Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Dpiaforge

FreeNot checked

DPIA and EU AI Act impact-assessment generator

GitHubEmbed

About

DPIA and EU AI Act impact-assessment generator

README

DPIAFORGE

DPIAFORGE

DPIA and EU AI Act impact-assessment generator

PyPI CI License: COCL 1.0 Suite

Compliance & GRC — get audit-ready and stay there, self-hosted.


pip install cognis-dpiaforge

dpiaforge scan .            # → prioritized findings in seconds

🔎 Example output

Real, reproducible output from the tool — runs offline:

$ dpiaforge-emit --version
dpiaforge 0.1.0
$ dpiaforge-emit --help
usage: dpiaforge [-h] [--version] [--format {table,json}] {assess} ...

DPIA & EU AI Act impact-assessment generator (offline, stdlib-only).

positional arguments:
  {assess}
    assess              run full DPIA + AI Act assessment on an activity JSON

options:
  -h, --help            show this help message and exit
  --version             show program's version number and exit
  --format {table,json}
                        output format (default: table)

Blocks above are real dpiaforge output — reproduce them from a clone.

Sample result format (illustrative values — run on your own data for real findings):

{
"findings": [
    {
        "id": "1234567890",
        "title": "Suspicious Network Traffic",
        "description": "Anomalous network traffic detected from IP 192.168.1.100.",
        "created_by": "John Doe",
        "created_at": "2023-02-15T14:30:00Z"
    },
    {
        "id": "2345678901",
        "title": "Malware Detection",
        "description": "Malware detected on system with IP 192.168.1.101.",
        "created_by": "Jane Smith",
        "created_at": "2023-02-16T10:45:00Z"
    }
]
}

Usage — step by step

  1. Install the CLI:

    pip install dpiaforge
    
  2. Assess a processing activity described in a JSON file (or - for stdin) for DPIA + EU AI Act risk:

    dpiaforge assess activity.json
    
  3. Pipe the activity in from another step:

    cat activity.json | dpiaforge assess -
    
  4. Read the output. The global --format json flag emits a machine-readable assessment:

    dpiaforge --format json assess activity.json > dpia.json
    
  5. Wire it into CI / governance automation — regenerate the assessment whenever the activity record changes:

    dpiaforge --format json assess activity.json > artifacts/dpia.json || exit 1
    

Contents

Why dpiaforge?

AI governance wave

dpiaforge is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.

Features

  • ✅ Dpia Threshold

  • ✅ Classify Ai Act Tier

  • ✅ Risk Score

  • ✅ Assess

  • ✅ Runs on Linux/macOS/Windows · Docker · devcontainer

  • ✅ Ports in Python, JavaScript, Go, and Rust (ports/)

Quick start


pip install cognis-dpiaforge

dpiaforge --version

dpiaforge scan .                       # scan current project

dpiaforge scan . --format json         # machine-readable

dpiaforge scan . --fail-on high        # CI gate (non-zero exit)

Example


$ dpiaforge scan .

  [HIGH    ] DPI-001  example finding             (./src/app.py)

  [MEDIUM  ] DPI-002  another signal              (./config.yaml)



  2 findings · risk score 5 · 38ms

Architecture

flowchart LR
  IN[input] --> P[dpiaforge<br/>analyze + score]
  P --> OUT[report]

Use it from any AI stack

dpiaforge is interoperable with every popular way of using AI:

  • MCP serverdpiaforge mcp (Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet)

  • OpenAI-compatible / JSON — pipe dpiaforge scan . --format json into any agent or LLM

  • LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line

  • CI / scripts — exit codes + SARIF for non-AI pipelines

How it compares

| | Cognis dpiaforge | EU AI Act tooling |

|---|:---:|:---:|

| Self-hostable, no account | ✅ | varies |

| Single command, zero config | ✅ | ⚠️ |

| JSON + SARIF for CI | ✅ | varies |

| MCP-native (AI agents) | ✅ | ❌ |

| Polyglot ports (JS/Go/Rust) | ✅ | ❌ |

| Open license | ✅ COCL | varies |

Built in the spirit of EU AI Act tooling, re-framed the Cognis way. Missing a credit? Open a PR.

Integrations

Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (dpiaforge mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.

Install — every way, every platform


pip install "git+https://github.com/cognis-digital/dpiaforge.git"    # pip (works today)

pipx install "git+https://github.com/cognis-digital/dpiaforge.git"   # isolated CLI

uv tool install "git+https://github.com/cognis-digital/dpiaforge.git" # uv

pip install cognis-dpiaforge                                          # PyPI (when published)

docker run --rm ghcr.io/cognis-digital/dpiaforge:latest --help        # Docker

brew install cognis-digital/tap/dpiaforge                             # Homebrew tap

curl -fsSL https://raw.githubusercontent.com/cognis-digital/dpiaforge/main/install.sh | sh

| Linux | macOS | Windows | Docker | Cloud |

|---|---|---|---|---|

| scripts/setup-linux.sh | scripts/setup-macos.sh | scripts/setup-windows.ps1 | docker run ghcr.io/cognis-digital/dpiaforge | DEPLOY.md (AWS/Azure/GCP/k8s) |

Related Cognis tools

  • soc2box — SOC 2 evidence collector and control tracker, self-hosted

  • gdprkit — GDPR/CCPA DSAR, RoPA, and cookie-consent toolkit

  • policyforge — Auto-generate security policies from a short questionnaire

  • vendorvet — Third-party / vendor risk questionnaires with SBOM cross-ref

  • auditrail — Tamper-evident audit-log aggregator with hash-chained attestation

  • frameworkmap — Crosswalk controls across NIST, ISO 27001, SOC 2, CMMC, PCI

Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram

Contributing

PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.

⭐ If dpiaforge saved you time, star it — it genuinely helps others find it.

Interoperability

{} composes with the 300+ tool Cognis suite — JSON in/out and a shared OpenAI-compatible /v1 backbone. See INTEROP.md for the suite map, composition patterns, and reference stacks.

License

Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.


Cognis Digital · one of 170+ tools in the Cognis Neural Suite · Making Tomorrow Better Today

from github.com/cognis-digital/dpiaforge

Install Dpiaforge in Claude Desktop, Claude Code & Cursor

Recommended · one command, every IDE
unyly install dpiaforge

Installs into Claude Desktop, Claude Code, Cursor & VS Code — handles npx, uvx and build-from-source repos for you.

First time? Get the CLI: curl -fsSL https://unyly.org/install | sh

Or configure manually

Run in your terminal:

claude mcp add dpiaforge -- uvx --from git+https://github.com/cognis-digital/dpiaforge cognis-dpiaforge

Step-by-step: how to install Dpiaforge

FAQ

Is Dpiaforge MCP free?

Yes, Dpiaforge MCP is free — one-click install via Unyly at no cost.

Does Dpiaforge need an API key?

No, Dpiaforge runs without API keys or environment variables.

Is Dpiaforge hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Dpiaforge in Claude Desktop, Claude Code or Cursor?

Open Dpiaforge on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Dpiaforge with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All ai MCPs