The toolshop¶
Small tools, skills and automations that make security and compliance work easier. Built in the open, shared as they mature.
My tools¶
ISO 27001 Implementation Kit
Seventeen documents and a 27-tab workbook that take an organisation from nothing to certified against ISO/IEC 27001:2022. Every requirement of Clauses 4 to 10 and all 93 Annex A controls sits as its own row with an owner, a status, a date and an evidence pointer, so nothing can be quietly skipped and the dashboard counts what is left. Free download, no sign-up, adapt as you like.
sameerkhairkar.comSCF Scoping Tool
The Secure Controls Framework maps 1,534 controls to 252 laws and frameworks across 44 countries. Almost nobody needs all 252. Say where you operate and what business you are in, and get the control set that actually applies — with the legal basis for each one, a scoped assessment workbook, an evidence request list, and a coverage map. Ships as a builder you run against your own SCF download, because the framework is NoDerivatives licensed.
sameerkhairkar.comDPIA + FRIA joint assessor
A decision wizard and combined workbook for the GDPR Data Protection Impact Assessment and the AI Act Fundamental Rights Impact Assessment as one exercise. Tallies the nine WP248 criteria and the Article 27(1) deployer test in parallel, drives a four-way verdict, and exports the joint record as print, markdown or standalone HTML. One self-contained page, zero third-party requests.
sameerkhairkar.comTPRM Assessment Toolkit
A DORA-aligned third-party risk assessment workbook, eight tabs, wired so the critical-or-important-function decision drives the assessment tier, the due-diligence depth and the Article 30 contract clauses. Comes with a process document and flowchart. Free download, adapt as you like.
sameerkhairkar.comDORA Navigator
The entire DORA package — 14 legal acts, 215 articles, 6 themes — as one interactive map. Four views (network, an implements-flow of which act details which article, a hierarchy wheel, and a treemap), full article text with clickable cross-references, and search by title, keyword or CELEX. One self-contained page, zero third-party requests.
github.comYaksha
A deterministic, report-only vulnerability and hardening scanner for Windows. It correlates dependency CVEs against CISA KEV and EPSS, audits configuration against CIS and DISA-STIG, checks autostart entries for persistence, and maps everything to MITRE ATT&CK. Runs twice a day and never changes your machine. MIT licensed.
Tools I'm watching¶
Not mine, but on my radar. Open tools relevant to security and compliance work with AI.
SkillSpector
NVIDIA's security scanner for AI agent skills. Checks for 64 vulnerability patterns, including prompt injection and data exfiltration.
github.comClawShield
A security proxy that sits in front of an AI agent and scans every message for prompt injection, PII leaks and policy violations.
github.comDecepticon
An autonomous red-team agent. Interesting for testing your own defences, with the usual caution that applies to offensive tooling.
owasp.orgCVE Lite CLI
Free, local-first vulnerability scanner for JS and TS projects from OWASP. No cloud, no account.
github.comEU compliance MCP server
An MCP server that serves EU regulation content to AI assistants. Free tier is limited, but the approach points where compliance tooling is going.