<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloud Native Compliance. Reimagined. on ComplyTime</title><link>https://complytime.dev/</link><description>Recent content in Cloud Native Compliance. Reimagined. on ComplyTime</description><generator>Hugo</generator><language>en-US</language><copyright>Copyright (c) 2024-2025 ComplyTime</copyright><lastBuildDate>Mon, 13 Apr 2026 02:36:36 +0000</lastBuildDate><atom:link href="https://complytime.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>Overview</title><link>https://complytime.dev/docs/projects/complytime-collector-components/overview/</link><pubDate>Mon, 13 Apr 2026 02:36:36 +0000</pubDate><guid>https://complytime.dev/docs/projects/complytime-collector-components/overview/</guid><description>&lt;p&gt;&lt;strong&gt;ComplyBeacon&lt;/strong&gt; is an open-source observability toolkit designed to collect, normalize, and enrich compliance evidence, extending the OpenTelemetry (OTEL) standard.&lt;/p&gt;
&lt;p&gt;By bridging the gap between raw policy scanner output and modern logging pipelines, it provides a unified, enriched, and auditable data stream for security and compliance analysis.&lt;/p&gt;</description></item><item><title>Overview</title><link>https://complytime.dev/docs/projects/complyctl/overview/</link><pubDate>Mon, 13 Apr 2026 01:10:00 +0000</pubDate><guid>https://complytime.dev/docs/projects/complyctl/overview/</guid><description>&lt;p&gt;A lightweight compliance runtime that pulls &lt;a href="https://gemara.openssf.org/"&gt;Gemara&lt;/a&gt; policies from an OCI registry and executes scans via plugins.&lt;/p&gt;
&lt;h3 id="architecture"&gt;Architecture&lt;a class="anchor" href="#architecture" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h3&gt;



&lt;div class="expressive-code"&gt;
 &lt;figure class="frame not-content"&gt;
 &lt;figcaption class="header"&gt;
 &lt;span class="title"&gt;&lt;/span&gt;
 &lt;/figcaption&gt;
 &lt;pre tabindex="0"&gt;&lt;code&gt;┌──────────────────────────────────────────────────────────────────┐
│ Host │
│ │
│ ┌──────────────┐ complyctl get ┌───────────────────────┐ │
│ │ OCI Registry │ ◄────────────────── │ │ │
│ │ │ ───────────────────►│ complyctl CLI │ │
│ │ Gemara │ catalog + policy │ │ │
│ │ policies │ layers (YAML) │ init / get / list │ │
│ └──────────────┘ │ generate / scan │ │
│ │ doctor / providers │ │
│ │ version │ │
│ └─────┬────────┬────────┘ │
│ │ │ │
│ ┌────────────┘ │ │
│ │ │ │
│ ▼ ▼ │
│ ┌──────────────┐ ┌────────────────┐ │
│ │ Cache │ │ Providers │ │
│ │ │ │ │ │
│ │ ~/.complytime│ │ ~/.complytime/ │ │
│ │ /policies/ │ │ providers/ │ │
│ │ state.json │ │ │ │
│ │ │ │ complyctl- │ │
│ │ OCI Layout │ │ provider-* │ │
│ │ per policy │ │ │ │
│ └──────────────┘ │ gRPC: Describe │ │
│ │ Generate, Scan │ │
│ ┌──────────────┐ └────────────────┘ │
│ │ Workspace │ │
│ │ │ complytime.yaml defines: │
│ │ ./complytime │ - registry URL │
│ │ .yaml │ - policy IDs + versions │
│ │ │ - targets + variables │
│ │ ./.comply- │ │
│ │ time/scan/ │ │
│ │ (output) │ Scan output (EvaluationLog, OSCAL, │
│ └──────────────┘ SARIF, Markdown) written to workspace │
└──────────────────────────────────────────────────────────────────┘&lt;/code&gt;&lt;/pre&gt;
 &lt;/figure&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Components:&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Overview</title><link>https://complytime.dev/docs/projects/gemara-content-service/overview/</link><pubDate>Fri, 10 Apr 2026 15:55:45 +0000</pubDate><guid>https://complytime.dev/docs/projects/gemara-content-service/overview/</guid><description>&lt;p&gt;An OCI-compliant content delivery and enrichment service for &lt;a href="https://github.com/ossf/gemara"&gt;Gemara&lt;/a&gt; compliance artifacts. Clients can discover and download Gemara content (L1 guidance, L2 catalogs, L3 policies) as OCI artifacts using standard tooling.&lt;/p&gt;</description></item><item><title>Overview</title><link>https://complytime.dev/docs/projects/complyscribe/overview/</link><pubDate>Wed, 08 Apr 2026 07:59:35 +0000</pubDate><guid>https://complytime.dev/docs/projects/complyscribe/overview/</guid><description>&lt;p&gt;ComplyScribe is a CLI tool that assists users in leveraging &lt;a href="https://github.com/oscal-compass/compliance-trestle"&gt;Compliance-Trestle&lt;/a&gt; in CI/CD workflows for &lt;a href="https://github.com/usnistgov/OSCAL"&gt;OSCAL&lt;/a&gt; formatted compliance content management.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;WARNING: This project is currently under initial development. APIs may be changed incompatibly from one commit to another.&lt;/p&gt;</description></item><item><title>Overview</title><link>https://complytime.dev/docs/projects/complytime/overview/</link><pubDate>Wed, 25 Mar 2026 06:57:47 +0000</pubDate><guid>https://complytime.dev/docs/projects/complytime/overview/</guid><description>&lt;p&gt;&lt;em&gt;No README available.&lt;/em&gt; Visit the &lt;a href="https://github.com/complytime/complytime"&gt;repository on GitHub&lt;/a&gt; for more information.&lt;/p&gt;</description></item><item><title>Compliance</title><link>https://complytime.dev/docs/projects/complytime-collector-components/attributes/compliance/</link><pubDate>Mon, 13 Apr 2026 02:36:36 +0000</pubDate><guid>https://complytime.dev/docs/projects/complytime-collector-components/attributes/compliance/</guid><description>&lt;!-- synced from complytime/complytime-collector-components/docs/attributes/compliance.md@main (d6842ba62f96) --&gt;
