If you are tracking IT risks in spreadsheets, managing support tickets across random channels, storing policies in multiple folders, and dreading your next IT audit, you are not alone.
Audit prep is usually frustrating and slow because daily IT work happens completely separately from compliance. When audit season hits, teams waste days taking manual screenshots, going through old emails, and chasing paperwork just to prove they follow their own policies.
Up until now, growing IT teams were forced to choose between ad-hoc spreadsheets or expensive enterprise software.
That is why I am excited to introduce TSI Compass.
TSI Compass is a beginner-friendly, self-hosted open-source IT GRC and ITSM platform. It connects your compliance needs (policies, risk registers, controls, audits, incidents, and reports) directly to your helpdesk tickets, change requests, and asset inventory. Everything sits behind a clean web console with a tamper-proof log for every action.
We designed TSI Compass for teams taking their first steps into compliance, making sure your everyday IT tasks satisfy auditors automatically. Instead of forcing you to manage two separate systems, TSI Compass ties your daily IT service management directly to your compliance framework with the following capabilities:
- Automated Evidence & Audit Prep: Access pre-loaded libraries aligned with ISO 27001 and SOC 2. The platform automatically prompts control owners to upload proof on a recurring schedule, and lets you export clean PDF or Excel reports for auditors in one click.
- Connected IT Operations: Manage helpdesk tickets, code and infrastructure changes, and keep track of hardware and vendor licenses in one place. If a support ticket turns out to be a security issue, you can escalate it to a formal incident with a single click.
- Practical Risk & Vulnerability Management: Score raw inherent risk against remaining residual risk using visual matrices. Centralise vulnerabilities from pen tests or security scans, assign remediation owners, and track SLA deadlines.
- Complete Audit Logging & Access Control: Map precise permissions for your team and record every policy change, risk update, and system action to an immutable audit trail.
- Open API & Automation: Use API Key authentication to push CI/CD vulnerability scans, sync third-party inventories, or stream infrastructure alerts straight into your compliance log.
By bringing risk, compliance, and daily IT operations into a single environment, TSI Compass makes audit readiness a natural part of how you run your business. Check out GitHub and the Functional Walkthrough to see it in action.