"Vibe-Trading: Your Personal Trading Agent"
GRC platform for risk, compliance, audit, and reporting
CISO Assistant is a self-hosted governance, risk, and compliance platform with built-in frameworks, control mapping, evidence tracking, and reporting. It works as a web app first, with extra CLI, MCP, and automation pieces for loading libraries and integrating with other systems.
People who need to run risk and compliance work in one system across many frameworks.
You can manage controls, risks, audits, and evidence in one place instead of spreading the work across separate spreadsheets and tools.
What it does
Framework library
Includes 200+ frameworks such as ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, and HIPAA.
Automatic control mapping
Maps controls across frameworks so you can reuse assessments and compare scopes without rebuilding everything by hand.
Risk and remediation workflows
Supports risk assessments, registers, acceptance flows, action plans, findings, and tracking for remediation work.
Audit and evidence management
Handles audits, campaigns, documents, evidence, and quality checks in the same system.
Integration and automation
Provides a REST API, CLI, Kafka integration, MCP support, and webhooks for external automation and imports.
Access and reporting
Includes RBAC, SSO, MFA, audit logs, dashboards, reports, and custom metrics.
How to get it
- 1clone the repo
git clone --single-branch -b main https://github.com/intuitem/ciso-assistant-community.git
- 2and run the starter script
./docker-compose.sh # Linux/MacOS ./docker-compose.ps1 # Windows
README
Star the project 🌟 to get releases notification and help growing the community!
intuitem.com
·
SaaS Free trial
·
Roadmap
·
Docs
·
Languages
·
Discord
·
Frameworks

CISO Assistant offers a fresh perspective on Cybersecurity Management and GRC (Governance, Risk, and Compliance) practices:
- Designed as a central hub to connect multiple cybersecurity concepts with smart linking between objects,
- Built as a multi-paradigm tool that adapts to different backgrounds, methodologies, and expectations,
- Explicitly decouples compliance from cybersecurity controls, enabling reusability across the platform,
- Promotes reusability and interlinking instead of redundant work,
- Developed with an API-first approach to support both UI interaction and external automation,
- Comes packed with a wide range of built-in standards, security controls, and threat libraries,
- Offers an open format to customize and reuse your own objects and frameworks,
- Includes built-in risk assessment and remediation tracking workflows,
- Supports custom frameworks via a simple syntax and flexible tooling,
- Provides rich import/export capabilities across various channels and formats (UI, CLI, Kafka, reports, etc.).

Our vision is to create a one-stop-shop for cybersecurity management—modernizing GRC through simplification and interoperability.
As practitioners working with cybersecurity and IT professionals, we've faced the same issues: tool fragmentation, data duplication, and a lack of intuitive, integrated solutions. CISO Assistant was born from those lessons, and we're building a community around pragmatic, common-sense principles.
We’re constantly evolving with input from users and customers. Like an octopus 🐙, CISO Assistant keeps growing extra arms—bringing clarity, automation, and productivity to cybersecurity teams while reducing the effort of data input and output.
Quick Start 🚀
[!TIP] The easiest way to get started is through the free trial of cloud instance available here.
Alternatively, once you have Docker and Docker-compose installed, on your workstation or server:
clone the repo:
git clone --single-branch -b main https://github.com/intuitem/ciso-assistant-community.git
and run the starter script
./docker-compose.sh # Linux/MacOS
./docker-compose.ps1 # Windows
If you are looking for other installation options for self-hosting, check the config builder and the docs.
[!NOTE] The docker-compose script uses prebuilt Docker images supporting most of the standard hardware architecture. If you're using Windows, make sure to have Docker Desktop with WSL2 installed and trigger the PowerShell script. It will feed Docker Desktop on your behalf.
The docker compose file can be adjusted to pass extra parameters to suit your setup (e.g. Mailer settings).
[!WARNING] If you're getting warnings or errors about image's platform not matching host platform, raise an issue with the details and we'll add it shortly after. You can also use
docker-compose-build.shinstead (see below) to build for your specific architecture.
[!CAUTION] Don't use the
mainbranch code directly for production as it's the merge upstream and can have breaking changes during our development. Either use thetagsfor stable versions or prebuilt images.
