Skip to content
View pethers's full-sized avatar

Organizations

@Hack23

Block or report pethers

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
pethers/README.md

Hack23 Logo

๐Ÿ‘จโ€๐Ÿ’ผ James Pether Sรถrling โ€” CEO & Founder, Hack23 AB

Cybersecurity consulting ยท Security architecture ยท Cloud security ยท DevSecOps ยท Public ISMS ยท Open Source Transparency
๐Ÿ“ Gothenburg, Sweden ๐Ÿ‡ธ๐Ÿ‡ช โ€” 30+ years in IT ยท CISSP ยท CISM ยท AWS Security & Solutions Architect (Professional)

Builder of ISMS-PUBLIC ยท Riksdagsmonitor ยท EU Parliament Monitor ยท European Parliament MCP Server ยท Citizen Intelligence Agency ยท CIA Compliance Manager ยท Black Trigram

Sponsor Hack23 on GitHub Sponsors Hack23 Website LinkedIn โ€” James Pether Sรถrling GitHub Organization โ€” Hack23 GitHub User โ€” pethers OpenHub โ€” pether

Hack23 Public ISMS ISO 27001:2022 aligned NIST CSF 2.0 aligned CIS Controls v8.1 aligned SLSA Level 3 supply-chain NIS2 / GDPR / EU CRA aligned

Top Swedish committers โ€” pethers


๐Ÿ“‘ Table of Contents


๐Ÿ’– Sponsor Hack23 โ€” Support Open Source Security

Sponsor Hack23

Help keep enterprise-grade security transparent, free, and independent.

Hack23 AB is bootstrapped, vendor-independent, and gives away what most consultancies sell behind a paywall โ€” a complete public ISMS aligned with ISO 27001:2022 / NIS2 / GDPR / EU CRA / NIST CSF 2.0 / CIS Controls v8.1, production-grade open-source platforms for parliamentary transparency, and a deep Discordian Cybersecurity blog demystifying real-world security practice.

Your sponsorship directly funds:

Why sponsor? Most security knowledge sits behind NDAs and audit-firm paywalls. Hack23 publishes the actual policies, threat models, architectures, and source code we run โ€” so anyone, anywhere, can learn from them, copy them, and improve them. Sponsorship is how the lights stay on without compromising independence or accepting hidden agendas.

๐ŸŒŸ Become a Hack23 sponsor โ†’ github.com/sponsors/Hack23


๐ŸŽฏ About Me

committers.top โ€” Sweden โ€” pethers

Strong advocate for transparency in organizations, secure software development practices, and innovative open-source solutions. Experienced security professional with over 30 years in information technology, specializing in security architecture, cloud security, DevSecOps, and compliance (ISO 27001, NIS2, GDPR, EU CRA, NIST CSF 2.0, CIS Controls v8.1).

Prior roles include:

  • ๐Ÿ›ก๏ธ Application Security Officer โ€” Stena
  • ๐Ÿ›ก๏ธ Information Security Officer โ€” Polestar
  • ๐Ÿ—๏ธ Senior Security Architect โ€” WirelessCar

Currently CEO/Founder of Hack23 AB โ€” a Swedish (Gothenburg-based) cybersecurity consultancy delivering practical security architecture, AWS cloud security, secure-SDLC enablement, and ISO 27001 / NIS2 / GDPR / EU CRA compliance through a 100 %-public ISMS and live open-source reference implementations.


๐Ÿ† Professional Certifications

CISSP โ€” (ISC)ยฒ Certified Information Systems Security Professional CISM โ€” ISACA Certified Information Security Manager AWS Certified Security โ€“ Specialty AWS Certified Solutions Architect โ€“ Professional

๐Ÿ” Commitment to Transparency and Security

At Hack23 AB, we believe that true security comes through transparency and demonstrable practices. Our Information Security Management System (ISMS) is publicly available, showcasing our commitment to open security practices and serving as a live reference for any organization building its own.

๐Ÿ“‹ Public ISMS Repository

Complete Information Security Management System โ€” 40+ policies aligned with ISO 27001:2022, NIS2, GDPR, EU CRA, NIST CSF 2.0, and CIS Controls v8.1.

ISMS Public Repository

๐Ÿ”’ Information Security Policy

Enterprise-grade security framework and governance โ€” the canonical, machine-verifiable policy set.

