Swedish Cybersecurity Consulting ยท Public ISMS ยท Civic-Tech & AI Political-Intelligence Open Source
๐ก๏ธ ISO 27001:2022 ยท ๐ NIST CSF 2.0 ยท ๐ฏ CIS Controls v8.1 ยท ๐ช๐บ GDPR & EU CRA ยท โ๏ธ AWS Security ยท ๐ค AI Newsrooms ยท ๐ Discordian Transparency
"Specialists in security architecture, cloud security, DevSecOps, AI governance and open source โ building radical transparency into every layer."
Make security and democratic transparency tangible through evidence-based open source.
Hack23 AB is an independent Swedish cybersecurity consultancy and civic-tech publisher founded by James Pether Sรถrling. We deliver:
- ๐ Cybersecurity consulting โ security architecture, cloud/AWS security, DevSecOps, ISMS implementation, AI governance and compliance (ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1, GDPR, NIS2, EU CRA).
- ๐ก๏ธ A fully public ISMS โ 38 policies, machine-verifiable, version-controlled at Hack23/ISMS-PUBLIC.
- ๐ค Six flagship open-source projects โ political-intelligence platforms, AI newsrooms, compliance tooling and a Korean martial-arts simulator โ all Apache-2.0 and aligned with the same ISMS.
- ๐ 30+ Discordian cybersecurity blog posts โ accessible, narrative-driven security writing that maps back to formal policies.
- ๐๏ธ Conference talks, training and security culture work โ turning security from a barrier into an enabler.
Everything we ship is non-partisan, ad-free, GDPR-clean, privacy-by-design and architecturally engineered so it cannot be weaponised for partisan or commercial influence.
๐ Help us keep our public ISMS, AI political newsrooms and civic-tech open source. All flagship projects are Apache-2.0, ad-free and operationally funded by Hack23 AB plus generous sponsors.
| โ Personal | ๐ข Professional | ๐๏ธ Institutional |
|---|---|---|
|
Individuals, students, journalists, civic activists. Funds:
|
Security professionals, dev teams, OSPOs, NGOs. Funds:
|
Universities, research institutes, media organisations. Funds:
|
๐ Sponsor at https://github.com/sponsors/Hack23 โ every contribution is acknowledged (unless anonymity is requested) and helps keep parliamentary monitoring, AI-driven journalism and the Hack23 ISMS independent.
%%{init: {"theme":"base","themeVariables":{"primaryColor":"#0066CC","primaryTextColor":"#fff","primaryBorderColor":"#003366","lineColor":"#94A3B8","secondaryColor":"#003399","tertiaryColor":"#7B1FA2","background":"#0F172A"}}}%%
graph TB
subgraph CONSULT["๐ผ Hack23 AB โ Cybersecurity Consulting"]
SVC["๐ Services<br/>hack23.com/services.html<br/>Architecture ยท Cloud ยท DevSecOps ยท Compliance"]
ISMS["๐ Public ISMS<br/>github.com/Hack23/ISMS-PUBLIC<br/>38 policies ยท ISO 27001:2022 ยท NIST CSF 2.0"]
BLOG["๐ Discordian Blog<br/>hack23.com/blog.html<br/>30+ posts ยท 8 languages"]
end
subgraph SOURCES["๐ก Primary Open Data"]
EP["๐ช๐บ European Parliament<br/>data.europarl.europa.eu"]
RD["๐ธ๐ช Riksdagen<br/>data.riksdagen.se"]
REG["๐ธ๐ช Regeringskansliet<br/>regeringen.se"]
end
subgraph MCP["๐ MCP Servers (AI Bridges)"]
EPMCP["๐ช๐บ European-Parliament-MCP-Server<br/>npm: european-parliament-mcp-server<br/>62 tools ยท 9 resources ยท 7 prompts"]
end
subgraph CIVIC["๐๏ธ Civic-Tech Platforms (Apache 2.0)"]
CIA["๐ต๏ธ Citizen Intelligence Agency<br/>github.com/Hack23/cia<br/>Java 26 ยท Spring ยท 110 DB views ยท 1971โ2024"]
RM["๐ณ๏ธ Riksdagsmonitor<br/>riksdagsmonitor.com<br/>11 agentic workflows ยท 14 languages"]
