Industry grade cyber security software, developed and provided free of charge.
5 open source projects
Home / Contributions
Small teams and large enterprises alike, running it on their own hardware. Not a trial, not a freemium tier, not a seat count. The whole product, in production, at no cost.
Industry grade cyber security software is developed and provided free of charge, to help make cyber security available for all organizations, with small or large pockets.
Good security should not be a budget line that only the Fortune 500 can carry. The tools on this page are the same class of software that commercial vendors license for thousands of dollars per node, per seat, per year. We build them, we run them ourselves, and we give them away.
Every project here is free, open source, and self hosted. No per seat fees, no per node fees, no trial clock, and no sales call. Download it, read the source, run it on your own hardware, and change it to fit the way your organization works.
A nonprofit, a school district, a county government, and a twelve person startup all face the same attackers as a bank. They rarely have the same budget. Each of these projects started because an organization we work with needed a capability it could not afford, so we built it and then released it for everyone else in the same position.
The projects cover the unglamorous foundations: knowing your vendor risk, finding the secrets your developers leaked, keeping poisoned packages out of your builds, staying online when a server dies, and keeping your database available. These are the things that break first and hurt longest.
Most organizations do not have a security problem so much as a set of specific, named gaps, each one normally closed by a commercial product with a five figure annual price tag. Below is the honest mapping: the gap, why it hurts, and which of our projects closes it.
| Security Gap | What Goes Wrong Without It | Product |
|---|---|---|
| DevSecOps and Application Security Testing | Secrets are committed and never found, vulnerable code ships, and nobody is scanning the branches that are not main. Static analysis is bolted on after release instead of running on every commit. |
Git Code Review |
| Secrets Detection and Credential Validation | An API key leaked three years ago is still live. Teams drown in thousands of unvalidated findings and stop reading the report. | Git Code Review |
| Secure Software Artifactory and Supply Chain Control | Builds pull straight from public registries, so a typosquatted or back-doored package reaches CI and developer laptops with nothing in the way, and there is no means of pulling it back. | ForgeRepo |
| Dependency Confusion and Package Approval | An attacker publishes your internal package name publicly and your build prefers it. Nothing reserves your namespaces, and no one approves what enters the pipeline. | ForgeRepo |
| Dependency and SBOM Inventory | When the next critical CVE lands, you cannot answer the only question that matters: which of our applications and branches actually use that library? | Git Code Review, ForgeRepo |
| SSL and TLS Certificate Lifecycle Management | A certificate expires on a Saturday and takes production down. In a cluster, renewal has to happen on every node, and the one that gets missed is the outage. | Failover LB |
| Post Quantum Encryption Readiness | Traffic captured today is decrypted later, once quantum capability arrives. Classical only key exchange leaves everything recorded now exposed in retrospect. | Failover LB |
| Web Application Firewall | Injection, traversal, and bot traffic hit the application directly, with no inspection layer and no virtual patch available while a fix is being written. | Failover LB |
| High Availability, Load Balancing, and DNS Failover | One server failing takes the service with it. Configuration drifts between nodes, dead backends keep receiving traffic, and there is no automated path to the second site. | Failover LB |
| Secure and Highly Available SQL Clustering | The database is a single point of failure, replication is unmonitored until it has silently stopped, and node to node traffic crosses the network in the clear. | MySQL Cluster |
| Encrypted Node to Node Transport | Cluster replication and backend connections ride untrusted networks without a private, encrypted tunnel between them. | Failover LB, MySQL Cluster |
| Risk and GRC Program Management | Controls live in a spreadsheet, the same evidence is gathered from scratch for each audit, and no one can show the current state of SOC 2, ISO 27001, PCI DSS, CMMC, HIPAA, or the NIST frameworks on demand. | Fair TPRM |
| Risk Register and Risk Quantification | Risks are rated red, amber, and green, which tells an executive nothing about how much money is at stake. FAIR (Factor Analysis of Information Risk) puts a dollar range on a risk instead of a colour. There is no single register, no owner per risk, and no record of what was accepted and why. | Fair TPRM |
| Exposure Risk Management and Security Rating Services | Nobody is watching your own or your suppliers' external attack surface. Expired certificates, exposed services, and open ports are discovered by an attacker or an insurer before they are discovered by you. | Fair TPRM |
| Third Party and Vendor Risk Management | Vendors are onboarded without assessment, questionnaires sit unanswered in inboxes, and nobody notices when a supplier's external security posture degrades after signing. | Fair TPRM |
| Evidence, Policy, and Audit Trail | Policies are scattered across shared drives, evidence is unencrypted, and there is no tamper resistant log of who changed which control and when. | Fair TPRM |
Priced commercially, the same coverage is typically a GRC platform, a TPRM platform, a SAST and secrets scanner, an artifact repository, a load balancer with a WAF, and a database clustering license. Each of those is a separate contract and a separate renewal. Here they are five downloads.
Each project is self hosted by design. Your vendor assessments, your source code findings, your packages, and your database stay on infrastructure you control. Nothing phones home to us, and there is no hosted tier we are quietly steering you toward.
The source is published so you can audit it. Security software that asks for broad access to your environment should be readable by the people who install it, and every one of these projects is. Four of the five are released under the MIT license, which means you may run them, modify them, and deploy them commercially without asking anyone's permission.
These tools are also part of how we teach. HackRange students work with the same software in the mentorship program, which means the projects get exercised by people who have every reason to find the rough edges. Fixes flow back upstream, and the next organization to download it gets a better product.
If your organization needs one of these capabilities and cannot justify a commercial contract, take the software. That is what it is for. If you find a bug, have a feature your sector needs, or want to contribute code or documentation, we would like to hear from you.