Skip to main content
OPEN SOURCE

Open-source GRC, enterprise-ready governance.

Release pending

TruSecure Community Edition is the real core of our platform — AI-assisted GRC workflows, framework mappings, obligation models, a policy assistant, a control library, and an integration framework — released as open source and built to run on the AI inference provider you choose.

Four ways to configure AI inference

Local / self-hosted

Run a model entirely within your own infrastructure.

Private AI gateway

Connect to an internal AI gateway you already operate.

Enterprise-approved

Use your organization's own contracted cloud AI account.

Other endpoint

Any additional endpoint speaking a compatible protocol.

OpenAISF · Written in-house at TruSecure

We also publish the standard we hold ourselves to.

OpenAISF is our open AI-safety and security conformance framework — developed in-house at TruSecure. It covers every requirement of ISO/IEC 42001, the NIST AI Risk Management Framework and the EU AI Act, and requires 118 controls across 20 domains, 36 of them originals no incumbent framework has: agent authority, detection, incident containment, identity delegation, AI data governance, and the integrity of conformance evidence itself.

Free and open — and conformance expires on its own, so it can't be claimed once and shelved.

Read the framework at openaisf.org →
openaisf.org
Covers
every requirement of ISO 42001, NIST AI RMF and the EU AI Act
Requires
118 controls across 20 domains
Originals
36 controls no incumbent framework has
Focus
agent authority · detection · containment · identity delegation · data governance · evidence integrity
Conformance
expires on its own
Built
in-house at TruSecure
Licence
CC BY 4.0 spec · Apache 2.0 tooling

The short answer

TruSecure's core — AI-assisted GRC workflows, framework mappings, a policy assistant, and a control library — is being released as open source under TruSecure Community Edition, soon to be released. It is the same shared core behind TruSecure's commercial platform, not a reduced version.