Probo
Open source compliance: SOC 2, ISO 27001, GDPR, HIPAA, risk & vendor management
Install this app
In your Cloudron dashboard, open the App Store, choose "Community apps" and paste this URL:
https://git.nostrdev.com/stuff/cloudron-probo/raw/branch/main/CloudronVersions.json
Description
Probo is a self-hostable governance, risk, and compliance (GRC) platform for engineering and security teams. It covers the full compliance lifecycle — risk identification, control tracking, vendor risk, data privacy, access reviews, audit programs, and document approval workflows — all accessible through a web console, a CLI, an MCP API, and a GraphQL API.
Why Probo?
- Full GRC coverage. Risk management, controls, vendor risk, data privacy (DPIA/TIA), access reviews, and audit programs in one place.
- AI-native by design. 270+ MCP tools expose every entity and operation, so any MCP-compatible LLM agent can read and write your GRC data, draft policies, run risk assessments, and generate evidence packs.
- Audit-ready. Policy-based RBAC, immutable audit logs, electronic document sign-off workflows, and evidence chains.
- Open source & self-hostable. MIT licensed. Your compliance data stays on your own infrastructure.
Capabilities
Risk Management Risk register, inherent/residual scoring, treatment strategies, threat-based assessments Controls & Frameworks Control library with maturity levels, framework import/export, Statement of Applicability Vendor / Third-Party Risk Vendor inventory, automated website risk assessment, DPA/BAA tracking, subprocessor discovery Data Privacy DPIA, Transfer Impact Assessments, processing records, data inventory, rights requests Access Reviews Campaign management, per-entry access decisions, SaaS/cloud/source-code integrations Audit Programs Audit scoping, control mapping, finding tracking, report generation Evidence & Measures Evidence collection (files and URLs), implementation state tracking, task assignment Document Management Versioned documents, approval quorums, electronic signatures, PDF export Compliance Page Public compliance portal, NDA management, certification publishing, custom domains Cookie & Consent Cookie banner management, tracker detection, consent recordsInterfaces
- Web console — the primary interface for day-to-day GRC work.
prbCLI — a full command-line client covering every resource type.- MCP API & GraphQL API — automate compliance from code, scripts, or LLM agents.
- n8n community node — no-code automation.
Frameworks
SOC 2, ISO 27001, GDPR, HIPAA, NIST 800-53, and custom frameworks (import/export).
Recent Changes
[0.2.0]

