Pour voir la démonstration complète en vidéo, consultez la section "Support & Contact" ci-dessous.
OpenRisk is a modern, enterprise-grade Risk Management Platform that transforms how organizations identify, assess, mitigate, and monitor risks. Built with a scalable microservices architecture, OpenRisk enables teams to move beyond spreadsheets and legacy systems into a seamless, automated risk management experience.
OpenRisk allows every organization to:
- β Identify IT & security risks
- β Score & Prioritize risks based on impact and probability
- β Track mitigation plans and action items
- β Monitor trends in real-time with interactive dashboards
- CTO & CISO - Strategic risk oversight and compliance
- DevSecOps - Integrated security in CI/CD pipelines
- Security Analysts - Risk assessment and investigation
- Compliance Teams - Audit trails and governance
- β‘ Automated Risk Assessment - Reduce manual evaluation time
- π Interactive Dashboards - Real-time risk visualization
- π³ Easy Deployment - Docker & Kubernetes ready
- π Enterprise Security - RBAC, SSO, audit logging
- π Scalable Architecture - Microservices-ready
- π² Risk Assessment - Comprehensive risk identification and scoring
- π‘οΈ Mitigation Tracking - Monitor and track risk mitigations in real-time
- π Enterprise Security - RBAC, audit logging, OAuth2/SAML2 SSO
- ποΈ Asset Inventory - Track assets, their criticality and dependencies
- π Compliance Management - Manage controls, evidence and compliance reports
- πΆ Financial Risk Quantification - Quantify exposure using SLE, ARO, ALE and ROSI
The Financial Quantification dashboard (/analytics/financial), shown on the built-in
demonstration dataset (DEMO_MODE=true), not on a customer's data. Available from the
Pro plan.
Each risk is quantified FAIR-style: single loss expectancy (SLE), annual rate of occurrence
(ARO), annualised loss expectancy (ALE = SLE Γ ARO), residual ALE and return on security
investment (ROSI). Amounts are computed in XAF and presented in XAF, XOF, EUR, USD, NGN, MAD,
GHS or ZAR. The dashboard aggregates them into one view for the CFO and the CISO
(backend/pkg/crq).
| Catalogue | Source instrument | Controls |
|---|---|---|
| COBAC (CEMAC): internal control of credit institutions | Règlement COBAC R-2016/04 | 45 |
| BCEAO / UEMOA: payment systems | Règlement n°15/2002/CM/UEMOA | 35 |
| ANTIC (Cameroon): cybersecurity | Loi nΒ°2010/012 | 25 |
Every control cites the article it derives from (backend/pkg/compliance/catalog_*.go). The
control descriptions are synthesised rewordings, not the regulatory text. Have them reviewed
by a qualified professional before relying on them in a real audit.
10 collectors: AWS, Azure, Google Cloud, Kubernetes, Docker, VMware vCenter, Active
Directory, Microsoft 365, GitHub and GitLab. Plus an on-premise Agent (nmap) for networks
the platform cannot reach directly (backend/internal/scanner).
- Docker & Docker Compose
- Git
- 4GB RAM, 2GB disk space
git clone https://github.com/opendefender/OpenRisk.git
cd OpenRisk
./install.shThat is the whole procedure. The installer generates the RS256 keypair and every secret, starts PostgreSQL, Redis, the API and the frontend, waits for health, and prints the credentials of the administrator it created:
[openrisk] β
OpenRisk is up.
[openrisk] β’ App: http://localhost:3000
[openrisk] β’ API: http://localhost:8080/api/v1
[openrisk] Sign in with:
[openrisk] β’ Email: admin@opendefender.io
[openrisk] β’ Password: <32 random characters, different on every install>
No file is edited by hand at any point. Re-running the installer keeps your configuration, your keys and that account.
A CI job (selfhost-install.yml) runs
this flow monthly on a fresh Ubuntu 24.04 VM and signs in with the printed
credentials. It has not yet had a green run β the defects that kept it red
are fixed in #328; the flow was verified by hand on a clean stack on 2026-09-09.
Full guide, including what a self-hosted instance is entitled to, upgrades and backups: docs/SELF_HOSTING.md.
Working on OpenRisk itself (hot reload, test databases, seeded fixtures) is a different setup: see docs/LOCAL_DEVELOPMENT.md.
OpenRisk ships no default password. The first administrator gets the
INITIAL_ADMIN_PASSWORD you set, or one generated on first boot and written
to a 0600 file, never to the logs (see docs/SELF_HOSTING.md).