EUM["๐ช๐บ EU Parliament Monitor<br/>euparliamentmonitor.com<br/>9 agentic workflows ยท 14 languages"]
end
subgraph PRODUCT["๐ Products & Platforms"]
CCM["๐ CIA Compliance Manager<br/>ciacompliancemanager.com<br/>npm: cia-compliance-manager<br/>React 19 ยท TypeScript 6"]
BT["๐ฅ Black Trigram<br/>blacktrigram.com<br/>npm: blacktrigram<br/>Three.js ยท React 19 ยท 70 vital points"]
GAME["๐ฎ Game Template<br/>github.com/Hack23/game<br/>SLSA 3 secure-by-default starter"]
end
subgraph AUDIENCE["๐ฅ Audience"]
USERS["Citizens ยท Journalists ยท Researchers ยท NGOs ยท Security teams ยท AI assistants (Claude ยท Cursor ยท Copilot ยท VS Code)"]
end
EP --> EPMCP
EPMCP --> EUM
RD --> CIA
REG --> CIA
CIA -->|"15 subsystems ยท nightly sync"| RM
EUM --> USERS
RM --> USERS
CIA --> USERS
CCM --> USERS
BT --> USERS
EPMCP -.->|"AI assistants"| USERS
SVC --> USERS
ISMS --> CIVIC
ISMS --> PRODUCT
BLOG --> USERS
style CONSULT fill:#003366,stroke:#0066CC,color:#fff
style ISMS fill:#0066CC,stroke:#003366,color:#fff
style EPMCP fill:#6366F1,stroke:#4F46E5,color:#fff
style CIA fill:#006B3F,stroke:#003F25,color:#fff
style RM fill:#00338D,stroke:#FECC00,color:#fff
style EUM fill:#003399,stroke:#FFCC00,color:#fff
style CCM fill:#0066CC,stroke:#003366,color:#fff
style BT fill:#000000,stroke:#FFD700,color:#FFD700
Single mission, one ISMS, one license (Apache-2.0), one set of compliance frameworks โ applied identically across consulting, civic-tech and commercial products.
Each project has its own ISMS-aligned SECURITY_ARCHITECTURE.md, THREAT_MODEL.md, OpenSSF Scorecard, OpenSSF Best Practices badge, SLSA 3 attestation and SonarCloud quality gate.
AI-driven monitoring of Sweden's Riksdag, Government and public agencies โ 349 current MPs, 2,494 historical politicians (1971โ2024), 3.5M+ votes, 109,000+ documents, 14 languages, every day.
๐ Surfaces: Live ยท Political Intelligence Hub ยท AI Newsroom ยท Dashboard ยท Sitemap ยท Features ยท Docs
Brussels and Strasbourg made readable. AI-newsroom over the European Parliament's open data โ 8 unified gh-aw workflows, 51 analytical artifacts per run, 14 languages, 1,700+ daily artifacts, full Admiralty / WEP / SAT / ACH tradecraft.
๐ Surfaces: Live ยท Political Intelligence Hub ยท Sitemap ยท API Docs ยท Features ยท Docs
Canonical TypeScript Model Context Protocol server bridging the European Parliament Open Data Portal v2 to any MCP-aware AI client (Claude Desktop, VS Code, Cursor, GitHub Copilot). 62 tools, 9 resources, 7 prompts, full GDPR-by-design.
๐ Surfaces: Repository ยท npm ยท API Docs ยท Features ยท Docs
Java/Spring/Vaadin OSINT platform monitoring Sweden's Riksdag, Government and Myndigheter since 2008. 110 database views, 50 risk-detection rules, 1971โ2024 longitudinal coverage, 3.5M+ votes, 109K+ documents. The data backbone behind Riksdagsmonitor.
๐ Surfaces: Repository ยท Architecture ยท Security Architecture ยท Threat Model ยท Features ยท Docs
React 19 / TypeScript 6 platform for CIA-triad assessment, multi-framework compliance, threat modeling and business-impact quantification. Available as a live web app and a tree-shakeable npm library with 10 subpath exports.
๐ Surfaces: Live App ยท npm ยท API Docs ยท Features ยท Docs
Production-ready 3D precision combat simulator. Eight I Ching trigram stances ยท 70 vital points ยท 51 authentic Korean martial-arts techniques ยท 5 fighter archetypes ยท 60fps desktop / 55fps+ mobile. React 19 ยท Three.js ยท TypeScript 6 ยท Vite 8.
