Open Source Contributions

Industry grade cyber security software, developed and provided free of charge.

5 open source projects

Home  /  Contributions

Thousands of companies worldwide have adopted the software below.


Small teams and large enterprises alike, running it on their own hardware. Not a trial, not a freemium tier, not a seat count. The whole product, in production, at no cost.

Our Mission

Industry grade cyber security software is developed and provided free of charge, to help make cyber security available for all organizations, with small or large pockets.

Good security should not be a budget line that only the Fortune 500 can carry. The tools on this page are the same class of software that commercial vendors license for thousands of dollars per node, per seat, per year. We build them, we run them ourselves, and we give them away.

Every project here is free, open source, and self hosted. No per seat fees, no per node fees, no trial clock, and no sales call. Download it, read the source, run it on your own hardware, and change it to fit the way your organization works.

A nonprofit, a school district, a county government, and a twelve person startup all face the same attackers as a bank. They rarely have the same budget. Each of these projects started because an organization we work with needed a capability it could not afford, so we built it and then released it for everyone else in the same position.

The projects cover the unglamorous foundations: knowing your vendor risk, finding the secrets your developers leaked, keeping poisoned packages out of your builds, staying online when a server dies, and keeping your database available. These are the things that break first and hurt longest.

Security Gaps, and the Products That Fill Them

Most organizations do not have a security problem so much as a set of specific, named gaps, each one normally closed by a commercial product with a five figure annual price tag. Below is the honest mapping: the gap, why it hurts, and which of our projects closes it.

Security Gap What Goes Wrong Without It Product
DevSecOps and Application Security Testing Secrets are committed and never found, vulnerable code ships, and nobody is scanning the branches that are not main. Static analysis is bolted on after release instead of running on every commit. Git Code Review
Secrets Detection and Credential Validation An API key leaked three years ago is still live. Teams drown in thousands of unvalidated findings and stop reading the report. Git Code Review
Secure Software Artifactory and Supply Chain Control Builds pull straight from public registries, so a typosquatted or back-doored package reaches CI and developer laptops with nothing in the way, and there is no means of pulling it back. ForgeRepo
Dependency Confusion and Package Approval An attacker publishes your internal package name publicly and your build prefers it. Nothing reserves your namespaces, and no one approves what enters the pipeline. ForgeRepo
Dependency and SBOM Inventory When the next critical CVE lands, you cannot answer the only question that matters: which of our applications and branches actually use that library? Git Code Review, ForgeRepo
SSL and TLS Certificate Lifecycle Management A certificate expires on a Saturday and takes production down. In a cluster, renewal has to happen on every node, and the one that gets missed is the outage. Failover LB
Post Quantum Encryption Readiness Traffic captured today is decrypted later, once quantum capability arrives. Classical only key exchange leaves everything recorded now exposed in retrospect. Failover LB
Web Application Firewall Injection, traversal, and bot traffic hit the application directly, with no inspection layer and no virtual patch available while a fix is being written. Failover LB
High Availability, Load Balancing, and DNS Failover One server failing takes the service with it. Configuration drifts between nodes, dead backends keep receiving traffic, and there is no automated path to the second site. Failover LB
Secure and Highly Available SQL Clustering The database is a single point of failure, replication is unmonitored until it has silently stopped, and node to node traffic crosses the network in the clear. MySQL Cluster
Encrypted Node to Node Transport Cluster replication and backend connections ride untrusted networks without a private, encrypted tunnel between them. Failover LB, MySQL Cluster
Risk and GRC Program Management Controls live in a spreadsheet, the same evidence is gathered from scratch for each audit, and no one can show the current state of SOC 2, ISO 27001, PCI DSS, CMMC, HIPAA, or the NIST frameworks on demand. Fair TPRM
Risk Register and Risk Quantification Risks are rated red, amber, and green, which tells an executive nothing about how much money is at stake. FAIR (Factor Analysis of Information Risk) puts a dollar range on a risk instead of a colour. There is no single register, no owner per risk, and no record of what was accepted and why. Fair TPRM
Exposure Risk Management and Security Rating Services Nobody is watching your own or your suppliers' external attack surface. Expired certificates, exposed services, and open ports are discovered by an attacker or an insurer before they are discovered by you. Fair TPRM
Third Party and Vendor Risk Management Vendors are onboarded without assessment, questionnaires sit unanswered in inboxes, and nobody notices when a supplier's external security posture degrades after signing. Fair TPRM
Evidence, Policy, and Audit Trail Policies are scattered across shared drives, evidence is unencrypted, and there is no tamper resistant log of who changed which control and when. Fair TPRM

Priced commercially, the same coverage is typically a GRC platform, a TPRM platform, a SAST and secrets scanner, an artifact repository, a load balancer with a WAF, and a database clustering license. Each of those is a separate contract and a separate renewal. Here they are five downloads.

The Projects

How We Build and Release

Each project is self hosted by design. Your vendor assessments, your source code findings, your packages, and your database stay on infrastructure you control. Nothing phones home to us, and there is no hosted tier we are quietly steering you toward.

The source is published so you can audit it. Security software that asks for broad access to your environment should be readable by the people who install it, and every one of these projects is. Four of the five are released under the MIT license, which means you may run them, modify them, and deploy them commercially without asking anyone's permission.

These tools are also part of how we teach. HackRange students work with the same software in the mentorship program, which means the projects get exercised by people who have every reason to find the rough edges. Fixes flow back upstream, and the next organization to download it gets a better product.

Use Them, Or Help Us Improve Them

If your organization needs one of these capabilities and cannot justify a commercial contract, take the software. That is what it is for. If you find a bug, have a feature your sector needs, or want to contribute code or documentation, we would like to hear from you.