Features

📋 Full feature list — click to expand (searchable, 59 features)
Compliance & frameworks
- Audit and campaigns management
- Automatic mapping
- Mapping explorer
- Custom frameworks supported
- +200 frameworks included
- Policies management
- Document management
- Evidence management
Risk management
- Risk assessments and registers
- EBIOS RM module
- Risk acceptance workflows
- Business Impact Analysis
- Cyber Risk Quantification
- Vulnerability management
- Vulnerability enrichment
Third-party risk
- Third-party risk management
Operations & remediation
- Action plan tracking and prioritization
- Findings tracking
- Recommendations engine
- Control plan
- Task management
- Kanban boards
- Periodic checks
- Technical posture management
- Exceptions tracking
- Incidents management
- Validation & approval flows
- Email reminders
Reporting & analytics
- Analytics and dashboards
- Reports generation
- Automated quality checks
- Advanced insights
- Custom metrics tracking
Collaboration & productivity
- Assignments & respondent mode
- Comments & collaboration
- Universal search
- Command palette
Automation & integrations
- Comprehensive REST API
- CLI for automation
- Data import wizard
- Kafka integration
- MCP support
- Outgoing webhooks
- Jira & ServiceNow integrations
- Consultant features (e.g. single-domain export/import)
Security & access
- Flexible RBAC
- SSO with SAML or OIDC
- MFA with TOTP and security keys
- SCIM provisioning
- Audit log
Privacy
- GDPR processings
Programme management
- Project management
- Responsibility matrices
Platform
- Portals & trust center
- Custom fields
- Multi-level domains
- Kubernetes (Helm) deployment
- Open Source
- Available in +26 languages
Upcoming features are listed on the roadmap.
CISO Assistant is developed and maintained by Intuitem, a company specialized in Cybersecurity, Cloud, and Data/AI.
Core Concepts
Here’s an extract of some of the building blocks in CISO Assistant to illustrate the decoupling concept that encourages reusability:

For full details, check the data model documentation.
Decoupling Concept
At the heart of CISO Assistant lies the decoupling principle, which enables powerful use cases and major time savings:
- Reuse past assessments across scopes or frameworks,
- Evaluate a single scope against multiple frameworks simultaneously,
- Let CISO Assistant handle reporting and consistency checks so you can focus on remediation,
- Separate control implementation from compliance tracking.
Here is an illustration of the decoupling principle and its advantages:
https://github.com/user-attachments/assets/87bd4497-5cc2-4221-aeff-396f6b6ebe62
System architecture

End-user Documentation
Check out the online documentation on https://intuitem.gitbook.io/ciso-assistant.
Setting up the local AI engine
Read more here: AI engine
Supported frameworks 🐙
- ISO 27001:2013 & 27001:2022 🌐
- NIST Cyber Security Framework (CSF) v1.1 🇺🇸
- NIST Cyber Security Framework (CSF) v2.0 🇺🇸
- NIS2 🇪🇺
- SOC2 🇺🇸
- PCI DSS 4.0.1 💳
- CMMC v2 🇺🇸
- PSPF 🇦🇺
- General Data Protection Regulation (GDPR): Full text and checklist from GDPR.EU 🇪🇺
- Essential Eight 🇦🇺
- NYDFS 500 with 2023-11 amendments 🇺🇸
- DORA (Act, RTS, ITS and GL) 🇪🇺
- NIST AI Risk Management Framework 🇺🇸🤖
- NIST SP 800-53 rev5 🇺🇸
- Règles OIV - Secteur « Activités civiles de l'Etat » (2019) 🇫🇷
- CCB CyberFundamentals Framework 🇧🇪
