AllegroGRC
AllegroGRC is an online, AI-driven Governance, Risk, and Compliance platform designed to automate cybersecurity risk assessments and security audits using the OCTAVE Allegro framework.

About AllegroGRC
AllegroGRC is an artificial intelligence-driven software designed to streamline Governance, Risk, and Compliance (GRC) processes. Built for organizations looking to modernize cybersecurity risk management, the system automates end-to-end risk evaluation and security audits into a centralized digital workflow.
Designed for systems admins, compliance auditors, and asset owners, AllegroGRC transforms procedural security standards into an intuitive digital experience—enabling teams to identify threats, score risks, and maintain regulatory alignment with confidence.
Automating Cyber Risk & Compliance Management
Traditional cybersecurity risk assessments often rely on manual, disconnected spreadsheets, leading to inconsistent risk evaluations and untracked mitigations.
AllegroGRC solves this challenge by digitizing asset profiling, automating qualitative-to-quantitative risk scoring, and enforcing evidence-based control verification. By bridging technical vulnerability data with executive decision support, the platform ensures that identified cyber risks are systematically mitigated and audit-ready.


System Features
AllegroGRC includes several core features that support daily GRC operations and improve overall security visibility.
Asset Inventory with CIA Triad criticality rating (Scale 1–9)
OWASP Top 10 vulnerability mapping and threat library
Dynamic 5x5 Risk Matrix & Severity Heatmap (Low to Critical)
Interactive OCTAVE Allegro Compliance Audit Checklist
Evidence-based validation and auditor verification workflow
Google Gemini LLM integration for automated executive summaries
Built-in AI Security Assistant for real-time GRC consultation
Role-Based Access Control (RBAC) for Admin, Auditor, and Auditee
Technologies Used
The application was developed using robust security standards and modern web infrastructure.
React & Modern Web UI Framework
JSON Web Tokens (JWT) Session Management
bcrypt Password Hashing
Multer (Secure File Upload Validation)
Google Gemini API (AI Decision Support System)
SQLite Database
HTTPS / TLS Encryption
My Contribution
As the Documentation Lead and Quality Assurance Tester, I was responsible for end-to-end system verification, functional testing, and technical documentation. I authored the comprehensive 41-page System Specification and User Manual. Additionally, I conducted functional and boundary testing across multi-role workflows (RBAC), validated AI response behaviors, identified system error edge cases, and documented troubleshooting procedures to ensure a seamless user experience.

Outcome
AllegroGRC successfully transformed complex cybersecurity auditing into a structured digital platform. Through thorough quality assurance testing and comprehensive technical documentation, the project delivered a fully validated GRC system that streamlines compliance scoring, automates executive reporting, and ensures operational reliability.
What I Learned
This project enhanced my core skills in software quality assurance, user manual creation, system behavior analysis, and GRC framework alignment (OCTAVE Allegro & ISO 27001). It deepened my understanding of how clear technical documentation and rigorous functional testing bridge the gap between complex business requirements and reliable software solutions.

