# Product Overview

Probo is an open-source governance, risk, and compliance platform for engineering, security, and compliance teams. It connects requirements, implementation work, evidence, risk, privacy, vendors, audits, and approved public information in one organization-scoped system.

## What you can do with Probo

- **Run a compliance program** — Manage frameworks, controls, measures, tasks, evidence, obligations, and Statements of Applicability.
- **Assess risk** — Maintain a risk register and model scopes, systems, threats, scenarios, and resulting risks.
- **Manage third parties and privacy** — Inventory vendors and subprocessors, assess them, document processing, and manage DPIAs, TIAs, data, and rights requests.
- **Control documents and audits** — Version and approve documents, collect signatures, scope audits, and track findings.
- **Share approved information** — Publish certifications, commitments, references, and protected files through the Compliance Portal.
- **Manage identity and access** — Configure SSO and SCIM, connect applications, and run access-review campaigns.
- **Manage consent and devices** — Publish cookie banners, retain consent records, and collect endpoint posture through Probo Agent.
- **Automate every domain** — Use GraphQL, the `prb` CLI, MCP, n8n, and webhooks instead of limiting work to the console.

## Who uses Probo

Probo is designed for the people who share responsibility for compliance:

- **Engineering and security leaders** demonstrate how systems and data are protected.
- **Compliance teams** coordinate frameworks, controls, evidence, risks, policies, and audits.
- **Control owners** complete assigned work and provide evidence that measures are operating.
- **Auditors and reviewers** evaluate the resulting records and supporting documentation.

## How a compliance program fits together

1. Define the organization boundary, memberships, frameworks, and obligations.
2. Review controls and connect them to the measures the team actually operates.
3. Assign tasks and collect evidence showing that measures are in place.
4. Identify assets, data, risks, and third parties, then connect safeguards and assessments.
5. Approve controlled documents and prepare audit scope, evidence, and applicability records.
6. Resolve findings, review access, and update the program as systems and requirements change.

Read [Core Concepts](/docs/product/getting-started/core-concepts) for a closer look at these relationships.

## Choose how to use Probo

The same open-source product can be operated for you with Probo Cloud or deployed on infrastructure you control.

- [Choose a deployment](/docs/product/getting-started/choose-deployment) — Compare managed Cloud, Docker Compose, and Kubernetes
- [Self-hosted quickstart](/docs/product/getting-started/quickstart) — Run Probo locally with Docker Compose
- [Set up your first framework](/docs/product/getting-started/first-organization-and-framework) — Create your organization and begin a compliance program
- [Glossary](/docs/product/getting-started/glossary) — Look up product and compliance terminology