- NIST SP-800-66 (HIPAA) 🏥
- HDS/HDH 🇫🇷
- OWASP Application Security Verification Standard (ASVS) 4 🐝🖥️
- RGS v2.0 🇫🇷
- AirCyber ✈️🌐
- Cyber Resilience Act (CRA) 🇪🇺
- TIBER-EU 🇪🇺
- NIST Privacy Framework 🇺🇸
- TISAX (VDA ISA) v5.1, v6.0 and v2027 🚘
- ANSSI hygiene guide 🇫🇷
- Essential Cybersecurity Controls (ECC) 🇸🇦
- CIS Controls v8* 🌐
- CSA CCM (Cloud Controls Matrix)* ☁️
- FADP (Federal Act on Data Protection) 🇨🇭
- NIST SP 800-171 rev2 (2021) 🇺🇸
- ANSSI : Recommandations de sécurité pour un système d'IA générative (v1.0) 🇫🇷🤖
- NIST SP 800-218: Secure Software Development Framework (SSDF) 🖥️
- GSA FedRAMP rev5 ☁️🇺🇸
- Cadre Conformité Cyber France (3CF) v1 (2021) ✈️🇫🇷
- ANSSI : SecNumCloud ☁️🇫🇷
- Cadre Conformité Cyber France (3CF) v2 (2024) ✈️🇫🇷
- ANSSI : outil d’autoévaluation de gestion de crise cyber 💥🇫🇷
- BSI: IT-Grundschutz-Kompendium 🇩🇪
- NIST SP 800-171 rev3 (2024) 🇺🇸
- ENISA: 5G Security Controls Matrix 🇪🇺
- OWASP Mobile Application Security Verification Standard (MASVS) 🐝📱
- Agile Security Framework (ASF) - baseline - by intuitem 🤗
- ISO 27001:2013 🌐 (For legacy and migration)
- EU AI Act 🇪🇺🤖
- FBI CJIS 🇺🇸👮
- Operational Technology Cybersecurity Controls (OTCC) 🇸🇦
- Secure Controls Framework (SCF) 🇺🇸🌐
- NCSC - Cyber Assessment Framework (CAF) v3.2 🇬🇧
- California Consumer Privacy Act (CCPA) 🇺🇸
- California Consumer Privacy Act Regulations 🇺🇸
- NCSC Cyber Essentials 🇬🇧
- Directive Nationale de la Sécurité des Systèmes d'Information (DNSSI) Maroc 🇲🇦
- Part-IS (Consolidated 16-10-2025) ✈️🇪🇺
- ENS Esquema Nacional de seguridad 🇪🇸
- Korea ISA ISMS-P 🇰🇷
- Swiss ICT minimum standard 🇨🇭
- Adobe Common Controls Framework (CCF) v5 🌐
- BSI Cloud Computing Compliance Criteria Catalogue (C5) 🇩🇪
- Référentiel d’Audit de la Sécurité des Systèmes d’Information, ANCS Tunisie 🇹🇳
- ECB Cyber resilience oversight expectations for financial market infrastructures 🇪🇺
- Mindeststandard-des-BSI-zur-Nutzung-externer-Cloud-Dienste (Version 2.1) 🇩🇪
- Formulaire d'évaluation de la maturité - niveau fondamental (DGA) 🇫🇷
- NIS2 technical and methodological requirements 2024/2690 🇪🇺
- Saudi Arabian Monetary Authority (SAMA) Cybersecurity Framework 🇸🇦
- Guide de sécurité des données (CNIL) 🇫🇷
- International Traffic in Arms Regulations (ITAR) 🇺🇸
- Federal Trade Commission (FTC) Standards for Safeguarding Customer Information 🇺🇸
- OWASP's checklist for LLM governance and security 🌐
- ANSSI : Recommandations pour les architectures des systèmes d’information sensibles ou à diffusion restreinte (v1.2) 🇫🇷
- CIS Benchmarks — Kubernetes (v1.10, v2.0.1), AWS, Azure, GCP, Microsoft 365, Google Workspace, GitHub, GitLab, Debian 12/13, Ubuntu 24.04 LTS, Windows 11 🌐
- De tekniske minimumskrav for statslige myndigheder 🇩🇰
- Google SAIF framework 🤖
- ANSSI : Recommandations relatives à l'administration sécurisée des SI (v3.0) 🇫🇷
- Prudential Standard CPS 230 - Operational Risk Management (APRA) 🇦🇺
- Prudential Standard CPS 234 - Information Security (APRA) 🇦🇺
- Vehicle Cyber Security Audit (VCSA) v1.1 🚘
- Cisco Cloud Controls Framework (CCF) v3.0 ☁️🌐
- FINMA - Circular 2023/01 - Operational risks and resilience - Banks 🇨🇭
- Post-Quantum Cryptography (PQC) Migration Roadmap (May 2025) 🔐
- Cloud Sovereignty Framework - 1.2.1 - Oct 2025 🇪🇺
- ISO 22301:2019 outline - Business continuity management systems 🌐
- CCB CyberFundamentals Framework 2025 🇧🇪
