A zero-dependency, offline-first multi-framework compliance self-assessment. One HTML file. No server. No accounts. Rate your organization's maturity across cybersecurity, privacy, federal-defense, AI-governance, and incident-response standards; track progress over time; export evidence for auditors.
.pumapack here, open it in PumaRisk (risk-worthy findings → risk register), PumaKeeper (task-worthy findings → workspace), PumaBoard, or any sibling app. Each consumer applies its own filter; foreign apps surface a friendly toast pointing you at where to open the file..pumapack (full backup, universal interop); CSV (controls + scores, spreadsheet round-trip); JSON (raw); RTF executive summary; Full report Markdown + RTF (every control with evidence, plans, cross-map references); cross-map matrix CSV; Print / Save as PDF.See the Keyboard tab for shortcuts.
Every assessment, score, evidence note, history snapshot, and risk-register entry is held in this browser's sessionStorage under the pumagrc2.* key prefix. Nothing is sent over the network. Closing the tab keeps your data; opening the file in a different browser, profile, or device shows an empty register.
Heads up. Clearing site data, using private/incognito mode, or losing the device erases everything. The browser is the database — back up regularly.
Use the Export button (cloud icon, topbar) for a full .pumapack backup — every workspace, every score, every history snapshot. Open the same pack in any sibling PumaWorx app for cross-app interop. From the gear menu you can also export:
This deletes every assessment, score, history snapshot, and preference under pumagrc2.* in this browser. It does not touch any .pumapack file you've exported.
Type DELETE EVERYTHING to confirm.
.pumapack.pumapack filePumaGRC2 fills the "I need a real maturity assessment but every GRC platform wants a quote, a sales call, and my SOC 2 attestation in escrow"-shaped hole. It's a serious framework tool — sixteen complete control catalogs, gap analysis, cross-mapping, history snapshots — that opens in your browser like a PDF and never phones home.
PumaWorx is a suite of offline, single-HTML productivity apps that run entirely in your local browser. The entire suite is a personal, open source vibecoding project.
Choose which frameworks appear in the sidebar and cross-map. Assessment data is preserved when a framework is hidden.
Name your workspace and pick the frameworks you want to score. You can add or remove frameworks later via the gear menu.
Capture the current assessment state for trend tracking.
This is an offline single-HTML app. No data goes to or from the internet. There is no server, no account, no sync, and no telemetry.
Your assessments live in your web browser's sessionStorage — on this device, in this browser, and nowhere else.
Your data is YOUR responsibility.
If you clear site data, use a private/incognito window, switch browsers, or lose this device, your assessments are gone. Back up regularly via the Export button in the topbar — produces .pumapack, CSV, or RTF.
Press ? any time for help and keyboard shortcuts.