Skip to content
@complytime

complytime

ComplyTime: Cloud Native Compliance. Reimagined.

From Code to Compliance, Intelligently.

ComplyTime is an engineering-first, API-driven framework designed to automate and unify compliance across the modern, cloud-native landscape. For the Cloud Native Developer and DevOps Engineer, it's a solution that simplifies compliance checks, making them an integral part of your workflow rather than an added burden.

About ComplyTime

ComplyTime bridges the gap between high-level policy and technical implementation, empowering developers and securing your entire product portfolio. We believe that effective compliance automation must be built on a foundation that respects and integrates with your existing workflows.

Our Philosophy: Engineering-First

We believe that effective compliance automation must be built on a foundation that understands and respects developer workflows.

  • Engineering-First: We focus on machine-readable data for "compliance-as-code," moving beyond traditional, document-centric models.
  • Built for Automation: Our architecture is designed for the ephemeral, API-driven nature of cloud-native systems, allowing for programmatic interaction with compliance data.
  • Flexible and Extensible: ComplyTime is scanner-agnostic and multi-standard, ensuring it remains relevant and adaptable to various compliance frameworks.

Project Architecture

ComplyTime is built on a foundation of modern, microservice-based components designed for flexibility and scale.

  • complyctl: A CLI tool providing a consistent compliance foundation for platforms like RHEL.
  • complyscribe: A key component of our pluggable framework, this service acts as a compliance-to-policy (C2P) engine, designed to be extensible for various compliance frameworks, not only OSCAL.
  • complybeacon: A observability toolkit leveraging OpenTelemetry to simplify audit logging and evidence collection in distributed environments like Kubernetes.
  • complytime-demos: A collection of demonstrations and examples for using the ComplyTime framework.

We leverage powerful, targeted open source components to achieve our goals. For instance, we utilize oscal-sdk-go and compliance-to-policy-go, sub-projects of OSCAL-Compass that align with our engineering-first, multi-standard vision.

Community & Contributing

We are committed to the open source community. All the information you need to get started is in our community repository.

  • How to Contribute: Check out our Contributing Guide to learn how to submit your first pull request, find an issue to work on, and understand our development process.
  • Community Standards: Our Code of Conduct outlines the standards we uphold to maintain a welcoming and inclusive environment for everyone.
  • Project Governance: Read our Governance document to understand our project roles and decision-making processes.

The Road Ahead

Our vision is to establish ComplyTime as the definitive framework for modern, automated compliance. Our roadmap includes:

  • Deepening Cloud-Native Integration: Enhancing our integration with core cloud-native technologies, including StackRox and OpenTelemetry.

Popular repositories Loading

  1. complyctl complyctl Public

    A command-line tool for streamlining end-to-end compliance workflows on local systems.

    Go 28 15

  2. complyscribe complyscribe Public

    A workflow automation tool for compliance content authoring

    Python 20 17

  3. complytime-demos complytime-demos Public

    A repository to hold automation and examples used to demo ComplyTime features.

    Jinja 3 10

  4. creme-brulee creme-brulee Public template

    2 2

  5. complytime-collector-components complytime-collector-components Public

    A policy-driven observability toolkit for compliance evidence collection

    Go 2 9

  6. compliance-to-policy-go compliance-to-policy-go Public

    Forked from oscal-compass/compliance-to-policy-go

    Fork of Compliance-to-Policy (C2P) provides the framework to bridge the gap between compliance and policy administration in Go.

    Go 1

Repositories

Showing 10 of 20 repositories
  • org-infra Public

    Repository for reusable workflows, shared configurations, and templates used in ComplyTime org.

    complytime/org-infra’s past year of commit activity
    Python 0 Apache-2.0 4 1 4 Updated Jan 6, 2026
  • complytime-collector-components Public

    A policy-driven observability toolkit for compliance evidence collection

    complytime/complytime-collector-components’s past year of commit activity
    Go 2 Apache-2.0 9 8 16 Updated Jan 6, 2026
  • gemara2oscal Public

    A transpiler for converting the gemara logical model to OSCAL

    complytime/gemara2oscal’s past year of commit activity
    Go 1 Apache-2.0 4 3 1 Updated Jan 5, 2026
  • gemara-mcp-server Public

    A MCP server for automating the authoring of GRC Risk Assessment documentation in gemara.

    complytime/gemara-mcp-server’s past year of commit activity
    Go 0 Apache-2.0 3 0 0 Updated Jan 5, 2026
  • baseline-demo Public

    A demonstration of C2P to assess a project against the OSPS Baseline

    complytime/baseline-demo’s past year of commit activity
    Open Policy Agent 0 Apache-2.0 8 8 0 Updated Jan 5, 2026
  • complyscribe Public

    A workflow automation tool for compliance content authoring

    complytime/complyscribe’s past year of commit activity
    Python 20 Apache-2.0 17 21 (5 issues need help) 3 Updated Jan 5, 2026
  • cac-content Public Forked from ComplianceAsCode/content

    Security automation content in SCAP, Bash, Ansible, and other formats

    complytime/cac-content’s past year of commit activity
    Shell 1 781 0 2 Updated Jan 5, 2026
  • .github Public

    A repository to apply peribolos to manage organization complytime.

    complytime/.github’s past year of commit activity
    Go 0 11 1 1 Updated Dec 26, 2025
  • complyctl Public

    A command-line tool for streamlining end-to-end compliance workflows on local systems.

    complytime/complyctl’s past year of commit activity
    Go 28 Apache-2.0 15 4 2 Updated Dec 24, 2025
  • community Public

    Community-related documents for the ComplyTime project.

    complytime/community’s past year of commit activity
    0 Apache-2.0 6 0 3 Updated Dec 18, 2025

Most used topics

Loading…