- Prestataires de détection des incidents de sécurité (PDIS) - Référentiel d’exigences 🇫🇷
- Vendor Due Diligence - simple baseline - intuitem 🌐
- ANSSI : Points de contrôle Active Directory (AD) (Avril 2026) 🇫🇷
- ISO 42001:2023 outline - Artificial Intelligence Management System, including Annex A 🤖🌐
- India's Digital Personal Data Protection Act (DPDPA) - 2023 🇮🇳
- E-ITS (Estonia's national cyber security standard) - 2024 🇪🇪
- Microsoft cloud security benchmark v1 - ☁️🌐
- Baseline informatiebeveiliging Overheid 2 (BIO2) 🇳🇱
- ANSSI : Questionnaire MonAideCyber 🇫🇷
- ITSP.10.171 - Protecting specified information in non-Government of Canada systems and organizations 🇨🇦
- CISA Vendor Supply Chain Risk Management (SCRM) Template 🇺🇸
- European Sustainability Reporting Standards (ESRS) 🇪🇺
- ITIL 4 Management Practices 🌐
- NOREA - DORA in Control Framework v3.0 🇪🇺
- NIS-1 transposition FR 🇫🇷
- PSSI État 🇫🇷
- Checklist de dossier d'homologation 🇫🇷
- Cahier des charges Label EBIOS RM v3.1 🇫🇷
- SecNumCloud v3.2 Annexe 2 : Recommandations aux commanditaires ☁️🇫🇷
- CCB CyberFundamentals Small - Self assessment 🇧🇪
- Mitre ATT&CK v19.1 - Threats and Mitigations catalog 🌐
- Mitre D3FEND - Reference controls 🌐
- OWASP Top 10 Web - Threat catalog 🐝🌐
- OWASP MAS Threat Modelling Guide - Threat catalog 🐝📱
- CISA Cybersecurity Performance Goals (CPG) v2.0 🇺🇸
- ANSSI : Référentiel Cyber France pour la réglementation NIS2 (ReCyF) 🇫🇷
- Cadre Conformité Cyber France (3CF) v3.1 (2026) ✈️🇫🇷
- Règles OIV - Secteur « Transport aérien » (2016) ✈️🇫🇷
- IEC 62443 series — parts 2-1, 2-4, 3-2, 3-3, 4-1, 4-2 🏭🌐
- CER Directive (Critical Entities Resilience) 🇪🇺
- EUDI ARF — EU Digital Identity Wallet High-Level Requirements (Annex 2.02) 🇪🇺
- UK Defence Standard 05-138 Issue 4 🇬🇧
- Référentiel HAS - Certification des établissements de santé pour la qualité des soins 🇫🇷🏥
- Personal Data Protection Law (PDPL) 🇸🇦
- NCSC - Cyber Assessment Framework (CAF) v4.0 🇬🇧
- Algemene Beveiligingseisen voor Rijksoverheidsopdrachten (ABRO) 2026 🇳🇱
- Algemene Beveiligingseisen voor Defensieopdrachten (ABDO) 2019 🇳🇱
- ANSSI : Cybersécurité des systèmes industriels - Mesures détaillées 🇫🇷🏭
- Cbw (NIS2) Control Framework v1.2 🇳🇱
- ENISA SME Cyber Resilience Maturity Assessment (CRA) 🇪🇺
- ISO 27701:2025 outline - Privacy Information Management System, including Annex A 🌐
- Plumber CI/CD Security Checks 🖥️
- UNESCO AI Maturity Framework 🤖🌐
Community contributions
- PGSSI-S (Politique Générale de Sécurité des Systèmes d'Information de Santé) 🇫🇷
- ANSSI : Recommandations de configuration d'un système GNU/Linux (v2.0) 🇫🇷
- PSSI-MCAS (Politique de sécurité des systèmes d’information pour les ministères chargés des affaires sociales) 🇫🇷
- ANSSI : Recommandations pour la protection des systèmes d'information essentiels (v1.0) 🇫🇷
- ANSSI : Recommandations de sécurité pour l'architecture d'un système de journalisation (v2.0) 🇫🇷
- ANSSI : Recommandations de sécurité relatives à TLS (v1.2) 🇫🇷
- New Zealand Information Security Manual (NZISM) 🇳🇿
- Clausier de sécurité numérique du Club RSSI Santé 🇫🇷
- Référentiel National de Sécurité de l’Information (RNSI), MPT Algérie 🇩🇿
- Misure minime di sicurezza ICT per le pubbliche amministrazioni, AGID Italia 🇮🇹
- Framework Nazionale CyberSecurity v2, FNCS Italia 🇮🇹
- Framework Nazionale per la Cybersecurity e la Data Protection, ACN Italia 🇮🇹
