Probo

Probo

WHAT IS IT?

Probo is an open source GRC (governance, risk, compliance) platform built for engineering teams. It covers the whole cycle: risk register, control tracking, vendor risk, data privacy, access reviews, audit programs and document approval workflows. The backend is Go with PostgreSQL, and the whole thing is self-hostable.

WHY IS IT INTERESTING?

  • The whole GRC cycle in one place: risks (inherent and residual scoring), controls, custom frameworks with a Statement of Applicability, audit evidence and document control.
  • Multi-framework: SOC 2, ISO 27001, GDPR and HIPAA, rather than starting over for each standard.
  • AI-native: Probo exposes 270+ MCP tools, letting an LLM agent drive compliance tasks (evidence collection, access reviews) directly.
  • Built for engineers: a web console, but also a CLI, GraphQL and MCP APIs, so it's automatable and not just click-through.
  • Vendor risk and privacy: third-party inventory, automated website assessment, DPA/BAA tracking, DPIA and processing records.

USE CASES

  • Prepare a SOC 2 or ISO 27001 without committing to a closed SaaS platform.
  • Centralize risks, controls and audit evidence for a security team.
  • Track the risk of vendors and third-party providers.
  • Automate compliance workflows via LLM agents (MCP) or n8n.