OFFLINE GRC · COMMUNITY EDITION
Compliance data this sensitive should never leave your network.
Risk registers, audit findings, incident reports. These documents describe exactly where your organisation is weakest. RaptorGRC is a Governance, Risk & Compliance platform that runs entirely inside your own network as a container, in whatever jurisdiction your data has to stay. Nothing phones home, ever. Community Edition is free, and you get the complete platform, every module, nothing held back.
$ docker compose up · on-premise · offline licence activation
WHO IT'S FOR
For any organisation that can't let compliance data leave the building.
Small and medium businesses
The complete GRC programme without the five-figure platform licence.
Healthcare, finance and legal
Regulated records and audit evidence stay under your control, in your jurisdiction.
Defence, public sector and critical infrastructure
Sovereignty by design. Runs fully air-gapped, with no outbound calls unless you configure one.
Anyone who can't use SaaS for this
If your compliance data can't sit in a vendor's cloud, this was built for you.
Built in the UK by a working GRC practitioner. Delivered as a container you control.
WHAT'S INSIDE
Your whole GRC programme, in one container.
Risk register
Maintain risk registers with heat-map visualisation, inherent and residual scoring, and treatment plans. Link risks to controls, assets and incidents, all stored on your own servers.
Compliance & incident registers
Track compliance obligations, evidence and approvals with full version history. Log incidents, manage response and record post-incident reviews, with every record auditable and entirely under your control.
Posture & maturity dashboards
See your whole compliance posture at a glance: NIST CSF 2.0 scorecards from Govern to Recover, a coverage heatmap across every category, and one-click gap analysis showing where to focus next. NCSC CAF (Achieved / Partially / Not Achieved) and CMMC (Levels 1–3) maturity dashboards follow the same pattern.
Command centre dashboard
One screen for the whole programme, covering open risks, compliance status, active incidents and overdue actions. It's the at-a-glance overview your steering meetings actually need.
Incident command, end to end
Triage incidents with severity and status at a glance, declare a major incident and put a named commander in charge, then drive response actions to completion while time-to-respond, contain and resolve tick in real time. Legal hold, custody trail and an AI-suggested response playbook are one click away.
Regulatory reporting clocks
When an incident lands, RaptorGRC works out which reporting regimes apply — NIS2, UK GDPR, DORA and any custom regime you define — and starts the clocks. Early-warning, notification and final-report deadlines count down in real time, every regulator submission is recorded against the incident, and missed deadlines are flagged before they happen, not after.
One task board for everything
Every actionable item across the platform — tasks, risk actions, incident actions, POA&M milestones, delivery-plan steps — on one kanban board. Swimlanes by source, priorities and due dates on every card, and role-pool tasks your team can claim. Drag between columns or reassign in place.
The same work, on a timeline
Flip the board to a gantt view: planned start to due date for every piece of work, overdue bars in red, a today line so the room can see exactly where the programme stands. Delivery chains plot left to right, so the sequence — design review, risk assessment, supplier assessment, security testing — is visible at a glance.
Asset obsolescence, before it bites
Every asset's vendor-support and end-of-life dates, rolled up per system: what's already out of support, what's approaching end of life, what's on extended support. A support timeline shows how exposure is distributed, a bundled EOL catalogue suggests support dates for common products, and expiring assets raise tasks automatically.
Vulnerability findings, tied to systems
Import Nessus scan results or record findings manually. Every finding sits against the system and asset it affects, with CVE, CVSS score and severity — and critical findings promote straight into the risk register, so scanner output becomes governed risk instead of a spreadsheet nobody owns.
Supplier assurance on a cadence
Third-party suppliers with criticality, risk score, contract status and renewal dates, linked to the systems they support. Assurance assessments run on a cadence you set, and overdue reassessments are flagged in red — so the supplier review that always slips stops slipping.
AI-assisted framework mapping
Import your own framework and the optional AI assistant analyses each control, suggests mappings to the frameworks already in the system, and explains its reasoning. It runs on your own Ollama instance, inside your network, so no data leaves the building. You review and confirm every mapping; nothing is applied automatically. The cross-framework matrix then shows every control against every other framework, marked not applicable, partial or full.
Threat modelling on a canvas
Map a system's attack surface visually. Drop entities, processes, data stores and trust boundaries on a canvas, connect the data flows, and tag each element with its TRACE threat domain and STRIDE categories. Assign threats from the built-in TRACE taxonomy to any element or flow and score them with DREAD. Data-flow diagrams and attack trees, all stored on your own servers.
The model shown is a real RaptorGRC threat model: a multi-vector attack against an AI platform — prompt injection, RAG and training-data poisoning, model exfiltration and excessive agency — across four trust zones, with the count on each element showing its assigned TRACE threats.
From threat to risk
Once threats are assigned, the model becomes a working queue. Every threat across the model's elements and flows sits in one table — its TRACE reference, the element it affects, DREAD score and a status you drive from Identified through Mitigating to Mitigated or Accepted. When a threat warrants formal treatment, promote it straight into the risk register in one click; it carries its linked assets with it and back-links to the new risk, so a diagram on a whiteboard becomes governed risk you can actually track.
Plus the registers you'd expect:
Audit log
Activity trail, search & export
Incidents
Response, SLA, reviews
Governance
Policies & documents, versioning
Assets & Systems
Inventory, FIPS, EOL, SBOM
POA&M
Milestones, remediation tracking
Evidence
Collection, linkage, audit trail
Tasks
Owners, due dates
Controls
Assessment & framework mapping
Reporting
PDF & Excel exports
RBAC
Roles & permissions
Threat catalogue
TRACE taxonomy & analysis
Security Test Verification
Test evidence & status
Notifications
Alerts & categories
AI assistant
Optional, PII-redacting, role-scoped
WHY OFFLINE
Nothing phones home. That's the whole point.
RaptorGRC ships as a single container that runs on your infrastructure, whether that's Docker, bare metal, or your own private cloud. No vendor has access to your risk registers, audit findings or incident reports. Licence activation is offline. Paste a token and you're running, with no outbound connection required, ever.
FRAMEWORK COVERAGE
Ships with frameworks built in. Imports any other.
Built in
Bring your own
Import any framework from Excel, CSV or OSCAL, whether that's ISO 27001, HIPAA, PCI DSS, or an internal control set. If you can put it in a spreadsheet, you can load it.
Starter templates with the control identifiers are bundled for CIS Controls v8, ISO 27001 Annex A, SOC 2, Cyber Essentials and NATO/MOD, so you import the structure and add your own licensed control text.
The optional local AI suggests mappings from your framework to the ones already loaded, with a rationale for each. You review and confirm every mapping.
SUPPORT & SERVICES
The platform is free. The expertise behind it is available.
RaptorGRC Community Edition is free and stays free — there is no paid tier of the software, and no feature held back for one. What we sell is time and expertise: support agreements, training, and help standing the platform up in your own environment.
Support agreements
Guaranteed response times, named escalation, and priority handling of the issues you raise. Upgrade assistance so version moves are planned rather than improvised. Written terms you can put in front of an auditor or a board.
Training & certification
Practitioner-led training on RaptorGRC and on the frameworks it implements — NCSC CAF, NIST CSF 2.0 and DORA. Certification for teams that need to evidence competence. Delivered remotely or on site.
Configuration & onboarding
We help you stand RaptorGRC up inside your own environment, configured to how your organisation actually works: frameworks, registers, roles and reporting. We never host the platform and never hold your data — the deployment is yours throughout.
Contact us for a support agreement.
Deploy it on your own terms.
Create a free account, download the container, and activate offline.
Register / Download$ docker compose up · on-premise · offline licence activation