Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Policyforge

FreeNot checked

Auto-generate security policies from a short questionnaire

GitHubEmbed

About

Auto-generate security policies from a short questionnaire

README

POLICYFORGE

POLICYFORGE

Auto-generate security policies from a short questionnaire

PyPI CI License: COCL 1.0 Suite

Compliance & GRC — get audit-ready and stay there, self-hosted.

pip install cognis-policyforge
policyforge scan .            # → prioritized findings in seconds

🔎 Example output

Real, reproducible output from the tool — runs offline:

$ policyforge-emit --version
policyforge 0.1.0
$ policyforge-emit --help
usage: policyforge [-h] [--version] [--format {table,json}]
                   {generate,coverage,frameworks} ...

Auto-generate audit-ready security policies from a questionnaire.

positional arguments:
  {generate,coverage,frameworks}
    generate            generate policy documents
    coverage            show control coverage map
    frameworks          list supported frameworks/controls

options:
  -h, --help            show this help message and exit
  --version             show program's version number and exit
  --format {table,json}
                        output format (default: table)

Blocks above are real policyforge output — reproduce them from a clone.

Sample result format (illustrative values — run on your own data for real findings):

{
"incident_id": "INC001",
"created_at": "2023-02-15T14:30:00Z",
"updated_at": "2023-02-15T14:31:00Z",
"findings": [
    {
        "id": "FIND001",
        "title": "Suspicious DNS Query",
        "description": "DNS query for suspicious domain",
        "severity": "medium",
        "created_at": "2023-02-15T14:30:00Z"
    },
    {
        "id": "FIND002",
        "title": "Unusual Network Traffic",
        "description": "Unusual network traffic detected",
        "severity": "high",
        "created_at": "2023-02-15T14:31:00Z"
    }
]
}

Usage — step by step

  1. Install the CLI (Python 3.9+):

    pip install git+https://github.com/cognis-digital/policyforge.git
    
  2. List the supported frameworks/controls so you can scope the questionnaire:

    policyforge frameworks
    
  3. Generate audit-ready policy documents from a questionnaire JSON file:

    policyforge generate questionnaire.json
    
  4. Review the control coverage map (use JSON for tooling):

    policyforge --format json coverage questionnaire.json > coverage.json
    
  5. Regenerate policies on every change in CI:

    - name: regenerate security policies
      run: |
        pip install git+https://github.com/cognis-digital/policyforge.git
        policyforge generate questionnaire.json
    

Contents

Why policyforge?

startups getting audit-ready

policyforge is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.

Features

  • ✅ Generate Policies
  • ✅ Coverage Report
  • ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
  • ✅ Ports in Python, JavaScript, Go, and Rust (ports/)

Quick start

pip install cognis-policyforge
policyforge --version
policyforge scan .                       # scan current project
policyforge scan . --format json         # machine-readable
policyforge scan . --fail-on high        # CI gate (non-zero exit)

Example

$ policyforge scan .
  [HIGH    ] POL-001  example finding             (./src/app.py)
  [MEDIUM  ] POL-002  another signal              (./config.yaml)

  2 findings · risk score 5 · 38ms

Architecture

flowchart LR
  IN[input] --> P[policyforge<br/>analyze + score]
  P --> OUT[report]

Use it from any AI stack

policyforge is interoperable with every popular way of using AI:

  • MCP serverpolicyforge mcp (Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet)
  • OpenAI-compatible / JSON — pipe policyforge scan . --format json into any agent or LLM
  • LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
  • CI / scripts — exit codes + SARIF for non-AI pipelines

How it compares

Cognis policyforge Comp AI
Self-hostable, no account varies
Single command, zero config ⚠️
JSON + SARIF for CI varies
MCP-native (AI agents)
Polyglot ports (JS/Go/Rust)
Open license ✅ COCL varies

Built in the spirit of Comp AI, re-framed the Cognis way. Missing a credit? Open a PR.

Integrations

Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (policyforge mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.

Install — every way, every platform

pip install "git+https://github.com/cognis-digital/policyforge.git"    # pip (works today)
pipx install "git+https://github.com/cognis-digital/policyforge.git"   # isolated CLI
uv tool install "git+https://github.com/cognis-digital/policyforge.git" # uv
pip install cognis-policyforge                                          # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/policyforge:latest --help        # Docker
brew install cognis-digital/tap/policyforge                             # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/policyforge/main/install.sh | sh
Linux macOS Windows Docker Cloud
scripts/setup-linux.sh scripts/setup-macos.sh scripts/setup-windows.ps1 docker run ghcr.io/cognis-digital/policyforge DEPLOY.md (AWS/Azure/GCP/k8s)

Related Cognis tools

  • soc2box — SOC 2 evidence collector and control tracker, self-hosted
  • gdprkit — GDPR/CCPA DSAR, RoPA, and cookie-consent toolkit
  • vendorvet — Third-party / vendor risk questionnaires with SBOM cross-ref
  • auditrail — Tamper-evident audit-log aggregator with hash-chained attestation
  • frameworkmap — Crosswalk controls across NIST, ISO 27001, SOC 2, CMMC, PCI
  • dpiaforge — DPIA and EU AI Act impact-assessment generator

Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram

Contributing

PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.

⭐ If policyforge saved you time, star it — it genuinely helps others find it.

Interoperability

{} composes with the 300+ tool Cognis suite — JSON in/out and a shared OpenAI-compatible /v1 backbone. See INTEROP.md for the suite map, composition patterns, and reference stacks.

License

Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.


Cognis Digital · one of 170+ tools in the Cognis Neural Suite · Making Tomorrow Better Today

from github.com/cognis-digital/policyforge

Install Policyforge in Claude Desktop, Claude Code & Cursor

Recommended · one command, every IDE
unyly install policyforge

Installs into Claude Desktop, Claude Code, Cursor & VS Code — handles npx, uvx and build-from-source repos for you.

First time? Get the CLI: curl -fsSL https://unyly.org/install | sh

Or configure manually

Run in your terminal:

claude mcp add policyforge -- uvx --from git+https://github.com/cognis-digital/policyforge cognis-policyforge

Step-by-step: how to install Policyforge

FAQ

Is Policyforge MCP free?

Yes, Policyforge MCP is free — one-click install via Unyly at no cost.

Does Policyforge need an API key?

No, Policyforge runs without API keys or environment variables.

Is Policyforge hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Policyforge in Claude Desktop, Claude Code or Cursor?

Open Policyforge on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Policyforge with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All development MCPs