Information Security Policy

๐Ÿ† Security Through Transparency

Our approach to cybersecurity consulting is built on a foundation of transparent practices:

  • ๐Ÿ” Open Documentation โ€” Complete ISMS framework available for review
  • ๐Ÿ“‹ Policy Transparency โ€” Detailed security policies and procedures publicly accessible
  • ๐ŸŽฏ Demonstrable Expertise โ€” Our own security implementation serves as a live demonstration
  • ๐Ÿ”„ Continuous Improvement โ€” Public documentation enables community feedback and enhancement

"Our commitment to transparency extends to our security practices โ€” demonstrating that true security comes from robust processes, continuous improvement, and a culture where security considerations are integrated from the start."

โ€” James Pether Sรถrling, CEO/Founder, Hack23 AB


๐Ÿข Hack23 AB

Swedish innovation hub specializing in cybersecurity consulting & solutions alongside immersive, security-aware game experiences.

๐ŸŒ https://hack23.com ยท ๐Ÿข Org.nr 559534-7807 ยท ๐Ÿ“ Gothenburg, Sweden ๐Ÿ‡ธ๐Ÿ‡ช

Hack23 Website Hack23 Services Why Hack23 CIA Triad FAQ Discordian Cybersecurity Blog Hack23 Sitemap

---

๐ŸŽ Discordian Cybersecurity Insights

Explore information security, ISMS policies, and cybersecurity best practices through the unique Discordian lens inspired by the Illuminatus! trilogy. "Think for yourself, question authority."

๐Ÿ“– Security Blog: 30+ Posts

Everything You Know About Security Is a Lie โ€” Nation-state capabilities, approved crypto paradox, and Chapel Perilous initiation. Complete ISMS coverage with radical transparency.

Discordian Security Blog

Featured Content:

  • ๐ŸŽญ Discordian Manifesto - Everything You Know About Security Is a Lie
  • ๐Ÿ“š Complete ISMS Coverage - All 30 posts link directly to ISMS-PUBLIC repository
  • ๐ŸŽ Illuminatus! Style - FNORD detection, Chapel Perilous references, 23 FNORD 5 signatures

All hail Eris! All hail Discordia! ๐ŸŽ


๐Ÿš€ Open Source Projects

A curated portfolio of Hack23 AB open-source projects โ€” every one operated under the public ISMS, with OpenSSF Scorecard, SLSA Level 3 attestations, DeepWiki docs, and reproducible builds.


๐ŸŒ The Hack23 Ecosystem

%%{init: {"theme":"base","themeVariables":{"primaryColor":"#0066CC","primaryTextColor":"#fff","primaryBorderColor":"#003366","lineColor":"#94A3B8","secondaryColor":"#003399","tertiaryColor":"#7B1FA2","background":"#0F172A"}}}%%
graph TB
    subgraph CONSULT["๐Ÿ’ผ Hack23 AB โ€” Cybersecurity Consulting"]
        SVC["๐Ÿ”‘ Services<br/>hack23.com/services.html<br/>Architecture ยท Cloud ยท DevSecOps ยท Compliance"]
        ISMS["๐Ÿ”“ Public ISMS<br/>github.com/Hack23/ISMS-PUBLIC<br/>38 policies ยท ISO 27001:2022 ยท NIST CSF 2.0"]
        BLOG["๐ŸŽ Discordian Blog<br/>hack23.com/blog.html<br/>30+ posts ยท 8 languages"]
    end

    subgraph SOURCES["๐Ÿ“ก Primary Open Data"]
        EP["๐Ÿ‡ช๐Ÿ‡บ European Parliament<br/>data.europarl.europa.eu"]
        RD["๐Ÿ‡ธ๐Ÿ‡ช Riksdagen<br/>data.riksdagen.se"]
        REG["๐Ÿ‡ธ๐Ÿ‡ช Regeringskansliet<br/>regeringen.se"]
    end

    subgraph MCP["๐Ÿ”Œ MCP Servers (AI Bridges)"]
        EPMCP["๐Ÿ‡ช๐Ÿ‡บ European-Parliament-MCP-Server<br/>npm: european-parliament-mcp-server<br/>62 tools ยท 9 resources ยท 7 prompts"]
    end

    subgraph CIVIC["๐Ÿ›๏ธ Civic-Tech Platforms (Apache 2.0)"]
        CIA["๐Ÿ•ต๏ธ Citizen Intelligence Agency<br/>github.com/Hack23/cia<br/>Java 26 ยท Spring ยท 110 DB views ยท 1971โ€“2024"]
        RM["๐Ÿ—ณ๏ธ Riksdagsmonitor<br/>riksdagsmonitor.com<br/>11 agentic workflows ยท 14 languages"]
        EUM["๐Ÿ‡ช๐Ÿ‡บ EU Parliament Monitor<br/>euparliamentmonitor.com<br/>9 agentic workflows ยท 14 languages"]
    end

