OSCALFlow

● Open Source

OSCALFlow

Automated OSCAL compliance documentation for GitHub repositories.

A TypeScript tool that automatically generates OSCAL-compliant compliance documentation from your GitHub repositories. Connect your repo and OSCALFlow produces machine-readable security documentation β€” ready for FedRAMP and NIST workflows.

πŸ”„ GitHub Integration

Connect to any GitHub repository. OSCALFlow analyzes your codebase and infrastructure to generate compliance documentation automatically.

πŸ“„ OSCAL Output

Produces OSCAL JSON and YAML β€” the machine-readable format required by OMB mandates and FedRAMP automation workflows.

βš™οΈ CI/CD Ready

Run in your GitHub Actions pipeline. Documentation stays up to date as your code evolves β€” no manual updates required.

πŸ—ΊοΈ Control Mapping

Automatically maps repository contents to NIST SP 800-53 controls. Understand your compliance posture as code changes.

πŸ“¦ TypeScript / Node.js

Written in TypeScript. Drop into any Node.js-capable environment. Open source and extensible.

πŸ”“ Open Source

Free, open source, and MIT licensed. Contribute, fork, extend, or deploy as part of your compliance automation pipeline.


See It in Action

Who Is This For?

πŸ—οΈ DevSecOps Teams

Automate the documentation side of DevSecOps. OSCAL output flows directly into compliance workflows without manual effort.

πŸ›οΈ Federal System Owners

OMB requires OSCAL. OSCALFlow generates it automatically from what you already have β€” your code.

πŸ’Ό ATO Package Preppers

Dramatically reduce the documentation effort for an Authorization to Operate. Baseline OSCAL artifacts ready in minutes.

Get Started