&lt;!-- NOTE: THIS FILE IS AUTOGENERATED. DO NOT EDIT BY HAND. --&gt;
&lt;!-- see templates/registry/markdown/attribute_namespace.md.j2 --&gt;
&lt;h2 id="compliance"&gt;Compliance&lt;a class="anchor" href="#compliance" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="compliance-assessment-attributes"&gt;Compliance Assessment Attributes&lt;a class="anchor" href="#compliance-assessment-attributes" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Attributes added by compliance assessment tools to map policy results to compliance frameworks. Provides compliance context, risk assessment, and regulatory mapping for audit and reporting. Maps to GEMARA Layer 5 (Enforcement) for Policy-as-Code workflows.&lt;/p&gt;</description></item><item><title>Design</title><link>https://complytime.dev/docs/projects/complytime-collector-components/design/</link><pubDate>Mon, 13 Apr 2026 02:36:36 +0000</pubDate><guid>https://complytime.dev/docs/projects/complytime-collector-components/design/</guid><description>&lt;!-- synced from complytime/complytime-collector-components/docs/DESIGN.md@main (bd0ad6159834) --&gt;
&lt;h3 id="key-features"&gt;Key Features&lt;a class="anchor" href="#key-features" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;OpenTelemetry Native&lt;/strong&gt;: Built on the OpenTelemetry standard for seamless integration with existing observability pipelines.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automated Enrichment&lt;/strong&gt;: Enriches raw evidence with risk scores, threat mappings, and regulatory requirements via the Compass service.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Composability&lt;/strong&gt;: Components are designed as a toolkit; they are not required to be used together, and users can compose their own pipelines.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Compliance-as-Code&lt;/strong&gt;: Leverages the &lt;code&gt;gemara&lt;/code&gt; model for a robust, auditable, and automated approach to risk assessment.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="architecture-overview"&gt;Architecture Overview&lt;a class="anchor" href="#architecture-overview" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;h4 id="design-principles"&gt;Design Principles&lt;a class="anchor" href="#design-principles" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Modularity:&lt;/strong&gt; The system is composed of small, focused, and interchangeable services.&lt;/p&gt;</description></item><item><title>Development</title><link>https://complytime.dev/docs/projects/complytime-collector-components/development/</link><pubDate>Mon, 13 Apr 2026 02:36:36 +0000</pubDate><guid>https://complytime.dev/docs/projects/complytime-collector-components/development/</guid><description>&lt;!-- synced from complytime/complytime-collector-components/docs/DEVELOPMENT.md@main (33bc511c1043) --&gt;
&lt;p&gt;This guide provides comprehensive instructions for setting up, building, and testing the ComplyBeacon project.
It complements the &lt;a href="https://github.com/complytime/complytime-collector-components/blob/main/docs/DESIGN.md"&gt;DESIGN.md&lt;/a&gt; document by focusing on the practical aspects of development.&lt;/p&gt;</description></item><item><title>Policy</title><link>https://complytime.dev/docs/projects/complytime-collector-components/attributes/policy/</link><pubDate>Mon, 13 Apr 2026 02:36:36 +0000</pubDate><guid>https://complytime.dev/docs/projects/complytime-collector-components/attributes/policy/</guid><description>&lt;!-- synced from complytime/complytime-collector-components/docs/attributes/policy.md@main (6ccd9e8264d2) --&gt;
&lt;!-- NOTE: THIS FILE IS AUTOGENERATED. DO NOT EDIT BY HAND. --&gt;
&lt;!-- see templates/registry/markdown/attribute_namespace.md.j2 --&gt;
&lt;h2 id="policy"&gt;Policy&lt;a class="anchor" href="#policy" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="policy-engine-attributes"&gt;Policy Engine Attributes&lt;a class="anchor" href="#policy-engine-attributes" aria-label="Anchor"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Attributes emitted by policy engines (OPA, Gatekeeper, etc.) during policy evaluation and enforcement. Maps to GEMARA Layer 4 (Evaluation) for Policy-as-Code workflows.&lt;/p&gt;</description></item><item><title>Publish Image</title><link>https://complytime.dev/docs/projects/complytime-collector-components/publish_image/publish-image/</link><pubDate>Mon, 13 Apr 2026 02:36:36 +0000</pubDate><guid>https://complytime.dev/docs/projects/complytime-collector-components/publish_image/publish-image/</guid><description>&lt;!-- synced from complytime/complytime-collector-components/docs/publish_image/publish_image.md@main (560d3f05d68e) --&gt;
&lt;p&gt;This guide explains how to publish in GHCR and promote in Quay for container images by using the org-infra reusable workflows.&lt;/p&gt;</description></item></channel></rss>