Open Source by Accenture

Cloud compliance assessments
in minutes, not months.

SWAO (Sovereign Workload Assessment and Onboarding) analyses your cloud workloads against industry compliance frameworks, produces audit-grade evidence, and generates a migration plan -- all in a single command. Community Edition is free and open source.

Why SWAO?

Traditional cloud compliance assessments take weeks of manual effort across multiple teams. SWAO compresses the entire workflow into a single automated pipeline -- from code to compliance evidence to migration plan.

Speed

Weeks to minutes

A full framework evaluation -- source code, infrastructure, dynamic UI -- completes in minutes. What used to require a team of consultants and a spreadsheet now runs from a single command. Re-assess after every change to catch compliance drift early.

Evidence

Audit-ready by design

Every finding cites the exact file, line number, or screen element that triggered it. SWAO produces HTML evidence packs, Power BI dashboards, and structured JSON that auditors and GRC platforms can consume directly -- no manual transcription.

Sovereignty

Your data stays yours

Runs on your own infrastructure. Choose your LLM provider (Anthropic, Ollama, AWS Bedrock, or Vertex AI). Secret redaction runs before any external call. Built for regulated industries where data residency is non-negotiable.

Built for every role in your programme

From the consultant running the assessment on a laptop to the CISO signing off on compliance evidence -- SWAO serves each stakeholder with the output they need.

Cloud Migration Consultants

Compress 7R engagements from weeks to days

Run a full Rehost / Replatform / Refactor analysis for an application in a single command. SWAO produces a portable Workload Sovereignty Profile (WSP) that carries the assessment forward into planning and onboarding -- no re-entry, no drift between phases.
  • Single binary, works on a laptop or client-hosted container
  • Unlimited assessments in Community Edition (no licence required)
  • Interactive TUI for guided exploration of findings
  • Generates migration runbook, risk register, and training plan
Compliance and Risk Officers

Audit-ready evidence, generated automatically

Every SWAO finding links back to the specific file, configuration line, or screen element that triggered it. Multi-regime assessments (GDPR + HIPAA + COBIT 5 in a single run) give a complete picture without duplicate effort.
  • HTML evidence packs and structured JSON for GRC platforms
  • Full human-override audit trail -- every manual decision is logged
  • GDPR, HIPAA, AI 10 Pillars, COBIT 5, NIST SP 800-66 R2 included free
  • Confidence scoring flags areas that need human review
Enterprise and Cloud Architects

From compliance gaps to sovereign landing zones

SWAO maps workload constraints to a target landing zone and emits a Terraform module tailored to your cloud provider and sovereign requirements. One assessment drives both compliance evidence and infrastructure design.
  • Landing Zone Assessment: fit/gap vs. your existing landing zone
  • meshStack Developer Portal Building Block deployment
  • Pluggable VCS, scanner, and tracker connectors
  • Portfolio assessment and wave planning (Enterprise Edition)
Developers and DevSecOps Teams

Compliance checks inside your development workflow

The SWAO MCP server lets AI coding assistants such as Claude Code and Cursor query your compliance findings directly from the editor. Ask about control status, browse blockers, and get remediation guidance without leaving your workflow.
  • MCP server on localhost:3737 -- connects to Claude Code and Cursor
  • Integrate findings into Jira, GitHub Issues, or Azure Boards
  • SAST, container scan, IaC scan, and secrets detection built in
  • Re-assess after every PR to detect compliance regression

How SWAO works

A 13-pass analysis pipeline reads your workload, evaluates it against compliance frameworks, and produces a single portable artefact -- the Workload Sovereignty Profile -- that drives everything downstream.

1. Input Sources
Source code repository
Infrastructure as Code (Terraform, Helm)
CMDB / FinOps data export
Dynamic web UI (Playwright crawl)
Workshop transcripts / runbooks
Your LLM (bring your own)
Anthropic Claude
Ollama (fully local)
AWS Bedrock / Vertex AI
2. Analysis Pipeline (13 Passes)
01Inventory
02State
03Data Class.
04Context
05SBOM
06Terraform
07Egress
08Crypto
09Synthesis
10Dynamic UI
11Compliance
12Blockers
13Scope & 7R Disposition
Each pass adds findings to the Workload Sovereignty Profile (WSP) -- a versioned YAML artefact that carries the full assessment state forward into planning and onboarding.
3. Output Artefacts
WSP.yaml Portable, versioned, machine-readable -- flows into planning and onboarding
HTML Evidence Report Per-control findings with file:line traceability
7R Disposition Rehost / Replatform / Refactor / Repurchase / Retire / Retain / Relocate
Migration Runbook Risk register, data plan, rollback plan, training plan
Terraform Scaffold Landing zone tailored to workload's sovereign constraints
Power BI / CSV / JSON For dashboards, GRC platforms, and portfolio roll-ups
Deployment Mode A

Consultant laptop

Single binary or Docker container. Install and run the first assessment in under 10 minutes. Ideal for discovery workshops and client demos. No infrastructure to provision.

Deployment Mode B

Client-hosted

Docker or Kubernetes on the client's own infrastructure. Source code never leaves the client environment. Preferred for regulated industries with strict data residency requirements.

Deployment Mode B-DevX

meshStack Building Block

SWAO deployed as a Developer Portal Building Block on meshStack. Application teams self-serve assessments from the platform they already operate -- no consultant needed for each run.

Community Frameworks

Five compliance frameworks included in every edition -- free, open, and continuously updated. No licence required to run any of them.

GDPR HIPAA AI 10 Pillars COBIT 5 NIST SP 800-66 R2
GDPR EU / Data Privacy

The General Data Protection Regulation is the European Union's primary law governing the collection, processing, and storage of personal data for EU residents. It applies to any organisation -- worldwide -- that processes EU citizen data.