The compose files refuse to start without their database and cache passwords.
An instance first started before this change may still have admin123 on
admin@opendefender.io: the backend logs a SECURITY WARNING at boot until
the password is changed.
To report a vulnerability, see SECURITY.md.
Password Requirements (enforced server-side at registration):
- Minimum 12 characters
- At least three of: lowercase, uppercase, digits, symbols
- Common and predictable passwords are rejected
- Preferably generated with a password manager (1Password, Bitwarden, etc.)
| Component | Technology | Version |
|---|---|---|
| Language | Go | 1.25.4 |
| Framework | Fiber | v2.52 |
| Database | PostgreSQL | 16 |
| ORM | GORM | v1.31 |
| Testing | Testify | v1.11 |
| Architecture | CLEAN | Domain-Driven |
| Component | Technology | Version |
|---|---|---|
| Framework | React | 19.2.0 |
| State | Zustand | 5.0.8 |
| Styling | Tailwind CSS | 3.4.0 |
| Forms | React Hook Form | 7.66 |
| Routing | React Router | 7.9.6 |
| Charts | Recharts | 3.5.0 |
| Component | Technology | Purpose |
|---|---|---|
| Containerization | Docker | Application packaging |
| Orchestration | Kubernetes | Production deployment |
| Charts | Helm | K8s configuration |
| CI/CD | GitHub Actions | Automated testing & deployment |
| Caching | Redis | Session & cache layer |
The following capabilities are available in the product today:
- Authentication, role-based access control and API token management
- Risk register, scoring, lifecycle management and mitigation tracking
- Asset inventory, criticality and dependency mapping
- Compliance frameworks, controls, evidence and PDF reporting
- Incident register, incident timeline and source ingestion
- Vulnerability management and asset discovery
- Financial risk quantification (FAIR-style SLE, ARO, ALE and ROSI) β
- Vendor risk management: vendor register, questionnaires, assessments and reminders β
- Governance workflows, immutable audit records, delegations and approvals
- Security automation rules, SLA tracking and notification workflows
β Gated by plan. A self-hosted install starts on the Free plan, which does not
unlock these. The plans and what each one grants are described in
docs/PRICING.md; the enforced matrix lives in
backend/pkg/entitlements/entitlements.go.
The detailed delivery status and its supporting evidence are maintained in
ROADMAP.md. A capability is listed here only when it is available to a
user; planned work belongs in the roadmap below.
| Document | Purpose |
|---|---|
| TESTING_GUIDE.md | Complete testing procedures & execution guide |
| TESTING_COMPLETION_SUMMARY.md | Phase 5 testing overview & metrics |
| OPTIMIZATION_REPORT.md | Performance optimization strategies & analysis |
| PERFORMANCE_TESTING.md | k6 load testing configuration & guide |
| LOCAL_DEVELOPMENT.md | Setup guide for development environment |
| API_REFERENCE.md | Complete API endpoint documentation |
| KUBERNETES_DEPLOYMENT.md | K8s deployment instructions |
| PRODUCTION_RUNBOOK.md | Production operations guide |
| SAML_OAUTH2_INTEGRATION.md | SSO integration guide |
| ADVANCED_PERMISSIONS.md | RBAC & permissions documentation |
For more documentation, see the docs directory.
docker compose up -d# See docs/STAGING_DEPLOYMENT.md
./scripts/deploy-kubernetes.sh --environment staging# See docs/PRODUCTION_RUNBOOK.md
helm install openrisk ./helm/openrisk \
-f helm/values-prod.yaml \
--namespace openriskIntegration Tests - Database-level testing with PostgreSQL & Redis
go test -v ./tests/integration_test.go -timeout 30m- 8 test cases covering CRUD, relationships, concurrency
- Query performance validation
- Audit logging verification
E2E Tests - User workflows in real browsers with Playwright
npx playwright test [--headed] [--project=chromium|firefox|webkit]
npx playwright show-report- 12+ test scenarios across 5 browsers/viewports
- Authentication, risk management, custom fields
- Mobile responsiveness (iPhone 12, Pixel 5)
- Performance metrics validation
Security Tests - Vulnerability scanning and protection verification
go test -v ./tests/security_test.go -timeout 30m- CSRF protection, SQL injection prevention
- XSS protection, rate limiting, auth bypass detection
- Security headers validation, CORS verification
Performance Benchmarks - Throughput and latency measurements
go test -v -bench=. ./tests/performance_benchmark_test.go -timeout 30m- 9 benchmarks covering all critical operations
- Cache vs database performance comparison
- Concurrent operation handling
Docker Compose Testing - Isolated test environment
docker-compose -f docker-compose.test.yaml up -d
docker-compose -f docker-compose.test.yaml run integration_tests
docker-compose -f docker-compose.test.yaml run security_tests
docker-compose -f docker-compose.test.yaml run performance_tests
docker-compose -f docker-compose.test.yaml run e2e_tests
docker-compose -f docker-compose.test.yaml down -v- 30+ test cases across all test suites
- 2,707 lines of test code
- 11 security categories (OWASP coverage)
- 9 performance benchmarks (all targets met)
- 5 browser/viewport combinations
See TESTING_GUIDE.md and TESTING_COMPLETION_SUMMARY.md for detailed testing documentation.
