Open-source GRC

Manage cyber risk, compliance and your ISMS from one platform

RiskPilot connects risk assessments, controls, action plans, audits, third parties, resilience and ISMS documentation in a secure multi-tenant platform.

Application language notice

The RiskPilot software interface is currently available in French only. An English application interface is planned for upcoming versions. This English website documents the current product without implying that the application UI is already translated.

Available today

A connected GRC workflow

RiskPilot helps security and compliance teams replace scattered spreadsheets with governed, traceable records.

Scope and assets

Structure scopes, assets, threats, vulnerabilities and security controls.

Risk management

Assess inherent, current and residual risk on a configurable 5 × 5 matrix.

Action plans

Track ownership, priorities, deadlines, costs, evidence, Kanban and calendar views.

Compliance

Manage frameworks, assessments, maturity, evidence, control tests and versioned SoA.

Audits and CAPA

Plan audit engagements, findings, root causes and independent effectiveness reviews.

Third parties

Record criticality, contracts, dependencies, exit plans and supplier campaigns.

Resilience

Handle incidents, BIA, RTO, RPO, BCP, DRP and continuity exercises.

ISMS documents

Version, approve and share controlled documents through tenant-aware ACLs.

Connected records

From operational evidence to executive decisions

Scope & assetsRisksActionsCompliance & audits360° view

Assets feed risk scenarios; risks generate treatment actions; controls link to requirements; evidence supports compliance and audits; incidents connect to assets, third parties, risks and actions.

Security by design

The backend remains the security authority

RiskPilot helps organisations structure compliance programmes. It is not presented as ISO 27001 certified.

Tenant isolation
API-side RBAC
TOTP MFA
Short-lived JWT
Rotating refresh tokens
Revocable sessions
Encrypted secrets
Document ACLs
Architecture

React frontend, Symfony authority

Nginx routes the React/TypeScript SPA and Symfony/PHP-FPM API. PostgreSQL stores business data, Redis transports Messenger jobs, and documents remain in private storage.

Browser → Nginx
  ├─ React / TypeScript / Vite
  └─ Symfony API / PHP-FPM
      ├─ PostgreSQL
      ├─ Redis / Messenger
      └─ Private document storage
AGPL-3.0-or-later

Open source and self-hostable

Deploy with Docker Compose, inspect the source code and contribute through issues and pull requests.

Open English documentation