Policyforge
FreeNot checkedAuto-generate security policies from a short questionnaire
About
Auto-generate security policies from a short questionnaire
README
POLICYFORGE
Auto-generate security policies from a short questionnaire
PyPI CI License: COCL 1.0 Suite
Compliance & GRC — get audit-ready and stay there, self-hosted.
pip install cognis-policyforge
policyforge scan . # → prioritized findings in seconds
🔎 Example output
Real, reproducible output from the tool — runs offline:
$ policyforge-emit --version
policyforge 0.1.0
$ policyforge-emit --help
usage: policyforge [-h] [--version] [--format {table,json}]
{generate,coverage,frameworks} ...
Auto-generate audit-ready security policies from a questionnaire.
positional arguments:
{generate,coverage,frameworks}
generate generate policy documents
coverage show control coverage map
frameworks list supported frameworks/controls
options:
-h, --help show this help message and exit
--version show program's version number and exit
--format {table,json}
output format (default: table)
Blocks above are real
policyforgeoutput — reproduce them from a clone.
Sample result format (illustrative values — run on your own data for real findings):
{
"incident_id": "INC001",
"created_at": "2023-02-15T14:30:00Z",
"updated_at": "2023-02-15T14:31:00Z",
"findings": [
{
"id": "FIND001",
"title": "Suspicious DNS Query",
"description": "DNS query for suspicious domain",
"severity": "medium",
"created_at": "2023-02-15T14:30:00Z"
},
{
"id": "FIND002",
"title": "Unusual Network Traffic",
"description": "Unusual network traffic detected",
"severity": "high",
"created_at": "2023-02-15T14:31:00Z"
}
]
}
Usage — step by step
Install the CLI (Python 3.9+):
pip install git+https://github.com/cognis-digital/policyforge.gitList the supported frameworks/controls so you can scope the questionnaire:
policyforge frameworksGenerate audit-ready policy documents from a questionnaire JSON file:
policyforge generate questionnaire.jsonReview the control coverage map (use JSON for tooling):
policyforge --format json coverage questionnaire.json > coverage.jsonRegenerate policies on every change in CI:
- name: regenerate security policies run: | pip install git+https://github.com/cognis-digital/policyforge.git policyforge generate questionnaire.json
Contents
- Why policyforge? · Features · Quick start · Example · Architecture · AI stack · How it compares · Integrations · Install anywhere · Related · Contributing
Why policyforge?
startups getting audit-ready
policyforge is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.
Features
- ✅ Generate Policies
- ✅ Coverage Report
- ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
- ✅ Ports in Python, JavaScript, Go, and Rust (
ports/)
Quick start
pip install cognis-policyforge
policyforge --version
policyforge scan . # scan current project
policyforge scan . --format json # machine-readable
policyforge scan . --fail-on high # CI gate (non-zero exit)
Example
$ policyforge scan .
[HIGH ] POL-001 example finding (./src/app.py)
[MEDIUM ] POL-002 another signal (./config.yaml)
2 findings · risk score 5 · 38ms
Architecture
flowchart LR
IN[input] --> P[policyforge<br/>analyze + score]
P --> OUT[report]
Use it from any AI stack
policyforge is interoperable with every popular way of using AI:
- MCP server —
policyforge mcp(Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet) - OpenAI-compatible / JSON — pipe
policyforge scan . --format jsoninto any agent or LLM - LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
- CI / scripts — exit codes + SARIF for non-AI pipelines
How it compares
| Cognis policyforge | Comp AI | |
|---|---|---|
| Self-hostable, no account | ✅ | varies |
| Single command, zero config | ✅ | ⚠️ |
| JSON + SARIF for CI | ✅ | varies |
| MCP-native (AI agents) | ✅ | ❌ |
| Polyglot ports (JS/Go/Rust) | ✅ | ❌ |
| Open license | ✅ COCL | varies |
Built in the spirit of Comp AI, re-framed the Cognis way. Missing a credit? Open a PR.
Integrations
Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (policyforge mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.
Install — every way, every platform
pip install "git+https://github.com/cognis-digital/policyforge.git" # pip (works today)
pipx install "git+https://github.com/cognis-digital/policyforge.git" # isolated CLI
uv tool install "git+https://github.com/cognis-digital/policyforge.git" # uv
pip install cognis-policyforge # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/policyforge:latest --help # Docker
brew install cognis-digital/tap/policyforge # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/policyforge/main/install.sh | sh
| Linux | macOS | Windows | Docker | Cloud |
|---|---|---|---|---|
scripts/setup-linux.sh |
scripts/setup-macos.sh |
scripts/setup-windows.ps1 |
docker run ghcr.io/cognis-digital/policyforge |
DEPLOY.md (AWS/Azure/GCP/k8s) |
Related Cognis tools
- soc2box — SOC 2 evidence collector and control tracker, self-hosted
- gdprkit — GDPR/CCPA DSAR, RoPA, and cookie-consent toolkit
- vendorvet — Third-party / vendor risk questionnaires with SBOM cross-ref
- auditrail — Tamper-evident audit-log aggregator with hash-chained attestation
- frameworkmap — Crosswalk controls across NIST, ISO 27001, SOC 2, CMMC, PCI
- dpiaforge — DPIA and EU AI Act impact-assessment generator
Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram
Contributing
PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.
⭐ If
policyforgesaved you time, star it — it genuinely helps others find it.
Interoperability
{} composes with the 300+ tool Cognis suite — JSON in/out and a shared
OpenAI-compatible /v1 backbone. See INTEROP.md for the
suite map, composition patterns, and reference stacks.
License
Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.
Install Policyforge in Claude Desktop, Claude Code & Cursor
unyly install policyforgeInstalls into Claude Desktop, Claude Code, Cursor & VS Code — handles npx, uvx and build-from-source repos for you.
First time? Get the CLI: curl -fsSL https://unyly.org/install | sh
Or configure manually
Run in your terminal:
claude mcp add policyforge -- uvx --from git+https://github.com/cognis-digital/policyforge cognis-policyforgeStep-by-step: how to install Policyforge
FAQ
Is Policyforge MCP free?
Yes, Policyforge MCP is free — one-click install via Unyly at no cost.
Does Policyforge need an API key?
No, Policyforge runs without API keys or environment variables.
Is Policyforge hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Policyforge in Claude Desktop, Claude Code or Cursor?
Open Policyforge on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectAmap Maps Mcp Server
MCP server for using the AMap Maps API
by duxiaohuiSupabase
Database, auth and storage
by SupabaseEverything
Reference / test server with prompts, resources, and tools.
Git
Tools to read, search, and manipulate Git repositories.
Sequential Thinking
Dynamic and reflective problem-solving through thought sequences.
Time
Time and timezone conversion capabilities.
Compare Policyforge with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
