Skip to content
@Hack23

www.hack23.com

Swedish innovation hub specializing in creating immersive and fun game experiences and expert cybersecurity consulting

Hack23 AB โ€” Swedish cybersecurity consulting and civic-tech publisher (logo)

๐Ÿ”’ Hack23 AB

Swedish Cybersecurity Consulting ยท Public ISMS ยท Civic-Tech & AI Political-Intelligence Open Source
๐Ÿ›ก๏ธ ISO 27001:2022 ยท ๐Ÿ” NIST CSF 2.0 ยท ๐ŸŽฏ CIS Controls v8.1 ยท ๐Ÿ‡ช๐Ÿ‡บ GDPR & EU CRA ยท โ˜๏ธ AWS Security ยท ๐Ÿค– AI Newsrooms ยท ๐ŸŽ Discordian Transparency

"Specialists in security architecture, cloud security, DevSecOps, AI governance and open source โ€” building radical transparency into every layer."

Hack23 AB official website hack23.com Hack23 cybersecurity consulting services Discordian cybersecurity blog by Hack23 Hack23 public ISMS repository Sponsor Hack23 AB on GitHub Sponsors

James Pether Sรถrling, CEO Hack23 AB, on LinkedIn Hack23 organisation on GitHub Hack23 conference talks and tech presentations hack23.com human-readable site map in 8 languages

ISO 27001:2022 aligned across all Hack23 repositories NIST Cybersecurity Framework 2.0 aligned CIS Controls v8.1 aligned GDPR โ€” privacy by design EU Cyber Resilience Act self-assessment NIS2 directive aligned SLSA Level 3 across flagship repos AI governance and OWASP LLM security policy


๐ŸŽฏ Mission

Make security and democratic transparency tangible through evidence-based open source.

Hack23 AB is an independent Swedish cybersecurity consultancy and civic-tech publisher founded by James Pether Sรถrling. We deliver:

  • ๐Ÿ” Cybersecurity consulting โ€” security architecture, cloud/AWS security, DevSecOps, ISMS implementation, AI governance and compliance (ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1, GDPR, NIS2, EU CRA).
  • ๐Ÿ›ก๏ธ A fully public ISMS โ€” 38 policies, machine-verifiable, version-controlled at Hack23/ISMS-PUBLIC.
  • ๐Ÿค– Six flagship open-source projects โ€” political-intelligence platforms, AI newsrooms, compliance tooling and a Korean martial-arts simulator โ€” all Apache-2.0 and aligned with the same ISMS.
  • ๐ŸŽ 30+ Discordian cybersecurity blog posts โ€” accessible, narrative-driven security writing that maps back to formal policies.
  • ๐ŸŽ™๏ธ Conference talks, training and security culture work โ€” turning security from a barrier into an enabler.

Everything we ship is non-partisan, ad-free, GDPR-clean, privacy-by-design and architecturally engineered so it cannot be weaponised for partisan or commercial influence.


๐Ÿ’– Sponsor Hack23

๐ŸŒŸ Help us keep our public ISMS, AI political newsrooms and civic-tech open source. All flagship projects are Apache-2.0, ad-free and operationally funded by Hack23 AB plus generous sponsors.

Become a Hack23 sponsor on GitHub Sponsors

โ˜• Personal ๐Ÿข Professional ๐Ÿ›๏ธ Institutional
Individuals, students, journalists, civic activists.
Funds:
  • ๐Ÿ“ก AWS hosting (CloudFront, S3, Route 53)
  • ๐ŸŒ Domain renewals (riksdagsmonitor.com, euparliamentmonitor.com, blacktrigram.com, hack23.com)
  • ๐ŸŽ Discordian blog publication
Security professionals, dev teams, OSPOs, NGOs.
Funds:
  • ๐Ÿค– Claude Opus / GPT API costs for the agentic newsrooms
  • ๐Ÿ›ก๏ธ Third-party security scanning (DAST, SAST, license scanners)
  • ๐Ÿ“ ISMS continuous-improvement work
Universities, research institutes, media organisations.
Funds:
  • ๐Ÿ“Š Long-term archive integrity (1971-onwards parliamentary corpora)
  • ๐ŸŒ 14-language translation infrastructure
  • ๐ŸŽ“ Educational outreach and conference presence

๐Ÿ‘‰ Sponsor at https://github.com/sponsors/Hack23 โ€” every contribution is acknowledged (unless anonymity is requested) and helps keep parliamentary monitoring, AI-driven journalism and the Hack23 ISMS independent.


