← MRM/Projects/AuditBoss
Compliance / Audit Working Rust · on-prem

AuditBoss

Turn the annual audit scramble into click → export.

Auditors ask the same questions every year — MFA, backups, patches, proof of integrity, historical state — and it becomes a three-month panic. AuditBoss continuously collects and cryptographically verifies that evidence on your own infrastructure, so the answer is always ready.

auditboss — verify & score
$ auditboss verify && auditboss score evidence intact · hash-chain valid · signatures OK one control set, evaluated against five frameworks SOC 2 ......... PASS NIST 800-53 ... PARTIAL ISO 27001 ..... PASS PCI DSS ....... PARTIAL CIS Controls .. PASS deterministic — same inputs → same Pass / Partial / Fail, with reasons ℹ a formal pass is confirmed by an accredited third-party assessor (QSA / 3PAO)

Representative output — not a live instance.

What PASS / PARTIAL means, and who confirms it: these are the platform's own control checks against your evidence. PASS = the mapped controls are met and evidenced; PARTIAL = some controls still need implementation or evidence before an audit. A formal, certifiable pass is not something this tool issues — it's granted by an independent accredited assessor: a PCI QSA / ASV for PCI DSS, or an accredited 3PAO (or equivalent) for NIST 800-53 / FedRAMP. AuditBoss gets you audit-ready and hands that assessor a clean, complete evidence package — it does not self-certify.
What it does
Forensic evidence vault — content-addressed (blake3), ed25519-signed, hash-chained storage that proves evidence is intact and complete via Merkle verification.
Controls-as-code — requirements are deterministic rules; the same inputs always produce the same Pass / Partial / Fail verdict, with reasons.
Five frameworks, one control set — CIS, SOC 2, NIST 800-53, ISO 27001 and PCI DSS scored together; map once, satisfy many. Extensible via JSON packs.
Real cross-platform collectors — Windows and Linux host posture, plus identity, backup, vendor and firewall ingestors. Not stubs.
Temporal analysis & fleet — immutable snapshots, point-in-time reconstruction, drift detection, and agent→hub collection across a private LAN.
Proof
0
tests green — verified on a real host
0
frameworks from one control set
0
CLI commands · 10 crates
tamper-evident
byte-level integrity localization
Rusttokio · axumblake3ed25519-dalekembedded dashboardzero cloud deps
🔒
Architecture and verified results shown. Source and binaries are private — this is a capability showcase, not a distribution.

Dreading the
next audit?

I build evidence systems that make audits boring — continuous, verifiable, and export-ready. Tell me which frameworks you're chasing.

Start a project →