- PSSIE du Bénin, ANSSI Bénin 🇧🇯
- IGI 1300 / II 901 - Liste des exigences pour la mise en oeuvre d'un SI classifié (ANSSI) 🇫🇷
- Référentiel Général de Sécurité 2.0 - Annexe B2 🇫🇷
- ANSSI : Recommandations sur la sécurisation des systèmes de contrôle d'accès physique et de vidéoprotection (v2.2) 🇫🇷
- ANSSI : Recommandations pour un usage sécurisé d’(Open)SSH (v1.3) 🇫🇷
- ANSSI : Recommandations de sécurité relatives à IPsec pour la protection des flux réseau (v1.1) 🇫🇷
- ANSSI : Recommandations relatives à l'interconnexion d'un système d'information à internet (v3.0) 🇫🇷
- Guides des mécanismes cryptographiques 🇫🇷
- Swift Customer Security Controls Framework (CSCF) v2025 🏦🌐
- OWASP Application Security Verification Standard (ASVS) 5 🐝🖥️
- NIST 800-82 (OT) - appendix 🏭🤖
- RBI Master Direction 2023 - india 🏦🇮🇳
- Loi 05-20 relative à la cybersécurité (Maroc) 🇲🇦
- Lithuanian NIS2 Cybersecurity Law (Kibernetinio saugumo įstatymas) 🇱🇹
- Prestataire d'audit de sécurité des systèmes d'information (PASSI) 🇫🇷
- ANS Programme CaRE - Domaine 2 (Continuité et reprise d'activité, sauvegarde) 🇫🇷🏥
- ANS HospiConnect HOP'EN2 (Sécurisation de l'accès au SIH) 🇫🇷🏥
- Loi n° 09-08 relative à la protection des personnes physiques 🇲🇦
- Checklist des exigences de la Loi n° 09-08 🇲🇦
- Référentiel des exigences de qualification des prestataires de services cloud ☁️🇲🇦
- AI Defense Matrix 🤖🌐
- Zero Trust for Operational Technology (ZT OT) 🇺🇸🏭
- T.C. CBDDO Bilgi ve İletişim Güvenliği Rehberi (BİGR) 🇹🇷
- NCA NCNICC-1:2025 🇸🇦
- NCA ECC-2:2024 🇸🇦
- NCA CCC-1:2020 🇸🇦
[!NOTE] Frameworks with
*require an extra manual step of getting the latest Excel sheet through their website as their license prevent direct usage. You can load the Excel sheet directly as a library.
Checkout the library and tools for the Domain Specific Language used and how you can define your own.
Coming soon
-
Indonesia PDP 🇮🇩
-
OWASP SAMM
-
COBAC R-2024/01
-
ICO Data protection self-assessment 🇬🇧
-
ASD ISM 🇦🇺
-
and much more: just ask on Discord. If it's an open standard, we'll do it for you, free of charge 😉
Add your own custom library
A library can represent a framework, a threat catalog, a set of reference controls, or even a custom risk matrix.
Libraries can now be loaded directly from Excel files. There is no need to manually convert them to YAML beforehand—the conversion is handled internally when an Excel file is uploaded.
Take a look at the tools directory and its dedicated README, which describes the expected format of library source files in Excel. The excel subdirectory contains example XLSX files used as sources for the existing libraries and can be used as templates for creating your own.
To load a library from an Excel file, go to the Governance → Library page, click Load, and select your Excel source file. Any validation or parsing errors will be reported during the import process.
Optional: converting libraries to YAML
While Excel files can be loaded directly, it is still possible to convert library source files to YAML using external Python scripts:
convert_library_v2.pyhelps you generate a library from a simple Excel file. Once your items are structured in the expected format, run the script to produce the corresponding YAML file.- The
toolsdirectory also contains specialized converters for specific frameworks (for example, CIS or CCM Controls).