๐ŸŒ The Hack23 Ecosystem

%%{init: {"theme":"base","themeVariables":{"primaryColor":"#0066CC","primaryTextColor":"#fff","primaryBorderColor":"#003366","lineColor":"#94A3B8","secondaryColor":"#003399","tertiaryColor":"#7B1FA2","background":"#0F172A"}}}%%
graph TB
    subgraph CONSULT["๐Ÿ’ผ Hack23 AB โ€” Cybersecurity Consulting"]
        SVC["๐Ÿ”‘ Services<br/>hack23.com/services.html<br/>Architecture ยท Cloud ยท DevSecOps ยท Compliance"]
        ISMS["๐Ÿ”“ Public ISMS<br/>github.com/Hack23/ISMS-PUBLIC<br/>38 policies ยท ISO 27001:2022 ยท NIST CSF 2.0"]
        BLOG["๐ŸŽ Discordian Blog<br/>hack23.com/blog.html<br/>30+ posts ยท 8 languages"]
    end

    subgraph SOURCES["๐Ÿ“ก Primary Open Data"]
        EP["๐Ÿ‡ช๐Ÿ‡บ European Parliament<br/>data.europarl.europa.eu"]
        RD["๐Ÿ‡ธ๐Ÿ‡ช Riksdagen<br/>data.riksdagen.se"]
        REG["๐Ÿ‡ธ๐Ÿ‡ช Regeringskansliet<br/>regeringen.se"]
    end

    subgraph MCP["๐Ÿ”Œ MCP Servers (AI Bridges)"]
        EPMCP["๐Ÿ‡ช๐Ÿ‡บ European-Parliament-MCP-Server<br/>npm: european-parliament-mcp-server<br/>62 tools ยท 9 resources ยท 7 prompts"]
    end

    subgraph CIVIC["๐Ÿ›๏ธ Civic-Tech Platforms (Apache 2.0)"]
        CIA["๐Ÿ•ต๏ธ Citizen Intelligence Agency<br/>github.com/Hack23/cia<br/>Java 26 ยท Spring ยท 110 DB views ยท 1971โ€“2024"]
        RM["๐Ÿ—ณ๏ธ Riksdagsmonitor<br/>riksdagsmonitor.com<br/>11 agentic workflows ยท 14 languages"]
        EUM["๐Ÿ‡ช๐Ÿ‡บ EU Parliament Monitor<br/>euparliamentmonitor.com<br/>9 agentic workflows ยท 14 languages"]
    end

    subgraph PRODUCT["๐Ÿ“‹ Products & Platforms"]
        CCM["๐Ÿ“‹ CIA Compliance Manager<br/>ciacompliancemanager.com<br/>npm: cia-compliance-manager<br/>React 19 ยท TypeScript 6"]
        BT["๐Ÿฅ‹ Black Trigram<br/>blacktrigram.com<br/>npm: blacktrigram<br/>Three.js ยท React 19 ยท 70 vital points"]
        GAME["๐ŸŽฎ Game Template<br/>github.com/Hack23/game<br/>SLSA 3 secure-by-default starter"]
    end

    subgraph AUDIENCE["๐Ÿ‘ฅ Audience"]
        USERS["Citizens ยท Journalists ยท Researchers ยท NGOs ยท Security teams ยท AI assistants (Claude ยท Cursor ยท Copilot ยท VS Code)"]
    end

