View full size
AuditYote
Live · Java, Spring Boot, React, PostgreSQL
A full-stack governance, risk, and compliance app. It logs security findings, maps each one to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0, and moves it through a role-gated review and sign-off workflow with separation of duties enforced on the server. It scores risk, tracks program-wide posture, keeps an audit trail, and exports CSV and PDF reports. Access runs through Spring Security with session authentication and role-based access control. The app is containerized, scanned in CI with Semgrep and Trivy, and deployed over HTTPS.
The live site is open to explore. Demo logins for both the analyst and reviewer roles are on the sign-in screen.





