-
Notifications
You must be signed in to change notification settings - Fork 51
Home en
coolstartnow edited this page Aug 30, 2026
·
1 revision
ISMS Builder is a self-hosted web platform for managing an Information Security Management System (ISMS). It covers the full compliance lifecycle — from policy authoring to audit evidence — for ISO 27001:2022, NIS2, GDPR/DSGVO, BSI IT-Grundschutz and other frameworks.
No cloud. No SaaS fees. Your data stays on your server.
Designed for SMEs, IT teams, and consultants who need a real ISMS tool without a five-figure vendor contract.
This project began as a working tool for a single ISMS practitioner and grew from there. It is open source because the work may be useful to others — not because it is a commercial product in disguise.
- What it is built for: a small ISMS team — often one person, sometimes a handful — that authors and maintains the documentation of a management system: policies, risks, assets, controls, evidence.
- What it expects of you: self-hosting means deployment, TLS, hardening, backups, updates, access control, and the data protection obligations for whatever you store are yours. The project ships a reasonable default configuration, not a managed service.
- What it is not: no hosted SaaS offering, no commercial support contract, no SLA, no certification against any standard, and no legal advice.
- Who maintains it: one person, alongside a full-time job. Issues and discussions are read and answered, usually within days.
- Docker: Using the image & environment variables — how to run the published GHCR image, JSON vs. PostgreSQL/MariaDB setups, every relevant environment variable, and why building your own image usually isn't necessary
- Architecture & Modules — code structure and an overview of every module
- FAQ — frequently asked questions
- Contributing — how to contribute to the project
- README — Quick Start, full feature list, screenshots
-
docs/— detailed module documentation (DE/EN/FR/NL), architecture reference, OpenAPI spec - CONTRIBUTING.md
- SECURITY.md
- Roadmap
© 2026 Claude Hecker