    EP --> EPMCP
    EPMCP --> EUM
    RD --> CIA
    REG --> CIA
    CIA -->|"15 subsystems ยท nightly sync"| RM
    EUM --> USERS
    RM --> USERS
    CIA --> USERS
    CCM --> USERS
    BT --> USERS
    EPMCP -.->|"AI assistants"| USERS
    SVC --> USERS
    ISMS --> CIVIC
    ISMS --> PRODUCT
    BLOG --> USERS

    style CONSULT fill:#003366,stroke:#0066CC,color:#fff
    style ISMS fill:#0066CC,stroke:#003366,color:#fff
    style EPMCP fill:#6366F1,stroke:#4F46E5,color:#fff
    style CIA fill:#006B3F,stroke:#003F25,color:#fff
    style RM fill:#00338D,stroke:#FECC00,color:#fff
    style EUM fill:#003399,stroke:#FFCC00,color:#fff
    style CCM fill:#0066CC,stroke:#003366,color:#fff
    style BT fill:#000000,stroke:#FFD700,color:#FFD700
Loading

Single mission, one ISMS, one license (Apache-2.0), one set of compliance frameworks โ€” applied identically across consulting, civic-tech and commercial products.


๐Ÿš€ Flagship Open-Source Projects

Each project has its own ISMS-aligned SECURITY_ARCHITECTURE.md, THREAT_MODEL.md, OpenSSF Scorecard, OpenSSF Best Practices badge, SLSA 3 attestation and SonarCloud quality gate.

๐Ÿ—ณ๏ธ Riksdagsmonitor โ€” Swedish Political Intelligence

AI-driven monitoring of Sweden's Riksdag, Government and public agencies โ€” 349 current MPs, 2,494 historical politicians (1971โ€“2024), 3.5M+ votes, 109,000+ documents, 14 languages, every day.

Riksdagsmonitor live platform Riksdagsmonitor source on GitHub riksdagsmonitor npm package OpenSSF Scorecard for Riksdagsmonitor OpenSSF Best Practices badge for Riksdagsmonitor Ask DeepWiki about Riksdagsmonitor Riksdagsmonitor license

๐Ÿ”— Surfaces: Live ยท Political Intelligence Hub ยท AI Newsroom ยท Dashboard ยท Sitemap ยท Features ยท Docs

๐Ÿ‡ช๐Ÿ‡บ EU Parliament Monitor โ€” European Political Intelligence

Brussels and Strasbourg made readable. AI-newsroom over the European Parliament's open data โ€” 8 unified gh-aw workflows, 51 analytical artifacts per run, 14 languages, 1,700+ daily artifacts, full Admiralty / WEP / SAT / ACH tradecraft.

EU Parliament Monitor live platform EU Parliament Monitor source on GitHub OpenSSF Scorecard for EU Parliament Monitor OpenSSF Best Practices badge for EU Parliament Monitor SLSA Level 3 attestations for EU Parliament Monitor Ask DeepWiki about EU Parliament Monitor EU Parliament Monitor license

๐Ÿ”— Surfaces: Live ยท Political Intelligence Hub ยท Sitemap ยท API Docs ยท Features ยท Docs

๐Ÿ”Œ European Parliament MCP Server โ€” AI Data Backbone

Canonical TypeScript Model Context Protocol server bridging the European Parliament Open Data Portal v2 to any MCP-aware AI client (Claude Desktop, VS Code, Cursor, GitHub Copilot). 62 tools, 9 resources, 7 prompts, full GDPR-by-design.

European Parliament MCP Server source on GitHub european-parliament-mcp-server npm package european-parliament-mcp-server npm monthly downloads OpenSSF Best Practices badge for European Parliament MCP Server Ask DeepWiki about European Parliament MCP Server European Parliament MCP Server documentation portal

๐Ÿ”— Surfaces: Repository ยท npm ยท API Docs ยท Features ยท Docs

๐Ÿ•ต๏ธ Citizen Intelligence Agency (CIA) โ€” Sweden's Data Backbone

Java/Spring/Vaadin OSINT platform monitoring Sweden's Riksdag, Government and Myndigheter since 2008. 110 database views, 50 risk-detection rules, 1971โ€“2024 longitudinal coverage, 3.5M+ votes, 109K+ documents. The data backbone behind Riksdagsmonitor.

