community-driven connectors. Add support for your custom stack easily.
Runs policy checks locally in your CI/CD
$ sigcomply check✓ Policies pass✓ Signing evidence files...
Your encrypted S3 bucket — evidence never leaves your infrastructure
soc2/aws-mfa/├── evidence.json├── manifest.json (signed)└── envelope.json
Aggregated scores only — no raw evidence, no resource IDs
score: 87%passed: 14 / 16status: compliant
Collect evidence from the tools you already use
// More integrations coming soon | Community contributions welcome
No credit card required • Cancel anytime
For teams getting started
For compliance-ready teams
Starts with a free 2-month trial — no credit card required.
Everything in Free, plus:
$99/mo vs $20,000+/year for tools like Vanta
Start collecting evidence today. No credit card required.