    subgraph PRODUCT["๐Ÿ“‹ Products & Platforms"]
        CCM["๐Ÿ“‹ CIA Compliance Manager<br/>ciacompliancemanager.com<br/>npm: cia-compliance-manager<br/>React 19 ยท TypeScript 6"]
        BT["๐Ÿฅ‹ Black Trigram<br/>blacktrigram.com<br/>npm: blacktrigram<br/>Three.js ยท React 19 ยท 70 vital points"]
        GAME["๐ŸŽฎ Game Template<br/>github.com/Hack23/game<br/>SLSA 3 secure-by-default starter"]
    end

    subgraph AUDIENCE["๐Ÿ‘ฅ Audience"]
        USERS["Citizens ยท Journalists ยท Researchers ยท NGOs ยท Security teams ยท AI assistants (Claude ยท Cursor ยท Copilot ยท VS Code)"]
    end

    EP --> EPMCP
    EPMCP --> EUM
    RD --> CIA
    REG --> CIA
    CIA -->|"15 subsystems ยท nightly sync"| RM
    EUM --> USERS
    RM --> USERS
    CIA --> USERS
    CCM --> USERS
    BT --> USERS
    EPMCP -.->|"AI assistants"| USERS
    SVC --> USERS
    ISMS --> CIVIC
    ISMS --> PRODUCT
    BLOG --> USERS

    style CONSULT fill:#003366,stroke:#0066CC,color:#fff
    style ISMS fill:#0066CC,stroke:#003366,color:#fff
    style EPMCP fill:#6366F1,stroke:#4F46E5,color:#fff
    style CIA fill:#006B3F,stroke:#003F25,color:#fff
    style RM fill:#00338D,stroke:#FECC00,color:#fff
    style EUM fill:#003399,stroke:#FFCC00,color:#fff
    style CCM fill:#0066CC,stroke:#003366,color:#fff
    style BT fill:#000000,stroke:#FFD700,color:#FFD700
Loading

Single mission, one ISMS, one license (Apache-2.0), one set of compliance frameworks โ€” applied identically across consulting, civic-tech and commercial products.


๐Ÿš€ Flagship Open-Source Projects

Each project has its own ISMS-aligned SECURITY_ARCHITECTURE.md, THREAT_MODEL.md, OpenSSF Scorecard, OpenSSF Best Practices badge, SLSA 3 attestation and SonarCloud quality gate.

๐Ÿ—ณ๏ธ Riksdagsmonitor โ€” Swedish Political Intelligence

AI-driven monitoring of Sweden's Riksdag, Government and public agencies โ€” 349 current MPs, 2,494 historical politicians (1971โ€“2024), 3.5M+ votes, 109,000+ documents, 14 languages, every day.

Riksdagsmonitor live platform Riksdagsmonitor source on GitHub riksdagsmonitor npm package OpenSSF Scorecard for Riksdagsmonitor OpenSSF Best Practices badge for Riksdagsmonitor Ask DeepWiki about Riksdagsmonitor Riksdagsmonitor license

๐Ÿ”— Surfaces: Live ยท Political Intelligence Hub ยท AI Newsroom ยท Dashboard ยท Sitemap ยท Features ยท Docs

๐Ÿ‡ช๐Ÿ‡บ EU Parliament Monitor โ€” European Political Intelligence

Brussels and Strasbourg made readable. AI-newsroom over the European Parliament's open data โ€” 8 unified gh-aw workflows, 51 analytical artifacts per run, 14 languages, 1,700+ daily artifacts, full Admiralty / WEP / SAT / ACH tradecraft.

EU Parliament Monitor live platform EU Parliament Monitor source on GitHub OpenSSF Scorecard for EU Parliament Monitor OpenSSF Best Practices badge for EU Parliament Monitor SLSA Level 3 attestations for EU Parliament Monitor Ask DeepWiki about EU Parliament Monitor EU Parliament Monitor license

๐Ÿ”— Surfaces: Live ยท Political Intelligence Hub ยท Sitemap ยท API Docs ยท Features ยท Docs

๐Ÿ”Œ European Parliament MCP Server โ€” AI Data Backbone

Canonical TypeScript Model Context Protocol server bridging the European Parliament Open Data Portal v2 to any MCP-aware AI client (Claude Desktop, VS Code, Cursor, GitHub Copilot). 62 tools, 9 resources, 7 prompts, full GDPR-by-design.