Assessment benefit: SWAO evaluates 47 controls covering data residency enforcement, consent management, retention policies, encryption at rest and in transit, data subject rights, and breach notification readiness. Each finding cites the specific GDPR article and the code or configuration that triggered it.
HIPAA US / Healthcare

The Health Insurance Portability and Accountability Act establishes US federal requirements for protecting Protected Health Information (PHI) in any system that stores, transmits, or processes patient data. Mandatory for all US healthcare entities and their business associates.

Assessment benefit: SWAO checks administrative, physical, and technical safeguards -- ePHI encryption, workforce access controls, audit logging, automatic logoff, data backup, and disaster recovery configurations -- against the HIPAA Security Rule's required and addressable implementation specifications.
AI 10 Pillars Responsible AI

Accenture's Responsible AI framework defines ten pillars for building and deploying AI systems that are fair, transparent, and accountable. It covers the full AI lifecycle -- from data sourcing and model design through deployment and monitoring.

Assessment benefit: SWAO assesses AI and ML workloads against all ten pillars: fairness, transparency, explainability, robustness, privacy, security, reliability, inclusiveness, accountability, and sustainability. Identifies gaps in model governance, bias controls, explainability tooling, and audit logging.
COBIT 5 IT Governance

Control Objectives for Information and Related Technologies (COBIT 5) is ISACA's globally recognised IT governance and management framework. It maps IT activities to business goals across five domains and 37 processes -- widely used by CISOs and internal audit teams worldwide.

Assessment benefit: SWAO maps your workload's IT controls to COBIT 5 processes across the Evaluate-Direct-Monitor (governance) and Align-Plan-Organise, Build-Acquire-Implement, Deliver-Service-Support, Monitor-Evaluate-Assess (management) domains. Ideal for regulated enterprises with a COBIT-aligned internal audit function.
NIST SP 800-66 R2 US / Healthcare (NIST)

NIST Special Publication 800-66 Revision 2 provides prescriptive implementation guidance for the HIPAA Security Rule. Where HIPAA defines the regulatory requirements, NIST SP 800-66 R2 specifies concrete technical controls -- making it the reference of choice for healthcare organisations seeking NIST alignment alongside HIPAA compliance.

Assessment benefit: 9 control families and 66 individual controls across Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Contingency Planning (CP), Identification and Authentication (IA), Incident Response (IR), Risk Assessment (RA), System and Communications Protection (SC), and System and Information Integrity (SI). Run alongside the HIPAA framework for a complete regulatory and implementation-guidance picture.

Build your own framework

Not covered by the five community frameworks? SWAO's framework format is a plain YAML file -- no TypeScript, no compilation, no specialist tooling required. Define your own controls, risk levels, remediation guidance, and regime metadata. Point SWAO at your YAML file and it runs immediately alongside the community frameworks.

Custom frameworks are ideal for internal security policies, client-specific contractual requirements, sector-specific regulations not yet in the community catalogue, or proprietary control frameworks. Contribute your framework back to the community via a GitHub pull request and help the ecosystem grow.

Framework authoring guide Share your framework

Getting started in four steps

From a fresh install to a full compliance report in under 15 minutes.

1
Install and initialise

Download the SWAO binary and run swao init to configure your workspace, LLM provider, and target compliance frameworks via a guided wizard.

2
Run an assessment

Point SWAO at your application repository. Static code analysis, dynamic UI crawling (Playwright), SBOM generation, and secret detection run automatically across 13 passes.

3
Review findings

Explore results in the interactive TUI or HTML evidence report. Filter by severity, framework control, or file path. Every finding links back to the exact source that triggered it.

4
Plan and migrate

Export a migration runbook, risk register, and Terraform landing-zone scaffold. Re-assess after remediation to track compliance improvement over time.

Choose your edition

Community Edition is free and Apache 2.0 licensed. Consultant and Enterprise editions add production outputs, portal integration, and programme-scale capabilities via Accenture Professional Services.

Feature Community Consultant Enterprise
Assessment Types
Application Assessment (AI-assisted: static, dynamic, SBOM) Yes Yes Yes
Audit Assessment (human checklist-driven, no LLM required) Yes Yes Yes
Landing Zone Assessment (fit/gap vs. your existing LZ) Yes Yes Yes
Portfolio Assessment (100+ apps, wave planning) - - Yes
Tools and Interface
CLI and interactive TUI Yes Yes Yes
LLM integration (Anthropic, Ollama, AWS Bedrock, Vertex AI) Yes Yes Yes
MCP server (Claude Code, Cursor, and other AI tools) - Yes Yes
Frameworks
5 Community Frameworks (GDPR, HIPAA, AI 10 Pillars, COBIT 5, NIST SP 800-66 R2) Yes Yes Yes
Reports and Outputs
HTML evidence report Yes Yes Yes
Portal and programme dashboard - Yes Yes
PDF report (branded with licensee details) - Yes Yes
Power BI export (.pbit template for dashboards and trends) - Yes Yes
Terraform and landing zone generation - - Yes
Licence and Support
Licence Apache 2.0 Proprietary Proprietary
Support GitHub Discussions Accenture PS Accenture PS

Get involved

SWAO is open source. Whether you are building with SWAO, contributing frameworks, or exploring an Accenture-led migration engagement, there is a path for you.

💬

Community Discussions

Ask questions, share custom frameworks, report issues, and follow release announcements on GitHub Discussions. The SWAO development team monitors this channel and welcomes community contributions.

Open Discussions
🏢

Accenture Professional Services

For Consultant or Enterprise Edition licences, programme-scale deployments, meshStack integration, or a guided cloud migration engagement, reach out via GitHub Discussions or your Accenture account team.

Contact via Discussions