OpenRisk provides a comprehensive REST API with 37+ endpoints:
POST /api/risks - Create risk
GET /api/risks - List risks
GET /api/risks/:id - Get risk details
PATCH /api/risks/:id - Update risk
DELETE /api/risks/:id - Delete risk
POST /api/mitigations - Create mitigation
GET /api/mitigations - List mitigations
PATCH /api/mitigations/:id - Update mitigation
POST /api/mitigations/:id/sub-actions - Add checklist item
PATCH /api/mitigations/:id/sub-actions/:aid - Toggle completion
POST /auth/login - JWT authentication
POST /auth/register - User registration
POST /auth/oauth2/:provider - OAuth2 login
POST /auth/saml/acs - SAML assertion endpoint
GET /api/tokens - List API tokens
POST /api/tokens - Create new token
DELETE /api/tokens/:id - Revoke token
GET /rbac/roles - List roles
POST /rbac/roles - Create role
PUT /rbac/roles/:id - Update role
DELETE /rbac/roles/:id - Delete role
GET /rbac/permissions - List permissions
GET /rbac/tenants - List tenants
POST /rbac/tenants - Create tenant
GET /rbac/tenants/:id/stats - Tenant statistics
DELETE /rbac/tenants/:id - Delete tenant
GET /api/analytics/dashboard - Dashboard metrics
GET /api/analytics/trends - Risk trends
GET /api/reports - List reports
POST /api/reports/export - Export risks/mitigations
See API_REFERENCE.md for complete endpoint documentation with examples.
OpenRisk implements enterprise-grade security:
- Authentication: JWT tokens (RS256) with expiration and JTI blacklist
- Authorization: RBAC with permission matrices and resource-level granularity
- Password Hashing: Argon2id (m=64MB, t=3, p=4) - never SHA256 or bcrypt alone
- Encryption: AES-256-GCM for sensitive data at rest
- Audit Trail: Complete audit logging for all operations (append-only)
- SSO: OAuth2 (Google, GitHub) and SAML2 support
- Rate Limiting: Per-IP and per-tenant quotas across the API, with a stricter throttle on credential endpoints
- Security Headers: CSP, HSTS, X-Frame-Options, Referrer-Policy and nosniff
- Input Validation: Server-side request validation (go-playground/validator); Zod on the frontend
- Default Credentials: Never hardcoded - always use environment variables
- Secrets Management: Support for external secret managers (Vault, AWS Secrets Manager)
- Rotate credentials and API keys regularly
- Use strong passwords (12+ characters, mixed case, numbers, symbols)
- Enable MFA/2FA for all user accounts
- Keep dependencies updated regularly
- Run security scans (TruffleHog, Snyk, Trivy)
- Monitor audit logs for suspicious activity
See ADVANCED_PERMISSIONS.md and SECURITY.md for detailed security documentation.