Citizen Intelligence Agency source on GitHub Citizen Intelligence Agency Maven site OpenSSF Scorecard for Citizen Intelligence Agency CII Best Practices badge for Citizen Intelligence Agency SLSA Level 3 attestations for Citizen Intelligence Agency SonarCloud quality gate for Citizen Intelligence Agency Ask DeepWiki about Citizen Intelligence Agency Citizen Intelligence Agency license

๐Ÿ”— Surfaces: Repository ยท Architecture ยท Security Architecture ยท Threat Model ยท Features ยท Docs

๐Ÿ“‹ CIA Compliance Manager โ€” Browser-Based GRC

React 19 / TypeScript 6 platform for CIA-triad assessment, multi-framework compliance, threat modeling and business-impact quantification. Available as a live web app and a tree-shakeable npm library with 10 subpath exports.

CIA Compliance Manager live application CIA Compliance Manager source on GitHub cia-compliance-manager npm package OpenSSF Scorecard for CIA Compliance Manager OpenSSF Best Practices badge for CIA Compliance Manager SLSA Level 3 attestations for CIA Compliance Manager Ask DeepWiki about CIA Compliance Manager

๐Ÿ”— Surfaces: Live App ยท npm ยท API Docs ยท Features ยท Docs

๐Ÿฅ‹ Black Trigram (ํ‘๊ด˜) โ€” Korean Martial-Arts Combat Simulator

Production-ready 3D precision combat simulator. Eight I Ching trigram stances ยท 70 vital points ยท 51 authentic Korean martial-arts techniques ยท 5 fighter archetypes ยท 60fps desktop / 55fps+ mobile. React 19 ยท Three.js ยท TypeScript 6 ยท Vite 8.

Play Black Trigram live Black Trigram source on GitHub blacktrigram npm package OpenSSF Scorecard for Black Trigram OpenSSF Best Practices badge for Black Trigram SLSA Level 3 attestations for Black Trigram Ask DeepWiki about Black Trigram

๐Ÿ”— Surfaces: Play ยท API Docs ยท Security Architecture ยท Threat Model ยท Features ยท Docs

๐ŸŽฎ Game Template โ€” Secure-by-Default Game Starter

Reference implementation of a secure web-game project: React + TypeScript + Three.js + Vite, SLSA 3, full SBOM, automated security testing, ISMS-policy mapping ready to fork.

Hack23 secure game template Game template ISMS policy mapping

โ˜๏ธ Lambda in Private VPC โ€” AWS Reference Architecture

Battle-tested reference implementation: AWS Lambda in a private VPC with VPC endpoints, CloudFront, WAF, KMS encryption, CloudTrail and Security Hub integration.

AWS Lambda in private VPC reference architecture Tutorial on hack23.com blog

๐Ÿงช Sonar-CloudFormation-Plugin โ€” Infrastructure-as-Code Static Analysis

Open-source SonarQube plugin that brings CloudFormation IaC scanning into existing SonarQube/SonarCloud quality gates.

Sonar CloudFormation plugin source on GitHub Hack23 SonarCloud organisation


๐Ÿ›ก๏ธ Public ISMS โ€” Hack23/ISMS-PUBLIC

A fully public, version-controlled, machine-verifiable Information Security Management System. 38 policies covering access control, cryptography, secure development, threat modeling, vulnerability management, AI governance, GDPR privacy, EU CRA, ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1.

