
Discovery 001 · Security Operations
Veckl
Launched· AlphaGit-backed security control testing for connected and disconnected environments.
Veckl gives security and compliance teams a web interface for creating, executing, and reviewing NIST 800-53 control test cases. It runs locally, on Kubernetes, or as a Zarf package for disconnected environments.
The Problem
Security control testing produces records that must remain inspectable, reviewable, and portable over time. Conventional test management systems often place that history inside a separate application database or audit layer.
The Git Expansion
Veckl makes GitHub or GitHub Enterprise Server the system of record. Test cases live as Markdown with YAML frontmatter, and every change becomes part of ordinary Git history. Git is not merely where Veckl's code is stored; it is the data model, review workflow, and durable audit trail for the work Veckl manages.
Operational Capabilities
What Veckl helps crews do
- 01Create, edit, execute, and review security control test cases
- 02Select controls from a NIST 800-53-backed catalog
- 03Record step-by-step execution results
- 04Review every change through Git history
- 05Deploy locally, on Kubernetes, or with Zarf in disconnected environments
Intended Crew
- Security and compliance teams
- GitHub and GitHub Enterprise Server administrators
- Platform engineers supporting connected or air-gapped environments
Mission Status
Alpha release
Veckl's first public alpha is available for self-hosted evaluation. Expect active development and changes informed by field feedback.
Technical Profile
- License
- Apache-2.0
- Operating model
- Self-hosted
- Maintainer
- Thomas Hinson