๐ Surfaces: Play ยท API Docs ยท Security Architecture ยท Threat Model ยท Features ยท Docs
Reference implementation of a secure web-game project: React + TypeScript + Three.js + Vite, SLSA 3, full SBOM, automated security testing, ISMS-policy mapping ready to fork.
Battle-tested reference implementation: AWS Lambda in a private VPC with VPC endpoints, CloudFront, WAF, KMS encryption, CloudTrail and Security Hub integration.
Open-source SonarQube plugin that brings CloudFormation IaC scanning into existing SonarQube/SonarCloud quality gates.
A fully public, version-controlled, machine-verifiable Information Security Management System. 38 policies covering access control, cryptography, secure development, threat modeling, vulnerability management, AI governance, GDPR privacy, EU CRA, ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1.
| Domain | Key Policies |
|---|---|
| ๐ ๏ธ Secure Development | Secure Development Policy ยท Threat Modeling ยท Vulnerability Management ยท Change Management |
| ๐ Access & Identity | Access Control Policy ยท Segregation of Duties ยท Mobile Device Management |
| ๐ Network & Crypto | Network Security Policy ยท Cryptography Policy |
| ๐พ Continuity | Backup & Recovery ยท Business Continuity Plan ยท Disaster Recovery Plan |
| ๐จ Incident | Incident Response Plan |
| ๐ค AI & LLM | AI Policy ยท OWASP LLM Security Policy |
| ๐ Risk & Compliance | Risk Register ยท Risk Assessment Methodology ยท Compliance Checklist ยท Security Metrics ยท ISMS Metrics Dashboard |
| ๐ช๐บ Regulatory | Privacy Policy (GDPR) ยท CRA Conformity Assessment Process (EU CRA) ยท ISO 5230 Self-Certification |
| ๐ Transparency | ISMS Transparency Plan ยท Open Source Policy ยท STYLE_GUIDE |
๐ Why public? Because security claims must be auditable. Every customer, regulator, journalist or curious citizen can read, fork, critique or reuse our ISMS โ and can independently verify that what we ship matches what we say.
We deliver hands-on, evidence-based cybersecurity work across five practice areas. Read the full service catalogue at hack23.com/services.html.
| ๐ Security Architecture | โ๏ธ Cloud Security & DevSecOps | ๐ Compliance & Regulatory |
|---|---|---|
|
Threat modeling (STRIDE, MITRE ATT&CK), zero-trust architecture, secure SDLC, OWASP Top 10 / SAMM, identity & access, cryptography & key management. Read more โ |
AWS Well-Architected (Security pillar), VPC & WAF design, IAM least-privilege, GuardDuty / Security Hub / KMS / CloudTrail, GitHub Actions hardening, SLSA 3, SBOM. Read more โ |
ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1, GDPR, NIS2, EU CRA, AI Act, SOC 2 readiness, supplier due-diligence, SBOM & ISO 5230 alignment. Read more โ |
| ๐ Open Source & OSPO | ๐ Training & Security Culture | ๐ค AI Governance |
|
OSPO setup, license & SBOM management, contributor agreements, OpenSSF Scorecard adoption, supply-chain hardening, FOSSA / FOSDEM workflows. Read more โ |
Tabletop exercises, secure-coding workshops, threat-modeling clinics, executive briefings, Discordian-style narrative training that actually sticks. Read more โ |
OWASP LLM Top 10, AI Act readiness, prompt-injection defence, agentic-workflow review (gh-aw), MCP server hardening, AI-in-CI/CD risk assessment. Read more โ |
๐จ Engage us: https://hack23.com/contact.html ยท LinkedIn: https://www.linkedin.com/in/jamessorling/
30+ posts of accessible, narrative-driven security writing โ every post maps back to formal ISMS policies and reference implementations.
Selected pillar posts:
- ๐ The Discordian Manifesto for Cybersecurity
- ๐ก๏ธ Building a Public ISMS โ Why & How
- ๐ What Is the Model Context Protocol (and How We Use It for Open Government Data)
- ๐ค Agentic Workflows for Political Journalism โ gh-aw, Claude Opus, Zero Editors
- ๐ช๐บ EU Cyber Resilience Act โ A Self-Assessment Walkthrough
โ Full archive at hack23.com/blog.html (8 languages, JSON-LD structured data, full RSS).
