Read
Human-readable, for the practitioner.
Open by design, current by default, grounded in provenance. Read it, parse it, ask it.
One open layer for regulated work: the rules people must follow, and the work itself. Read it, parse it, ask it, with the source and the date behind every answer.
What we do
OpenControls turns proprietary, siloed reference data, the regulatory mandates and technical controls that define what must be done, and the map of work itself, the jobs people do and the AI that can do them, into one harmonized graph. We don't ask any framework to change a word. Translation, not conquest.
Human-readable, for the practitioner.
Machine-readable, for the platform.
Promptable through an MCP server, for the AI agent.
The portfolio
Compliance and workforce automation aren't two companies. They're two surfaces of one structured-knowledge layer, two ends of the same five-lens methodology.
Compliance you can read, parse, and ask.
The compliance front door. Open any STIG and see the regulation above it, the role that owns it, and the work it takes to close it. Free to look up.
Was it yours to use?
The decision layer for whether content was yours to use. Right-to-use, right-to-release, with the verdict and the evidence attached.
The work AI can do, mapped to the work people do.
For any occupation, see what software replaces, augments, supports, and informs, with the source behind every call.
One vocabulary for every framework.
The working dictionary underneath the layer, where terms are reconciled across frameworks so translation stays honest.
The open standard.
The open standard OpenControls maps into and helps advance, alongside OSCAL.
Participation, not a wholly-owned product.
Founders' mandate
Compliance shouldn't be a struggle, and the map of human work shouldn't sit in closed PDFs either. We're building the open layer underneath it all, with a common language machines can understand, humans can trust, and organizations can rely on. Compliance is the first surface we've built on it. Workforce automation is the next.
Current PrePrint
No preprint is published yet. Publish one in the admin and it appears here automatically.
The Library
The library holds preprints, downloadable bundles, and other resources. The metadata is open to all; the files unlock with a free account.
Why trust it
Every answer carries the source and the date behind it. We don't crown a winner, and we don't attest. We map and provide defensible evidence; you make the call.
Practitioners look up STIGs on STIGViewer, the compliance front door, every month.
The multi-lensatic methodology is public and the paper is online for peer review.
Source and date on every connection. Translation, not conquest; no framework changes a word.
Stay current
New preprints, methodology updates, and what's shipping across the portfolio. No noise.