About

Open source, by design.

Secfoo is an open-source orchestrator for context-based security review — built so security work runs through the same coding-agent CLI your team already has open, instead of a separate portal.

Our approach

Honest about what a report can and can't know

The program dashboards are built from what a report can state at review time and the exceptions you record by hand — not a persistent findings-lifecycle system with manually-updated statuses. Where the data can't support a claim, Secfoo says so rather than guessing.

  • Coverage means "has an assessment" — there's no separate system registry.
  • CCM conformance is scored at the 17-domain level, not per individual control.
  • Post-build findings are recorded by hand — no report can know what it missed.
  • Reports from before a contract version show zeros or hatching, never a guess.

Open source, self-hosted

Secfoo is licensed under MIT. Reports and the dashboard run entirely on your machine — the mermaid diagram renderer, once vendored, serves locally too, so the dashboard never calls out to a CDN while you're reading a report built from a possibly untrusted repository.

MIT Self-hosted

Get in touch

Questions, feedback, or an activity you'd like to see in the catalog.

info@secfoo.com github.com/secfoo-com/secfoo
Contact

Send us a message

Questions, feedback, or an activity you'd like to see in the catalog. Goes straight to info@secfoo.com.

10–5000 characters.

By submitting, you agree to our privacy notice. We use your details only to respond to this message.

Read the source, run it yourself

No account, no SaaS dependency — install it and point it at a target.

View on GitHub