Introduce a hierarchical risk assessment model with six entity types: - Risk Assessment: top-level container scoped to an organization - Risk Assessment Scope: sub-container for scoping threat modeling exercises within an assessment - Risk Assessment Node: DFD elements typed as ENTITY, BOUNDARY, ASSET, or DATA within a scope - Risk Assessment Process: directed data flows between two nodes - Risk Assessment Threat: descriptive threats attached to a process with a free-text category (e.g. Confidentiality, Integrity) - Risk Scenario: thin join linking a threat to a risk from the register, carrying only a name and description Risk scoring (likelihood, impact, treatment) remains on the existing Risk entity. Threats are purely descriptive. Risk Scenarios connect the threat model to the risk register without duplicating scores. Backend: migration with PG enum for node types, coredata structs, service layer with full CRUD and validation, GraphQL schema with 18 mutations and paginated connections, authorization actions and policies, and base_resolvers.go Node dispatch for all entity types. Frontend: Risk Assessments list page with create dialog, detail page showing scopes as cards with nodes/processes/threats tables, inline create/edit/delete actions on all entities, and a Scenarios tab on the Risk detail page linking threats to risks. Existing RiskGraph.ts hook file removed in favor of colocated queries in page files. E2E tests cover CRUD for all entity types, RBAC, and tenant isolation. Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
Probo is an open-source compliance platform built for startups that helps you achieve SOC-2 compliance quickly and efficiently. Unlike traditional solutions, Probo is designed to be accessible, transparent, and community-driven.
🚀 Getting Started
Prerequisites
- Go 1.21+
- Node.js 22+
- Docker
- mkcert
Quick Start
-
Clone the repository:
git clone --recurse-submodules https://github.com/getprobo/probo.git cd probo -
Install dependencies:
# Install Go dependencies go mod download # Install Node.js dependencies npm ci -
Start the development environment:
# Start infrastructure services make stack-up # Build the project make build # Generate the local dev config (writes cfg/dev.yaml) make dev-config # Start the application using development settings bin/probod -cfg-file cfg/dev.yaml
The application will be available at:
- Application: http://localhost:8080
Testing Custom Domains
To test the custom domains feature locally, add the CNAME target to your hosts file:
# Add this line to /etc/hosts (macOS/Linux) or C:\Windows\System32\drivers\etc\hosts (Windows)
127.0.0.1 custom.getprobo.com
This allows you to test custom trust center domains on your local machine. The generated cfg/dev.yaml sets the CNAME target via custom-domains.cname-target; change CUSTOM_DOMAINS_CNAME_TARGET before running make dev-config to override it.
For detailed setup instructions, see our Contributing Guide.
🏗️ Current Status
Probo is in early development, focusing on building a solid foundation for compliance management.
🛠️ Tech Stack
Backend
- Go - API server
- PostgreSQL - Data storage
- GraphQL - API layer
Frontend
- React with TypeScript
- Relay - Data fetching
- TailwindCSS - Styling
Infrastructure
- Docker - Containerization
- OpenTelemetry - Observability
- GitHub Actions - CI/CD
Observability
- Grafana - Metrics visualization
- Prometheus - Metrics collection
- Loki - Log aggregation
- Tempo - Distributed tracing
🤝 Contributing
We love contributions from our community! There are many ways to contribute:
- 🌟 Star the repository to show your support
- 🐛 Report bugs
- 💡 Request features
- 🔧 Submit pull requests
- 📖 Improve documentation
Please read our Contributing Guide before making a pull request.
📚 Documentation
🌐 Community & Support
- Join our Discord community
- Follow us on Twitter
- Connect on LinkedIn
- Visit our website
📄 License
Probo is MIT licensed.