Founder & CEO of Hack23 AB. 25+ years in software security, cloud architecture, civic-tech and OSINT. Independent, non-partisan, opinionated about transparency.
mindmap
root((๐จโ๐ผ James Pether Sรถrling<br/>CEO ยท Hack23 AB))
๐ Security
Architecture
Threat modeling
Cryptography
AppSec / OWASP
โ๏ธ Cloud
AWS Solutions Architect
Well-Architected
DevSecOps
Lambda ยท VPC ยท KMS ยท WAF
๐ก๏ธ Compliance
ISO 27001:2022
NIST CSF 2.0
CIS Controls v8.1
GDPR ยท NIS2 ยท EU CRA ยท AI Act
๐ Open Source
Apache 2.0 advocate
OSPO setup
Public ISMS author
OpenSSF Scorecard
๐ธ๐ช Civic Tech
OSINT tradecraft
Riksdag ยท EU ยท Government data
AI political journalism
Democratic transparency
๐ Discordian
Narrative security writing
30+ blog posts
Conference talks
โ Full bio, certifications and engagement options at hack23.com/about.html.
- ๐ค Conference talks on AWS security, OSINT, ISMS-as-code, Apache POI, agentic AI workflows, civic tech and parliamentary monitoring
- ๐ฐ Coverage on civic-tech transparency, parliamentary OSINT, Riksdagsmonitor and the Hack23 public ISMS
- ๐ OpenSSF Best Practices, OpenSSF Scorecard, SLSA Level 3, FOSSA license-clean across all flagship repos
โ Slides & recordings: github.com/Hack23/talks ยท Press: hack23.com/press.html
Every Hack23 surface is cross-linked for discoverability. Bookmark the hack23.com sitemap for the human-readable index in 8 languages, or use the per-project links below.
| Project / Topic | Repository | Live / Hosted | Features | Docs |
|---|---|---|---|---|
| ๐ Hack23 AB | โ | hack23.com | Services ยท About ยท Press ยท Contact | Blog ยท Sitemap |
| ๐ก๏ธ Public ISMS | ISMS-PUBLIC | โ | 38 policies | README |
| ๐ณ๏ธ Riksdagsmonitor | riksdagsmonitor | riksdagsmonitor.com | Features | Docs ยท PI Hub |
| ๐ช๐บ EU Parliament Monitor | euparliamentmonitor | euparliamentmonitor.com | Features | Docs ยท PI Hub |
| ๐ EP MCP Server | European-Parliament-MCP-Server | npm ยท Portal | Features | Docs |
| ๐ต๏ธ Citizen Intelligence Agency | cia | hack23.github.io/cia | Features | Docs |
| ๐ CIA Compliance Manager | cia-compliance-manager | ciacompliancemanager.com | Features | Docs ยท API |
| ๐ฅ Black Trigram | blacktrigram | blacktrigram.com | Features | Docs ยท API |
| ๐ฎ Game Template | game | โ | README | ISMS Mapping |
| โ๏ธ Lambda in Private VPC | aws-lambda-private-vpc | โ | Tutorial | README |
| ๐งช Sonar CFN Plugin | sonar-cloudformation-plugin | SonarCloud | README | โ |
| ๐๏ธ Talks | talks | โ | Slides | โ |
| ๐ Discordian Blog | โ | hack23.com/blog.html | Manifesto | โ |
- ๐ Cybersecurity consulting: https://hack23.com/contact.html
- ๐ก๏ธ ISMS questions: open an issue on
Hack23/ISMS-PUBLIC - ๐ Vulnerability disclosure: see each repo's
SECURITY.md(orHack23/.github/SECURITY_ARCHITECTURE.md) - ๐ Sponsor: https://github.com/sponsors/Hack23
"Security is transparency in action. Democracy is transparency at scale. Hack23 is both โ in code." ๐
ยฉ 2008โ2026 Hack23 AB (Org.nr 559534-7807, Gothenburg, Sweden) ยท Apache License 2.0 ยท ๐ Sponsor