Curtis Compliance Pro

Hosted pro tier for Curtis Compliance — GitHub App, multi-repo audit rollup, PDF export, custom frameworks. Source-available (BSL/FSL/SSPL — license class TBD).

At a glance

status
In development
model
Source-available
license
BSL / FFL / SSPL (TBD)
tier
Hosted pro
base
curtis-compliance (MIT)

Highlights

Hosted GitHub App
Drop-in for organizations that want PR review without running the action themselves. Multi-repo rollup out of the box.
PDF audit export
Court-defensible export of the hash-chained audit log. Hand it to auditors, regulators, or your CISO.
Custom frameworks
Beyond HIPAA / SOC2 / PCI-DSS — define your own control citations and map them to code patterns.
Source-available, not closed
Following Sentry / MongoDB / SSPL model — public repo, restrictive license. Auditable source, commercial use restricted.

Stack

TypeScriptGitHub AppSame engine as curtis-compliance

Pro tier for Curtis Compliance. Hosted GitHub App for organizations that want multi-repo audit rollup, PDF export, and custom frameworks without running the action themselves.

Licensing model

Not closed-source. Source-available following the Sentry / MongoDB / SSPL playbook — public repo, restrictive license, auditable source, commercial use restricted. The MIT-licensed OSS tier stays MIT; the pro tier adds the hosted surface and enterprise features on top.

License class (BSL vs FSL vs SSPL) is the open decision — landing before the package goes live. The stub repo at github.com/JordanNewell/curtis-compliance-pro already has 7 inbound links from the curtis-compliance README.

Status

Exploratory — the engine is proven (curtis-compliance has been shipping since 2026-07-20), the packaging is the work in progress.