{"id":51644528,"url":"https://github.com/frousselet/cairn","last_synced_at":"2026-07-13T21:30:58.894Z","repository":{"id":341290214,"uuid":"1168307919","full_name":"frousselet/cairn","owner":"frousselet","description":"GRC tool","archived":false,"fork":false,"pushed_at":"2026-07-03T12:59:01.000Z","size":11129,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-03T14:29:20.513Z","etag":null,"topics":["ebios-rm","grc","hds","isms","iso27001","iso27005","risk","risk-management","security"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/frousselet.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-02-27T08:35:47.000Z","updated_at":"2026-07-03T12:59:03.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/frousselet/cairn","commit_stats":null,"previous_names":["frousselet/open-grc","frousselet/cairn"],"tags_count":104,"template":false,"template_full_name":null,"purl":"pkg:github/frousselet/cairn","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/frousselet%2Fcairn","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/frousselet%2Fcairn/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/frousselet%2Fcairn/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/frousselet%2Fcairn/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/frousselet","download_url":"https://codeload.github.com/frousselet/cairn/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/frousselet%2Fcairn/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35437763,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-13T02:00:06.543Z","response_time":119,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ebios-rm","grc","hds","isms","iso27001","iso27005","risk","risk-management","security"],"created_at":"2026-07-13T21:30:58.202Z","updated_at":"2026-07-13T21:30:58.888Z","avatar_url":"https://github.com/frousselet.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Cairn\n\nOpen-source **Governance, Risk and Compliance** (GRC) platform.\n\nManage your organisation's security posture, track compliance with regulatory frameworks (ISO 27001, GDPR, NIS2, ...), and run structured risk assessments (ISO 27005, EBIOS RM) - all from a single, self-hosted application.\n\n![Cairn dashboard](docs/screenshots/dashboard.png)\n\n## What you get\n\n- **Governance** : organisational scopes (with a Draft -\u003e Definition -\u003e Validation -\u003e In force -\u003e Review perimeter lifecycle), sites (with a Draft -\u003e Commissioning -\u003e Operational -\u003e Review operational lifecycle, plus Decommissioned / Archived), strategic issues, stakeholders, objectives, SWOT, roles and activities\n- **Assets** : essential and support assets with CIA valuation, dependencies, SPOF detection and a supplier registry (contacts, mapped addresses, a risk lifecycle and per-requirement compliance evaluation) with CSV bulk import, plus a **Documents** area with **contracts** (multi-party - suppliers and customer stakeholders, amendments, an attached PDF stored securely and a Draft -\u003e Active -\u003e Expired/Terminated lifecycle) and **certificates** (the company's own ISO/HDS/SOC 2 certificates, each attached to the framework it attests, with certification body, validity dates, covered sites, renewal history and an attached PDF)\n- **Risks** : ISO 27005 and EBIOS RM (ANSSI v1.5, workshops 0 to 5) assessments, threat and vulnerability catalogs, treatment plans and formal risk acceptance\n- **Compliance** : frameworks, requirements, assessments, findings, action plans and inter-framework mappings, with Excel import and an optional **risk-driven applicability** mode (a framework derives each requirement's applicability automatically from its linked risks)\n- **Steering** : a real-time, **configurable widget dashboard** (Apple-style edit mode with drag-to-reorder, two-dimensional `WxH` tile sizing with each tile's content auto-fitted to its size - no scroll, no empty space - reusable widgets (the same widget, e.g. a single-KPI **Indicator**, can be placed multiple times, each with its own settings), and an add/remove gallery, persisted per user) covering overall compliance, individual KPI indicators, an **Ask Cairn** LLM-synthesised daily briefing (a metrics snapshot summarised by the configured model, fetched asynchronously and cached), compliance by framework, active objectives, priority risks, upcoming deadlines, a conditional **ongoing audits** widget (shown only while an audit is running), the current-to-residual risk treatment flow chart and the current and residual risk matrices (each its own widget), plus **Section** headings (a bare, full-width title rendered straight on the page background) to group widgets into labelled sections; a unified To do / Doing / Done \"Tasks\" board aggregating action plans, treatment actions, audits and risk assessments; ISO 27001 management reviews; and PDF/DOCX/PPTX report generation (SoA, audit report, risk register, meeting minutes)\n- **Trust Center** : a public, curated page to share your security posture (certifications and compliance level, subprocessors, security measures, downloadable documents), built directly into Cairn and optionally servable on a separate domain - an explicit, opt-in curation layer so internal GRC data never leaks\n- **Ask Cairn (optional)** : natural-language questions in the command palette (\"Which decisions were made at the last management review?\"), answered by a pluggable LLM provider (Mistral AI by default; OpenAI / any OpenAI-compatible endpoint; Claude; self-hosted Ollama) that cites real records and enforces your permissions, with thumbs up/down feedback that admins can export to improve the assistant. Its name is customisable in the company settings (defaults to \"Ask Cairn\")\n\nEverything is bilingual (English/French), audit-ready (full change history, versioning, lifecycle workflows) and access-controlled (role-based permissions, scope-based tenancy, passkey login).\n\nBeyond the web UI, every feature is also available through a [REST API](docs/api.md) and a built-in [MCP server](docs/mcp-server.md), so scripts and AI assistants can work with your GRC data directly.\n\n## Quick start\n\nWith [Docker](https://docs.docker.com/get-docker/) installed:\n\n```bash\ncp .env.example .env\ndocker compose up --build\n```\n\nThen open [http://localhost:8000](http://localhost:8000). On a fresh database a **first-run onboarding screen** greets you: it shows the database migration state and lets you either **start from scratch** (a two-step wizard: configure your company, then create the first administrator account - everything is sent in a single request, so nothing is written to the database until the admin exists) or **start with sample data** (load the demo dataset behind a live progress bar, then sign you in automatically). See [first-run onboarding](docs/modules/m0-accounts/onboarding.md). You can still create an admin from the CLI instead (`docker compose exec web python manage.py createsuperuser`).\n\nPrefer pure Python for debugging? Cairn also runs with no Docker and no external service using [mise](https://mise.jdx.dev/) (SQLite + in-memory channels), with ready-to-use VS Code launch configurations - see [running in pure Python for debugging](docs/installation.md#option-3--run-in-pure-python-for-debugging-mise).\n\nTo run the published image without cloning the repository, and for production notes (scheduled commands), see the [installation guide](docs/installation.md).\n\n## Documentation\n\n| Document | Contents |\n| -------- | -------- |\n| [Installation guide](docs/installation.md) | Docker setup (from source or published image), pure-Python debugging with mise, scheduled commands |\n| [Features](docs/features.md) | Detailed feature reference for every module |\n| [REST API](docs/api.md) | Base paths, authentication, conventions |\n| [MCP server](docs/mcp-server.md) | Endpoints, OAuth 2.0, full tool reference |\n| [Module specifications](docs/modules/README.md) | Business rules and per-entity contracts |\n\n## Tech stack\n\nDjango 5.2 LTS, PostgreSQL 16, Django REST Framework, Django Channels + Redis (real-time and shared cache), Bootstrap 5.3 + HTMX + Apache ECharts (frontend), Docker. Optional: Mistral AI, OpenAI / OpenAI-compatible endpoints, Claude (Anthropic), or self-hosted Ollama (Ask Cairn assistant).\n\n## Licence\n\nMIT\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffrousselet%2Fcairn","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffrousselet%2Fcairn","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffrousselet%2Fcairn/lists"}