Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
caos-os — Customer Assurance Operating System. Answer the security questionnaires your customers send you, once. | Kitploit
Tools/GitHubGitHub/digicred-oss/caos-os
Authentication & AuthorizationDefensive ToolsInformation GatheringPrivacyMachine Learning
GitHubdigicred-oss/caos-os

caos-os

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

View Repository
1291 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CAOS — Customer Assurance Operating System

Answer the security questionnaires your customers send you, once.

Every company that handles customer data gets the same requests over and over: security questionnaires, privacy assessments, vendor risk reviews, procurement due diligence, evidence requests. Most organizations answer them by hand — a spreadsheet from the customer, a folder of policies, an email thread, and someone's memory of what they said last time.

CAOS turns that into a system of record. Questionnaires become structured, answerable work. Finished answers and your compliance documents become a searchable, citable corpus. The next questionnaire starts from what you already said, with every claim traceable to the document or prior answer it came from.

It is self-hosted. Your policies, your answers, and your customers' questionnaires stay on your infrastructure.

Status: v0. CAOS runs in production, but this repository is newly public. Interfaces, schema, and configuration are still moving. External contributions are not open yet — see Contributing.


What it does

Reads questionnaires without guessing. Upload a customer's XLSX and CAOS renders it faithfully — sheets, rows, cells, hidden columns, validation dropdowns. You then mark which rows are answerable and which cells to fill, in ranges rather than one at a time. There is no per-customer parser, because there is no standard: a bold row can be a question, a blank column can be the answer target, and every heuristic that gets one workbook right gets another confidently wrong.

Builds a corpus from work you already finished. Closing a questionnaire publishes its answered rows as reusable Q&A. Uploaded policies, certifications, and reports become citable passages. Both are versioned immutably, so an answer you sent last quarter still explains itself against the document that was current then.

Finds the right prior answer. Retrieval runs lexical and semantic search together, fuses their rankings, and reranks the top candidates. Compliance language needs both: exact tokens like "SOC 2 Type II" that embeddings smear, and paraphrases that keyword search misses entirely.

Drafts grounded answers. Optional. The model searches your corpus through bounded, allow-listed tools and drafts an answer with citations — plus a label saying where its authority came from: Knowledge grounded, Mixed, General guidance, or Based on current answer. A General guidance answer makes no claim about your organization, and says so.

Answers in Google Chat. A /ciso slash command hits the same grounded corpus, with a link back into a persistent conversation in the web app.

Exports back into the customer's own workbook. Answers are written into the original file structure, in the cells you mapped — not into a CAOS-shaped approximation of it.

Records everything. An append-only audit log with database-enforced immutability, carrying exact before-and-after answer values.


Modules

CAOS is organised into nine domain modules. Three of them — Evidence, Knowledge, and Tasks — are global: they are not owned by projects, because their value comes from crossing engagements.

ModuleOwnsDocs
IdentityAuth modes, sessions, roles, users, external subject bindingsdocs
ProjectsThe engagement container; close cascadedocs
QuestionnairesWorkbook reading, row mapping, answering workspace, exportdocs
EvidenceGlobal repository of reusable compliance artifactsdocs
KnowledgeSources, passages, embeddings, retrieval, exclusions, citationsdocs
AICISO conversations, generations, grounding labelsdocs
ChatGoogle Chat verification, identity binding, deliverydocs
TasksRequested human work across modulesdocs
AuditAppend-only event logdocs

Architecture

                          Internet
                             │
                       ┌─────┴─────┐
                       │   nginx   │   TLS · static frontend · /api proxy
                       └─────┬─────┘
              ┌──────────────┼──────────────┐
              │              │              │
        ┌─────┴─────┐  ┌─────┴─────┐  ┌─────┴──────┐
        │ Frontend  │  │    API    │  │  Taskiq    │
        │  React    │  │  FastAPI  │  │  workers   │
        │  static   │  │  :18800   │  │            │
        └───────────┘  └─────┬─────┘  └─────┬──────┘
                             │              │
                       ┌─────┴──────────────┴─────┐
                       │                          │
                 ┌─────┴──────┐            ┌──────┴─────┐
                 │ PostgreSQL │            │   Redis    │
                 │  pgvector  │            │ queue+cache│
                 └────────────┘            └────────────┘
                             │
                       ┌─────┴─────┐
                       │ Providers │   Bedrock · local models · Google Chat
                       └───────────┘

Backend — Python 3.12+, FastAPI, SQLAlchemy 2 async, PostgreSQL with pgvector, Redis, Taskiq workers. Each module splits into domain → application → infrastructure → presentation, with one-way dependencies. domain depends on nothing.

Frontend — React 19, TypeScript, Vite, Tailwind v4, shadcn/ui, Zustand. App-wide session and shell state live in src/app; feature and server-cache state live in feature stores; long-running page workflows live in feature controllers.

Both retrieval channels live in PostgreSQL. There is no separate vector database — one store means one transaction boundary and one backup.

External vendors are kept at arm's length. Every integration separates a Platform Protocol (what CAOS expects, in product language), an Adapter Protocol, and a Vendor Implementation — the only layer importing the SDK. This is why embedding and reranking run on pinned local models or on Bedrock with no application code aware of which.

Detail: architecture · integration boundaries


How data flows

A document becomes retrievable. Upload → immutable version → durable ingestion job → commit → dispatch to a worker → extract passages of ≤1,500 characters, each keeping a citation locator (PDF page, DOCX paragraph, XLSX sheet/row/cell) → generate embeddings → searchable. The job commits before dispatch, so a queue failure becomes a visible retryable state rather than an invisible pending row.

A questionnaire becomes answered work. Upload → faithful row views → you map rows and answer targets → one workspace item per answerable row, each pointing at its exact source cells → autosave drafts → explicit completion with an expected-revision compare-and-set, so a stale tab gets 409 rather than overwriting a colleague.

Download Tool