OpenRisk includes keyboard shortcuts to help you work faster. Below is a complete list of available shortcuts:
| Shortcut | Action | Context |
|---|---|---|
| βK or Ctrl+K | Open global search | Anywhere in the app |
| βN or Ctrl+N | Create new risk | Dashboard and Risks page |
| Esc | Close modal/dialog | Any open modal or dialog |
| Shortcut | Action | Context |
|---|---|---|
| β | Previous search result | In search suggestions |
| β | Next search result | In search suggestions |
| Enter | Select search result | Search suggestions open |
| Esc | Close search dropdown | Search suggestions open |
| Shortcut | Action | Context |
|---|---|---|
| Esc | Close risk details | Risk details panel open |
| Esc | Close edit modal | Risk editing modal open |
- Search Tip: Use βK / Ctrl+K from anywhere to quickly search for risks, assets, or mitigations
- Quick Create: Press βN / Ctrl+N on the dashboard to rapidly create new risks
- Navigation: Use arrow keys in search results to navigate without your mouse
- Mobile: These shortcuts work best on desktop/laptop keyboards
- Edit Last Risk - βE / Ctrl+E
- Filter Results - βF / Ctrl+F
- Delete Selected - βD / Ctrl+D
- Focus Search - / key
- Settings - β, / Ctrl+,
We welcome contributions from the community! Please see CONTRIBUTING.md for guidelines.
- Fork the repository
- Create a feature branch (
git checkout -b feature/AmazingFeature) - Commit your changes (
git commit -m 'Add AmazingFeature') - Push to the branch (
git push origin feature/AmazingFeature) - Open a Pull Request
OpenRisk is open-core:
- Community Edition (the core GRC platform) β GNU AGPL v3.0 (
LICENSE). Free to self-host, study, modify and redistribute. The AGPL's network clause means anyone running a modified core as a hosted service must publish their changes under the AGPL. - Enterprise Edition (advanced SSO, AI copilot, premium connectors & SOAR,
multi-organisation management) β OpenRisk Commercial License
(
LICENSE.commercial), used under a paid subscription. - The design system (
frontend/design-system/andfrontend/src/shared/ds/) β Apache License 2.0 (frontend/design-system/LICENSE). Deliberately permissive: the tokens and primitives are meant to be copied and extended, including by commercial code. Attribution lives inNOTICE. Apache-2.0 grants no trademark rights β the OpenRisk and OpenDefender names and logos are not licensed by it.
Every source file declares its edition via its SPDX-License-Identifier header
(AGPL-3.0-only, LicenseRef-OpenRisk-Commercial or Apache-2.0). The
authoritative boundary between the three is LICENSING.md.
For commercial licensing: licensing@opendefender.io
- GitHub Issues: Report bugs or request features
- Discussions: Join community discussions
- Security: See SECURITY.md for security vulnerability reporting
Phase 6C Pre-Launch Audit (March 10, 2026) - Complete project assessment before SaaS deployment:
-
π COMPREHENSIVE_AUDIT_REPORT.md - Executive summary with 8 analysis dimensions:
- Performance Analysis (Score: 8/10)
- Architecture & Design Patterns (Score: 9/10)
- Security Audit (Score: 9/10)
- Code Quality Assessment (Score: 8/10)
- Documentation Review (50+ files)
- Testing Coverage (28 test files, ~40%)
- Dependency Analysis (50+ total dependencies)
- Zero AI/ML patterns detected β
-
π― RISK_REGISTER_FEATURES_ANALYSIS.md - Core feature verification:
- β 13/13 Risk Register features confirmed present
- β All 4 visualization types implemented
- β Custom fields & templates working
- β Bulk operations (UPDATE, DELETE, ASSIGN, EXPORT)
- β Audit trail & timeline tracking
- β Search, filtering & sorting
- Status: 95% COMPLETE & PRODUCTION READY
-
π ANALYSIS_INDEX.md - Navigation hub for all audit documents with quick metrics
-
β COMPLETION_SUMMARY.md - Final verdict & next steps
- Implementation: Complete typeahead hook with fuzzy matching algorithm
- Features:
- Keyboard shortcuts (Cmd+K, Cmd+/, ββ, Enter, Esc)
- Fuzzy match scoring (0-1 relevance ranking)
- Recent searches (localStorage-backed)
- Command palette with global actions
- Status: β Production-ready
- Documentation: ADVANCED_TYPEAHEAD_IMPLEMENTATION.md
The items below are not available in the product today. Quarters are planning
targets, not commitments; the authoritative status remains
ROADMAP.md.
- Policy Management
- Public Trust Center
- Business Continuity (BCP/PCA-PRA)
- Security Awareness Training
- Access Review & Certification
- Sensitive Data Discovery
- Risk Digital Twin (simulation)
- Attack Path Graph
- Collaborative War Room β live collaboration. The incident War Room screen exists and shows a real incident's timeline; the roster, tasks and chat are not backed by a collaboration service yet.
OpenRisk is developed and maintained by the OpenDefender community.
- π Check the documentation
- π Search existing issues
- π¬ Ask in discussions