Hack23 public ISMS repository Information Security Policy ISMS compliance checklist

Domain Key Policies
๐Ÿ› ๏ธ Secure Development Secure Development Policy ยท Threat Modeling ยท Vulnerability Management ยท Change Management
๐Ÿ”‘ Access & Identity Access Control Policy ยท Segregation of Duties ยท Mobile Device Management
๐ŸŒ Network & Crypto Network Security Policy ยท Cryptography Policy
๐Ÿ’พ Continuity Backup & Recovery ยท Business Continuity Plan ยท Disaster Recovery Plan
๐Ÿšจ Incident Incident Response Plan
๐Ÿค– AI & LLM AI Policy ยท OWASP LLM Security Policy
๐Ÿ“Š Risk & Compliance Risk Register ยท Risk Assessment Methodology ยท Compliance Checklist ยท Security Metrics ยท ISMS Metrics Dashboard
๐Ÿ‡ช๐Ÿ‡บ Regulatory Privacy Policy (GDPR) ยท CRA Conformity Assessment Process (EU CRA) ยท ISO 5230 Self-Certification
๐ŸŒŸ Transparency ISMS Transparency Plan ยท Open Source Policy ยท STYLE_GUIDE

๐ŸŒŸ Why public? Because security claims must be auditable. Every customer, regulator, journalist or curious citizen can read, fork, critique or reuse our ISMS โ€” and can independently verify that what we ship matches what we say.


๐Ÿ”‘ Cybersecurity Consulting Services

We deliver hands-on, evidence-based cybersecurity work across five practice areas. Read the full service catalogue at hack23.com/services.html.

๐Ÿ” Security Architecture โ˜๏ธ Cloud Security & DevSecOps ๐Ÿ“‹ Compliance & Regulatory
Threat modeling (STRIDE, MITRE ATT&CK), zero-trust architecture, secure SDLC, OWASP Top 10 / SAMM, identity & access, cryptography & key management.

Read more โ†’
AWS Well-Architected (Security pillar), VPC & WAF design, IAM least-privilege, GuardDuty / Security Hub / KMS / CloudTrail, GitHub Actions hardening, SLSA 3, SBOM.

Read more โ†’
ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1, GDPR, NIS2, EU CRA, AI Act, SOC 2 readiness, supplier due-diligence, SBOM & ISO 5230 alignment.

Read more โ†’
๐ŸŒ Open Source & OSPO ๐ŸŽ“ Training & Security Culture ๐Ÿค– AI Governance
OSPO setup, license & SBOM management, contributor agreements, OpenSSF Scorecard adoption, supply-chain hardening, FOSSA / FOSDEM workflows.

Read more โ†’
Tabletop exercises, secure-coding workshops, threat-modeling clinics, executive briefings, Discordian-style narrative training that actually sticks.

Read more โ†’
OWASP LLM Top 10, AI Act readiness, prompt-injection defence, agentic-workflow review (gh-aw), MCP server hardening, AI-in-CI/CD risk assessment.

Read more โ†’

๐Ÿ“จ Engage us: https://hack23.com/contact.html ยท LinkedIn: https://www.linkedin.com/in/jamessorling/


๐ŸŽ Discordian Cybersecurity Blog โ€” hack23.com/blog.html

30+ posts of accessible, narrative-driven security writing โ€” every post maps back to formal ISMS policies and reference implementations.

Read the Discordian cybersecurity blog at hack23.com/blog.html Hack23 Discordian manifesto

Selected pillar posts:

โ†’ Full archive at hack23.com/blog.html (8 languages, JSON-LD structured data, full RSS).


๐Ÿ‘จโ€๐Ÿ’ผ About โ€” James Pether Sรถrling

Founder & CEO of Hack23 AB. 25+ years in software security, cloud architecture, civic-tech and OSINT. Independent, non-partisan, opinionated about transparency.

James Pether Sรถrling on LinkedIn James Pether Sรถrling on GitHub About James Pether Sรถrling on hack23.com

mindmap
  root((๐Ÿ‘จโ€๐Ÿ’ผ James Pether Sรถrling<br/>CEO ยท Hack23 AB))
    ๐Ÿ” Security
      Architecture
      Threat modeling
      Cryptography
      AppSec / OWASP
    โ˜๏ธ Cloud
      AWS Solutions Architect
      Well-Architected
      DevSecOps
      Lambda ยท VPC ยท KMS ยท WAF
    ๐Ÿ›ก๏ธ Compliance
      ISO 27001:2022
      NIST CSF 2.0
      CIS Controls v8.1
      GDPR ยท NIS2 ยท EU CRA ยท AI Act
    ๐ŸŒ Open Source
      Apache 2.0 advocate
      OSPO setup
      Public ISMS author
      OpenSSF Scorecard
    ๐Ÿ‡ธ๐Ÿ‡ช Civic Tech
      OSINT tradecraft
      Riksdag ยท EU ยท Government data
      AI political journalism
      Democratic transparency
    ๐ŸŽ Discordian
      Narrative security writing
      30+ blog posts
      Conference talks
Loading

