Sourcentis creates innovative open-source solutions for information security, trusted by hospitals, laboratories, universities, and banking institutions worldwide.
Our mission: Empower organizations to master their IT systems and security compliance — with tools that are pragmatic, transparent, and within reach.
A comprehensive, open-source information system cartography tool designed to help organizations understand, visualize, and manage their entire IT landscape — from business processes to physical infrastructure.
Built on: PHP, Laravel, Vue.js, PostgreSQL
Why Mercator?
- ANSSI-aligned — Follows French national cybersecurity authority (ANSSI) best practices
- 100% Open Source — GPL license, fully transparent, no lock-in
- 7 Complementary Views — From GDPR records to ecosystem dependencies, application stacks, infrastructure, and more
- Interactive Dependency Analysis — Click any asset to explore upstream/downstream dependencies and detect single points of failure
- API-First — Complete REST API for seamless integration with your existing tools
- BPMN 2.0 Support — Bridge the gap between business processes and technical infrastructure
- Compliance-Ready — Auto-generates maturity scores, audit reports (PDF, Excel, CSV), and NIS2/ISO 27001 compliance evidence
Key Features:
- Dynamic dashboards and asset tracking
- Built-in impact analysis for change management
- Support for multiple integrations (Active Directory, VMware, GLPI, ServiceNow, Kubernetes)
- Governance and access control management
- Risk visualization and compliance tracking
Deployed in: 30+ countries across hospitals, research centers, universities, government agencies, and enterprises.
Community Recognition:
- 🏆 OW2 Best Open Source Project 2024
- 500+ GitHub stars
- Featured at Voxxed Days 2025, SSTIC 2023, Hack.lu 2024
Get Started:
A dedicated open-source platform for centralized management, planning, monitoring, and reporting of security control effectiveness — ensuring organizations stay compliant with ISO 27001, ISO 27004, NIS2, DORA, HDS, PCI-DSS, and more.
Built on: PHP, Laravel, Vue.js, PostgreSQL
Why Deming?
- ISO 27004 Compliant — Designed to measure and demonstrate control effectiveness, not just compliance checkboxes
- 100% Open Source — GPL license, full transparency, no proprietary modules
- Centralized Control Management — Single source of truth for all security measures, evidence, and indicators
- Real-Time Dashboards — Customizable KPIs for continuous ISMS improvement
- Flexible Referential Framework — Out-of-the-box support for ISO 27001, DORA, NIS2, HDS, PCI-DSS; add custom referentials via Excel templates
- Evidence & Audit Trail — Comprehensive tracking of all control activities and compliance actions
- Collaborative Workflows — Assign responsibilities, schedule audits, track progress across teams
Key Features:
- Control planning and scheduling with automatic reminders
- Evidence attachment and version control
- Audit-ready reporting
- Multi-referential mapping
- Role-based access and audit logs
- Integration with external systems via API
Community Recognition:
- 🏆 OW2 Project of the Month (October 2024)
- Featured in Linux Pratique #148
- Presented at Hack.lu 2023, African Cybersecurity Resource Center
Get Started:
| Feature | Sourcentis | Typical Proprietary Tools |
|---|---|---|
| Cost | Free, forever | Expensive per-user licensing |
| Transparency | Full source code available | Black box |
| Customization | Modify, fork, adapt freely | Locked to vendor roadmap |
| Integration | Full API, multiple connectors | Limited integrations |
| Lock-in | None — you own your data | Vendor dependency |
| Compliance | ANSSI-aligned, NIS2-ready | Generic compliance support |
- 15,000+ organizations downloading our tools
- 30+ countries with active installations
- 500+ GitHub stars for Mercator
- Trusted by: Hospitals, Universities, Research Centers, Major Enterprises
- Recognition: OW2 Best Project 2024, Linux Pratique, SSTIC, Hack.lu
Sourcentis offers professional support contracts including:
- Guaranteed response times (4h to 48h depending on severity)
- Dedicated email support with assigned contact
- Critical patches within 5 business days
- Implementation and onboarding assistance
- Advanced knowledge base access
Who should contract support?
- Healthcare providers and HDS-regulated entities
- NIS2 essential/important infrastructure operators
- Large organizations with mission-critical deployments
- Any context requiring contractual SLAs
Sourcentis is listed on RESAH APoLLO 77, enabling public healthcare and government entities to procure without formal tender.
- Repository: https://github.com/sourcentis/mercator
- Website: https://www.sourcentis.com/mercator/
- Documentation: https://sourcentis.github.io/mercator/en
- Issues: https://github.com/sourcentis/mercator/issues
- Discussions: https://github.com/sourcentis/mercator/discussions
- Repository: https://github.com/sourcentis/deming
- Website: https://www.sourcentis.com/deming/
- Documentation: https://sourcentis.github.io/deming/en
- Issues: https://github.com/sourcentis/deming/issues
- Discussions: https://github.com/sourcentis/deming/discussions
- Website: https://www.sourcentis.com
- Blog: https://www.sourcentis.com/blog/
- Contact: https://www.sourcentis.com/contact/
- Legal: https://www.sourcentis.com/legal/
Frontend: Vue.js, TypeScript, Tailwind CSS
Backend: PHP 8+, Laravel, RESTful API
Database: PostgreSQL
Infrastructure: Docker, Kubernetes-ready
Deployment: Self-hosted, on-premise
We welcome contributions from the community! Whether you're:
- 🐛 Reporting bugs — Open an issue with details
- ✨ Suggesting features — Start a discussion first
- 🔧 Writing code — Fork, develop, and open a pull request
- 📚 Improving docs — Translations and clarity improvements are valued
- 🤝 Sharing feedback — Use our discussion forums
Contributing to Mercator: https://github.com/sourcentis/mercator/blob/main/CONTRIBUTING.md
Contributing to Deming: https://github.com/sourcentis/deming/blob/main/CONTRIBUTING.md
All Sourcentis projects are licensed under the GNU General Public License v3.0 (GPL-3.0), ensuring:
- ✅ Free use for any purpose
- ✅ Source code transparency
- ✅ Freedom to modify and distribute
- ✅ Derivatives must remain open source
- 🎤 Blog: Sourcentis Blog
- 💬 GitHub Discussions: Active in both Mercator and Deming repositories
- 📧 Newsletter: Subscribe on Sourcentis.com
Sourcentis SARL
19, rue de l'Industrie
L-8069 Bertrange, Luxembourg
- Email: contact@sourcentis.com
- Website: https://www.sourcentis.com
- Support Portal: https://www.sourcentis.com/support/