Fleet screenshot thumbnail

Fleet

Fleet lets IT and security teams query every device in their organization like a SQL database, using osquery to surface installed software, running processes, configurations, and vulnerabilities within seconds across macOS, Windows, Linux, iOS, Android, and ChromeOS. The Go-based server exposes a web console and REST API for centralized device management, with MDM capabilities built on nanoMDM for Apple device enrollment, configuration profiles, and remote lock or wipe. Vulnerability management cross-references installed software inventories against NVD and OVAL CVE databases, automatically flagging known vulnerabilities with severity scores and remediation guidance. Software deployment handles OS updates using Apple Declarative Device Management, Windows Update, and custom installer packages distributed through S3-compatible storage. A GitOps workflow enables infrastructure-as-code management where device policies, osquery queries, and configuration profiles live as YAML files in Git repositories, with CI/CD pipelines pushing changes through the fleetctl CLI. The fleetd agent bundle includes osquery for telemetry, Orbit for version management, and Fleet Desktop providing end users a menu bar status indicator. Integrations connect to Snowflake, Splunk, Elastic, Jira, Zendesk, Vanta, and GitHub Actions for automated compliance reporting. CIS benchmark policies verify security baselines across operating systems. Deployment requires MySQL for persistence and Redis for caching, running as Docker containers or on Kubernetes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

Deploy
Cerbos screenshot thumbnail

Cerbos

Cerbos decouples authorization logic from application code entirely, evaluating human-readable YAML policies in under one millisecond through a stateless Policy Decision Point that requires no application state synchronization or cross-network fan-out. Its custom decision engine benchmarks up to 17x faster than OPA-based alternatives. Access control policies use conditions expressed in Google's Common Expression Language, supporting role-based, attribute-based, and policy-based access control patterns including derived roles, scoped policies, and permissions-aware data filtering that pushes authorization predicates directly into database queries. The PDP exposes both gRPC and HTTP APIs with SDKs for JavaScript, Python, Go, Java, .NET, Rust, PHP, and Ruby, making integration a single function call regardless of tech stack. GitOps-native workflows treat policies as code with Git versioning, CI validation through GitHub Actions, coverage reports, breaking-change detection, and audit logs of every authorization decision for ISO27001, SOC2, and HIPAA compliance. Deployment flexibility spans Kubernetes sidecars, standalone services, systemd daemons, AWS Lambda functions, and WebAssembly-embedded PDPs that run authorization logic directly in browsers, serverless architectures, and edge devices. The Admin API manages policy lifecycle operations programmatically, while the built-in Playground and REPL provide interactive testing environments for policy authoring and debugging. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.

Deploy
Wazuh screenshot thumbnail

Wazuh

Protecting over 10,000 organizations worldwide with 16,000+ GitHub stars, Wazuh delivers enterprise-grade security operations through a fully open-source platform with zero feature gating. The unified XDR and SIEM solution deploys lightweight agents across Linux, Windows, macOS, Solaris, AIX, and HP-UX endpoints that stream security telemetry to a centralized cluster built on OpenSearch for indexing and the Wazuh Dashboard for visualization and management. Core capabilities include real-time file integrity monitoring with inotify-based detection and who-data attribution, automated vulnerability assessment that correlates software inventories against continuously updated CVE databases, Security Configuration Assessment against CIS benchmarks, rootkit detection, and log data analysis with a rules engine supporting over 3,000 built-in detection rules mapped to MITRE ATT&CK tactics and techniques. Wazuh monitors cloud infrastructure at the API level with native modules for AWS, Azure, and Google Cloud, detects container anomalies through Docker engine integration, and ingests third-party telemetry via syslog and REST APIs from sources like VirusTotal, TheHive, YARA, Suricata, and PagerDuty. Pre-built compliance dashboards and reports cover PCI DSS, HIPAA, NIST 800-53, GDPR, and TSC frameworks. Active response capabilities automatically trigger countermeasures including firewall rule updates, account lockouts, and endpoint isolation when threats are detected. The platform scales horizontally with multi-node clustering for high availability. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-2.0 licensed.

Deploy
Rocket.Chat screenshot thumbnail

Rocket.Chat

Blast off into productivity space with Rocket.Chat SIX, the ultimate team collaboration cosmos! Imagine a place where your messages, tasks, and projects all live in harmony, orbiting around your team's efficiency like a well-organized galaxy. This isn't just any old chat platform; it's a customizable universe where you're the master of your data domain, with the power to tweak, integrate, and innovate to your heart's content. Ready to provide stellar customer service? Engage with your clients in a way that's so contextually on-point, they'll feel like you're mind-reading across the cosmos. Plus, with a chat engine that's like a gravitational pull for user engagement, your app or website will become the center of your users' universe. And for the security-conscious space cadets, fear not! Rocket.Chat SIX is locked down tighter than a spaceship hatch, with end-to-end encryption and a buffet of deployment options to satisfy your security appetite. All this, hosted on RepoCloud, where the cost is as lightweight as zero-gravity. So why settle for a terrestrial tool when you can have a celestial experience? Rocket.Chat SIX: because your team deserves to collaborate in a universe that's light-years ahead!

Deploy
Comp AI screenshot thumbnail

Comp AI

Comp AI turns the months-long slog of SOC 2, ISO 27001, HIPAA, and GDPR certification into a largely automated process by connecting to your existing infrastructure and continuously collecting the evidence auditors actually ask for. Point it at your AWS account, Google Cloud project, GitHub organization, or any of 580+ supported integrations, and autonomous agents pull configuration snapshots, access logs, encryption status, and policy compliance data on a recurring schedule so your compliance posture reflects reality rather than last quarter's manual export. The AI policy engine analyzes your tech stack, team structure, and risk tolerance to generate organization-specific policies for information security, access control, incident response, data retention, and vendor management; no two companies get the same boilerplate. An open-source device agent runs on employee machines checking disk encryption, firewall status, screen lock settings, password length, and antivirus presence around the clock, flagging failures the moment they occur instead of surfacing them during an audit. Built-in penetration testing agents scan your codebase and API endpoints for vulnerabilities like SQL injection and output audit-ready reports. The vendor risk management module scores third-party services and surfaces compliance gaps before they become findings. A public trust center lets prospects verify your compliance status directly, eliminating security questionnaire bottlenecks. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.

Deploy
Mayan EDMS screenshot thumbnail

Mayan EDMS

Mayan EDMS stores, classifies, and retrieves millions of documents with automatic OCR, workflow automation, and audit-ready access controls that organizations have relied on for over a decade. Tesseract integration extracts searchable text from scanned PDFs and images in over 100 languages, transforming paper archives into instantly queryable digital collections without manual data entry. The workflow engine routes documents through approval chains using configurable state machines that trigger notifications, enforce retention policies, and maintain complete audit trails for regulatory compliance. Version tracking preserves every revision with full diff capabilities, while GnuPG digital signatures provide cryptographic proof of authenticity and tamper detection for sensitive records. Role-based permissions combined with object-level ACLs and LDAP integration ensure documents remain visible only to authorized users, down to individual file granularity. Full-text search powered by Whoosh or ElasticSearch handles advanced queries across massive document stores with faceted filtering and relevance ranking. The Django REST Framework API enables programmatic upload, metadata extraction, and workflow triggering from external systems. Beyond simple folder hierarchies, metadata schemas, document types, tags, and cabinet structures provide multi-dimensional classification tailored to how your organization actually works. Background processing through Celery handles OCR, conversion, and preview generation asynchronously, keeping the web interface responsive under heavy ingest loads.

Deploy