OpenSSF project

Gemara

Schemas, SDKs, and tooling implementing the Gemara GRC engineering model — machine-readable formats that bridge high-level compliance requirements and low-level technical evidence to enable automated risk assessment across security tooling.

How each persona uses Gemara

Open Source Professional (OSPO) OSPO

Expresses the organization's controls and compliance requirements in Gemara's shared model so they can be assessed consistently across projects.

See everything for OSPO →

Security Engineer / Architect Security

Maps threats, controls, and evidence onto Gemara's layered schema to drive automated, repeatable risk assessment.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Consumes Gemara's machine-readable model to automate control evaluation and evidence collection inside the pipeline.

See everything for DevOps →

Executive / End-User Consumer Executive

Reads risk and compliance status rolled up through Gemara's model rather than from disconnected, hand-assembled spreadsheets.

See everything for Executive →

Problems Gemara helps with

Policy & Compliance Enforcement Compliance

Encodes governance, risk, and compliance requirements as a shared data model so controls map cleanly between regulations and evidence.

See everything for Compliance →

Measuring Security Posture Posture

Standardizes how risk and control evidence are expressed so posture can be assessed automatically and compared across projects.

See everything for Posture →

Relationships

Outgoing