Skip to main content

ASVS Compliance Engine

Turn Security Requirements into Verifiable Code.

CircleCI PyPI - Version Python Version License Docker


ASVS Compliance Engine Demo

Stop managing security in spreadsheets. The ASVS Compliance Engine is a DevSecOps toolkit that operationalizes the OWASP Application Security Verification Standard (ASVS) 5.0. It treats compliance as code, scanning your infrastructure, verifying your app headers, and enforcing evidence requirements in your CI/CD pipeline.

Get Started · Documentation · Report Bug


⚡ The Problem: Compliance Rot

Most security compliance efforts fail because they rely on static documents (Word/Excel) that become obsolete the moment they are written. This engine bridges the gap between Requirements and Reality.

❌ The Old Way (Static) ✅ The Compliance Engine (Dynamic)
Manual Attestation: "I promise we use bcrypt." Automated Evidence: Scans package.json for bcrypt library.
Stale Docs: Architecture diagrams from 2021. Living Docs: Requirements mapped directly to code files.
Blind Spots: Cloud configs checked manually. IaC Scanning: Terraform plans scanned for ASVS V5.3 violations.
Audit Panic: Scrambling for screenshots. Instant Dashboards: Single-click HTML audit reports.

🚀 Key Features

1. Automated Evidence Verification

Don't just claim you use secure libraries—prove it. Map ASVS requirements directly to files in your repository using evidence.yml. The engine verifies their existence and content during every build.

Evidence Verification

2. Infrastructure-as-Code (IaC) Scanning

Shift security left by catching cloud storage misconfigurations before they deploy. Our native scanner checks Terraform plans against ASVS V5.3 (Storage & Cryptography).

IaC Scanner

3. Auditor-Ready Dashboards

Stop manually compiling evidence. Generate a comprehensive HTML report that combines documentation status, code evidence, and DAST results into a single pane of glass for your SOC2/ISO 27001 auditor.

Compliance Dashboard

🛠️ Quick Start

Option A: Python (Recommended)

# 1. Install the toolkit
pip install "asvs-compliance-tools[evidence,verification]"

# 2. Initialize your project (Interactive Wizard)
# Generates your security docs and evidence.yml
python -m tools.init_project --interactive

# 3. Verify Compliance
# Scans your docs and code for evidence
python -m tools.compliance_gate --level 2 --evidence-manifest evidence.yml

Option B: Docker

No Python environment? No problem.

# Build the image
docker build -t asvs-engine .

# Run the Compliance Gate
docker run -v $(pwd):/app asvs-engine tools.compliance_gate --level 2

📦 What's Inside?

Tool Command Description
Compliance Gate compliance_gate Enforces documentation and code evidence rules.
Verification Suite verification_suite DAST scanner for Security Headers, CSRF, and Cookies.
IaC Scanner iac_scanner Scans Terraform plans for unencrypted storage.
Drift Detector drift_detector Checks if your ASVS definitions are out of sync with OWASP.
Report Gen generate_report Compiles JSON outputs into an HTML dashboard.

🤝 Contributing

We are building the standard for open-source compliance.

💖 Support the Project

If this tool saves your team hours of audit preparation, please consider sponsoring the development. Your support funds the creation of pre-built Evidence Packs for frameworks like Django, Spring Boot, and Node.js.


Built with ❤️ for the Security Community

OWASP ASVS •

Metadata

Release files for asvs-compliance-tools 2.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for asvs-compliance-tools 2.2.0
File Size Uploaded
asvs_compliance_tools-2.2.0.tar.gz 44.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for asvs-compliance-tools 2.2.0
File Interpreter ABI Platform
asvs_compliance_tools-2.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 78.7 kB

Release files / asvs_compliance_tools-2.2.0.tar.gz

Download URL asvs_compliance_tools-2.2.0.tar.gz
Size 44.3 kB
Tags Source
SHA-256 checksum
How to use checksums
6d234f6f43532dec4204da2328dfab7265c3c6f093705859b5943120ac295c25
BLAKE2b-256 checksum
How to use checksums
8cbd6b4832abe2d9ee08b72491fea981db534821332a3468e5f8163cb25802bf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.14

Release files / asvs_compliance_tools-2.2.0-py3-none-any.whl

Download URL asvs_compliance_tools-2.2.0-py3-none-any.whl
Size 34.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1f93cedc52706533924a79b5f2592d7afce6bde6b1aedcd46839133d4bf98723
BLAKE2b-256 checksum
How to use checksums
2f0d7bf210fa86af6e8cf1e1e951a8925126609fe2a4bd2073d6dfbed317b1c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.14

Release history Release notifications | RSS feed

This release

2.2.0 This release

2 release files

2.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page