Creating mapping libraries
To facilitate the creation of mappings between frameworks, you can use the prepare_mapping_v2.py tool. It generates an Excel file based on two existing framework libraries in YAML format. After filling in the mappings, the resulting Excel file can be:
- loaded directly into the application, or
- converted to YAML using
convert_library_v2.py.
Community
Join our open Discord community to interact with the team and other GRC experts.
Testing the cloud version
The fastest and easiest way to get started is through the free trial of cloud instance available here.
Testing locally 🚀
To run CISO Assistant locally in a straightforward way, you can use Docker compose.
- Update docker
Make sure you have a recent version of docker (>= 27.0).
- Clone the repository
git clone --single-branch -b main https://github.com/intuitem/ciso-assistant-community.git
cd ciso-assistant-community
- Launch docker-compose script for prebuilt images:
./docker-compose.sh # Linux/MacOS
./docker-compose.ps1 # Windows
Alternatively, you can use this variant to build the docker images for your specific architecture:
./docker-compose-build.sh # Linux/MacOS
./docker-compose-build.ps1 # Windows
When asked for, enter your email and password for your superuser.
You can then reach CISO Assistant using your web browser at https://localhost:8443/
For the following executions, use "docker compose up" directly.
Setting up CISO Assistant for development
[!WARNING]
Important note for Windows users
The best working solution for users developing on Windows is to use Ubuntu installed on WSL2 (Docker is not required).
It is now also possible to run and develop CISO Assistant natively on Windows without WSL2 nor Docker, but it will require some extra steps. Please note that the native running on Windows is still in EXPERIMENTAL PHASE and should NOT be used if you are unsure of what you are doing, or if you want to ensure stability throughout development. Nevertheless, we would love to hear any suggestions in order to enhance the development experience for Windows users. Please feel free to open an Issue/PR about it!
Requirements
- Python 3.14+
- pip 25.3+
- uv 0.9+
- node 24+
- npm 10.2+
- pnpm 10.30+
- yaml-cpp (
brew install yaml-cpp libyamlorapt install libyaml-cpp-dev)
[EXPERIMENTAL] Additional requirements for development on Windows without WSL2
If you want to develop the project without WSL2, you will need to install MSYS2, add the MSYS2 UCRT64 binaries to your [system PATH environment variable](https://learn.microsoft.com/en-us/powershell/module/microso
Files in the repo
- .claude
- .github
- automation
- backend
- charts
- cli
- config
- dispatcher
- documentation
- enterprise
- frontend
- git_hooks
- integration
- packaging
- perf_testing
- product-docs
- tools
- .dockerignore
- .editorconfig
- .eslintrc.js
- .gitattributes
- .gitignore
- .plumber.yaml
- .pre-commit-config.yaml
- Caddyfile
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
- Contributor License Agreement.md
- conventional_commits.md
- core_objects.png
- docker-compose-build.ps1
- docker-compose-build.sh
- docker-compose-build.yml
- docker-compose.ps1
- docker-compose.sh
- docker-compose.yml
- features.png
- gh_banner.png
- LICENSE-AGPL.txt
- LICENSE.md
- posture.png
- publiccode.yml
- README.md
- reformat.ps1
- reformat.sh
- resources.md
- SECURITY.md
- single_hub.png
- update-ciso-assistant.sh
- X-RAYS_QUALITY_CHECKS.md
Discussion (0)
Ask about usage, or say what you built with itSign in to join the discussion.
No comments yet. Be the first to say what this is good for.
More other

Your Personal AI Assistant; easy to install, deploy on your own machine or on the cloud; supports multiple chat apps with easily extensible capabilities.
macOS video editor built for AI
😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]
AIPOCH Open-Science is an open-source, local-first, model-agnostic AI research workbench for macOS, Windows, and Linux, with scientific agents, Python/R notebooks, data connectors, and reproducible provenance.
Open-source Claude Design alternative. One-click import your Claude Code / Codex API key. Prompt → prototype / slides / PDF. Multi-model (Claude, GPT, Gemini, Kimi, GLM, Ollama). BYOK, local-first, MIT.