European Parliament MCP Server source on GitHub european-parliament-mcp-server npm package european-parliament-mcp-server npm monthly downloads OpenSSF Best Practices badge for European Parliament MCP Server Ask DeepWiki about European Parliament MCP Server European Parliament MCP Server documentation portal

๐Ÿ”— Surfaces: Repository ยท npm ยท API Docs ยท Features ยท Docs

๐Ÿ•ต๏ธ Citizen Intelligence Agency (CIA) โ€” Sweden's Data Backbone

Java/Spring/Vaadin OSINT platform monitoring Sweden's Riksdag, Government and Myndigheter since 2008. 110 database views, 50 risk-detection rules, 1971โ€“2024 longitudinal coverage, 3.5M+ votes, 109K+ documents. The data backbone behind Riksdagsmonitor.

Citizen Intelligence Agency source on GitHub Citizen Intelligence Agency Maven site OpenSSF Scorecard for Citizen Intelligence Agency CII Best Practices badge for Citizen Intelligence Agency SLSA Level 3 attestations for Citizen Intelligence Agency SonarCloud quality gate for Citizen Intelligence Agency Ask DeepWiki about Citizen Intelligence Agency Citizen Intelligence Agency license

๐Ÿ”— Surfaces: Repository ยท Architecture ยท Security Architecture ยท Threat Model ยท Features ยท Docs

๐Ÿ“‹ CIA Compliance Manager โ€” Browser-Based GRC

React 19 / TypeScript 6 platform for CIA-triad assessment, multi-framework compliance, threat modeling and business-impact quantification. Available as a live web app and a tree-shakeable npm library with 10 subpath exports.

CIA Compliance Manager live application CIA Compliance Manager source on GitHub cia-compliance-manager npm package OpenSSF Scorecard for CIA Compliance Manager OpenSSF Best Practices badge for CIA Compliance Manager SLSA Level 3 attestations for CIA Compliance Manager Ask DeepWiki about CIA Compliance Manager

๐Ÿ”— Surfaces: Live App ยท npm ยท API Docs ยท Features ยท Docs

๐Ÿฅ‹ Black Trigram (ํ‘๊ด˜) โ€” Korean Martial-Arts Combat Simulator

Production-ready 3D precision combat simulator. Eight I Ching trigram stances ยท 70 vital points ยท 51 authentic Korean martial-arts techniques ยท 5 fighter archetypes ยท 60fps desktop / 55fps+ mobile. React 19 ยท Three.js ยท TypeScript 6 ยท Vite 8.

Play Black Trigram live Black Trigram source on GitHub blacktrigram npm package OpenSSF Scorecard for Black Trigram OpenSSF Best Practices badge for Black Trigram SLSA Level 3 attestations for Black Trigram Ask DeepWiki about Black Trigram

๐Ÿ”— Surfaces: Play ยท API Docs ยท Security Architecture ยท Threat Model ยท Features ยท Docs

๐ŸŽฎ Game Template โ€” Secure-by-Default Game Starter

Reference implementation of a secure web-game project: React + TypeScript + Three.js + Vite, SLSA 3, full SBOM, automated security testing, ISMS-policy mapping ready to fork.

Hack23 secure game template Game template ISMS policy mapping

โ˜๏ธ Lambda in Private VPC โ€” AWS Reference Architecture

Battle-tested reference implementation: AWS Lambda in a private VPC with VPC endpoints, CloudFront, WAF, KMS encryption, CloudTrail and Security Hub integration.

AWS Lambda in private VPC reference architecture Tutorial on hack23.com blog

๐Ÿงช Sonar-CloudFormation-Plugin โ€” Infrastructure-as-Code Static Analysis

Open-source SonarQube plugin that brings CloudFormation IaC scanning into existing SonarQube/SonarCloud quality gates.

Sonar CloudFormation plugin source on GitHub Hack23 SonarCloud organisation


๐Ÿ›ก๏ธ Public ISMS โ€” Hack23/ISMS-PUBLIC

A fully public, version-controlled, machine-verifiable Information Security Management System. 38 policies covering access control, cryptography, secure development, threat modeling, vulnerability management, AI governance, GDPR privacy, EU CRA, ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1.

Hack23 public ISMS repository Information Security Policy ISMS compliance checklist

Domain Key Policies
๐Ÿ› ๏ธ Secure Development Secure Development Policy ยท Threat Modeling ยท Vulnerability Management ยท Change Management
๐Ÿ”‘ Access & Identity Access Control Policy ยท Segregation of Duties ยท Mobile Device Management
๐ŸŒ Network & Crypto Network Security Policy ยท Cryptography Policy
๐Ÿ’พ Continuity Backup & Recovery ยท Business Continuity Plan ยท Disaster Recovery Plan
๐Ÿšจ Incident Incident Response Plan
๐Ÿค– AI & LLM AI Policy ยท OWASP LLM Security Policy