WHAT IS IT?
Probo is an open source GRC (governance, risk, compliance) platform built for engineering teams. It covers the whole cycle: risk register, control tracking, vendor risk, data privacy, access reviews, audit programs and document approval workflows. The backend is Go with PostgreSQL, and the whole thing is self-hostable.
WHY IS IT INTERESTING?
- The whole GRC cycle in one place: risks (inherent and residual scoring), controls, custom frameworks with a Statement of Applicability, audit evidence and document control.
- Multi-framework: SOC 2, ISO 27001, GDPR and HIPAA, rather than starting over for each standard.
- AI-native: Probo exposes 270+ MCP tools, letting an LLM agent drive compliance tasks (evidence collection, access reviews) directly.
- Built for engineers: a web console, but also a CLI, GraphQL and MCP APIs, so it's automatable and not just click-through.
- Vendor risk and privacy: third-party inventory, automated website assessment, DPA/BAA tracking, DPIA and processing records.
USE CASES
- Prepare a SOC 2 or ISO 27001 without committing to a closed SaaS platform.
- Centralize risks, controls and audit evidence for a security team.
- Track the risk of vendors and third-party providers.
- Automate compliance workflows via LLM agents (MCP) or n8n.
