The open source governance, risk and compliance platform your whole organisation shares one risk register on
SimpleRisk is the widely used open source governance, risk and compliance platform. Capture and score risks with the CLASSIC, CVSS, DREAD or OWASP methodologies, plan and track mitigations and management reviews, run compliance audits against frameworks and controls, manage assets, and report on your organisation's risk posture from one shared system.
cloudimg ships SimpleRisk fully installed and hardened: the database schema is loaded and the browser setup wizard is closed, first boot generates a unique administrator password and a unique database password for every instance into a root only file, the MariaDB risk register runs bound to loopback only on its own data volume, and every deployment is paired with a step by step guide and 24/7 support.
Real screenshots taken while testing this image against its deployment guide.
This is a repackaged open source software product wherein additional charges apply for cloudimg support services.
SimpleRisk is the widely used open source governance, risk and compliance (GRC) platform used by organisations worldwide to run their risk register. Capture and score risks using CLASSIC, CVSS, DREAD or OWASP methodologies, plan and track mitigations and management reviews, run compliance audits against frameworks and controls, manage assets, and report on your organisation's risk posture from one shared system. The current release in this listing is SimpleRisk 20260519-001.
## Use case: ISO 27001 certification readiness
A team preparing for ISO 27001 certification can use SimpleRisk to build and maintain its risk register, map controls, schedule management reviews, and track mitigation progress from a single platform. The compliance audit module lets your information security team document control effectiveness and generate evidence for external auditors, while the reporting dashboard gives leadership a real time view of residual risk across the organisation. The same compliance and control mapping supports work against the other frameworks your organisation follows.
## Pre configured and ready in minutes
With a standard SimpleRisk deployment you must install PHP and its extensions, configure a web server, provision a database, load the schema, and secure the initial administrator account. This image completes all of that before first boot, so your risk and compliance team can focus on managing risk rather than infrastructure.
Application stack: SimpleRisk on PHP 8.3 with OPcache and all required extensions, the nginx web server, and the MariaDB database engine, all from the distribution package set. The MariaDB database, where SimpleRisk stores your risk register and compliance data, is bound to the loopback interface only and is never exposed to the network, and lives on a dedicated data volume kept separate from the operating system disk.
## Security hardened for sensitive risk data
Because a GRC tool holds sensitive risk data, security is the priority. On the first boot of your instance a one shot service generates a fresh MariaDB password and a fresh administrator password unique to that instance and writes the administrator password to a root only file, so no shared or default passwords ship in the image. There is no default administrator login on the shipped image, and the open setup wizard that a fresh SimpleRisk install would otherwise expose is closed before the image is captured. Browse to the instance address and sign in to start managing risk. We recommend restricting network access to trusted source ranges and enabling HTTPS, both covered in the deployment guide.
## 24/7 expert support from cloudimg
Compared to free community images, this listing includes 24/7 expert support from cloudimg with a one hour average response time for critical issues. Our engineers provide SimpleRisk specific assistance including deployment guidance, TLS and reverse proxy setup, network access hardening, version upgrades, and MariaDB database administration.
All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.