โ†’ Full bio, certifications and engagement options at hack23.com/about.html.


๐ŸŽ™๏ธ Talks, Press & Recognition

Hack23 talks repository on GitHub Hack23 press coverage

  • ๐ŸŽค Conference talks on AWS security, OSINT, ISMS-as-code, Apache POI, agentic AI workflows, civic tech and parliamentary monitoring
  • ๐Ÿ“ฐ Coverage on civic-tech transparency, parliamentary OSINT, Riksdagsmonitor and the Hack23 public ISMS
  • ๐Ÿ… OpenSSF Best Practices, OpenSSF Scorecard, SLSA Level 3, FOSSA license-clean across all flagship repos

โ†’ Slides & recordings: github.com/Hack23/talks ยท Press: hack23.com/press.html


๐Ÿ—บ๏ธ Site Map & SEO Index

Every Hack23 surface is cross-linked for discoverability. Bookmark the hack23.com sitemap for the human-readable index in 8 languages, or use the per-project links below.

Project / Topic Repository Live / Hosted Features Docs
๐Ÿ”’ Hack23 AB โ€” hack23.com Services ยท About ยท Press ยท Contact Blog ยท Sitemap
๐Ÿ›ก๏ธ Public ISMS ISMS-PUBLIC โ€” 38 policies README
๐Ÿ—ณ๏ธ Riksdagsmonitor riksdagsmonitor riksdagsmonitor.com Features Docs ยท PI Hub
๐Ÿ‡ช๐Ÿ‡บ EU Parliament Monitor euparliamentmonitor euparliamentmonitor.com Features Docs ยท PI Hub
๐Ÿ”Œ EP MCP Server European-Parliament-MCP-Server npm ยท Portal Features Docs
๐Ÿ•ต๏ธ Citizen Intelligence Agency cia hack23.github.io/cia Features Docs
๐Ÿ“‹ CIA Compliance Manager cia-compliance-manager ciacompliancemanager.com Features Docs ยท API
๐Ÿฅ‹ Black Trigram blacktrigram blacktrigram.com Features Docs ยท API
๐ŸŽฎ Game Template game โ€” README ISMS Mapping
โ˜๏ธ Lambda in Private VPC aws-lambda-private-vpc โ€” Tutorial README
๐Ÿงช Sonar CFN Plugin sonar-cloudformation-plugin SonarCloud README โ€”
๐ŸŽ™๏ธ Talks talks โ€” Slides โ€”
๐ŸŽ Discordian Blog โ€” hack23.com/blog.html Manifesto โ€”

๐Ÿค Get in Touch

Contact Hack23 AB Email Hack23 AB at info@hack23.com James Pether Sรถrling on LinkedIn Sponsor Hack23 AB on GitHub Sponsors


"Security is transparency in action. Democracy is transparency at scale. Hack23 is both โ€” in code." ๐ŸŽ

ยฉ 2008โ€“2026 Hack23 AB (Org.nr 559534-7807, Gothenburg, Sweden) ยท Apache License 2.0 ยท ๐Ÿ’– Sponsor

Pinned Loading

  1. cia cia Public

    Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government institutions, and parliamentaryโ€ฆ

    Java 235 56

  2. sonar-cloudformation-plugin sonar-cloudformation-plugin Public archive

    Sonarqube cloudformation plugin, IaC security supports cfn-nag/checkov

    Java 27 9

Repositories

Showing 10 of 18 repositories