PolicyPress is live on the GitHub Marketplace

SC2 launches PolicyPress - write policies in Markdown, publish a branded site and versioned PDFs from one GitHub Action. Free for your own organization.

SC2 published on
3 min, 447 words

PolicyPress, our compliance policy toolchain, is now available on the GitHub Marketplace. Write your security policies in Markdown, keep them in your own Git repository, and a single GitHub Action publishes a branded policy site and versioned, audit-ready PDFs on every push.

Who it’s for

If your organization’s policies live in a Word document someone emailed around - nobody sure which version is current, who approved it, or when it was last reviewed - PolicyPress is for you. It sits deliberately between the two usual answers: GRC suites priced for enterprises, and wikis that can’t produce the versioned, signed-off PDF trail an auditor or customer actually asks for.

You do not need to know anything about web development, LaTeX, or compliance frameworks. If you can click a button on GitHub and edit a text file, you can have a professional policy library in an afternoon - and because PolicyPress is the toolchain, not the content, your policies never leave your infrastructure.

What you get

  • A policy website your employees can bookmark, branded with your logo and colors, with a dashboard homepage computed from the policies themselves
  • A versioned PDF for every policy, named by title and version, plus full revision history - who approved what, and when
  • Draft watermarks and redaction - policies under review are clearly marked, and internal notes are stripped from published PDFs
  • Compliance mapping - tag policies with Secure Controls Framework and SOC 2 control IDs and get coverage reports as versioned PDFs
  • Opt-in extras for procurement and audit: tagged accessible PDFs (PDF/UA-1), a machine-readable audit bundle with SHA-256 hashes of every artifact, and private-by-default publishing with a turnkey SSO configuration

Free for your own organization

PolicyPress is free to run for your own organization at any size - nonprofit, school, government body, or for-profit company - under the PolyForm Noncommercial and Internal Use licenses. Payment enters only when you want SC2 to stand behind it (a support subscription) or when you use PolicyPress to serve third parties, such as an MSP running it for clients or a hosted offering. Details are on the project page.

Get started


Questions about standing up a policy library for your organization? Contact SC2 — we help small and mid-sized teams build practical, proportionate security programs, and PolicyPress is how we make the paperwork part painless.