---
title: "Deploy CISO Assistant | (Just Updated) GRC You Can Actually Log Into"
category: "Other"
url: https://railway.com/deploy/ciso-assistant-v3210-or-grc-you-can-actu
---

# Deploy CISO Assistant | (Just Updated) GRC You Can Actually Log Into

**[Deploy CISO Assistant | (Just Updated) GRC You Can Actually Log Into on Railway](https://railway.com/template/ciso-assistant-v3210-or-grc-you-can-actu)**

- **Creator:** SuperSlowSloth
- **Category:** Other
- **Total deploys:** 1

## Template content

### backend

- **Image:** ghcr.io/bon5co/ciso-assistant-railway-backend:3.21.0

### web

- **Image:** ghcr.io/bon5co/ciso-assistant-railway-frontend:3.21.0
- **Public domain:** Yes

## Documentation

# Deploy and Host CISO Assistant on Railway

CISO Assistant is an open-source GRC platform: risk assessments and a risk
register, compliance audits against 150+ built-in frameworks (ISO 27001, NIS2,
SOC 2, CRA, GDPR, NIST CSF and more), applied controls, evidence, findings,
incidents and third-party assessments.

This template ships CISO Assistant 3.21.0 with the admin account already
created from a generated password, so the deploy is usable the moment it goes
green, and with the database, the attachments and the job queue on a persistent
volume.

## About Hosting CISO Assistant

Two services: the web app (SvelteKit UI plus an in-container nginx gateway) on a
public domain, and the Django API with its huey worker on private networking.
Upstream's reference deployment is five containers — a separate reverse proxy,
a separate worker, Postgres and Qdrant. The proxy and the worker are folded in
here, the app runs on SQLite (the backend selects it whenever no Postgres is
configured, which is upstream's supported single-instance mode), and Qdrant is
left out because it only backs the optional semantic-search feature. That is
two billed services instead of five for the same product.

Everything durable lives under one volume at `/code/db`: the SQLite database,
the huey queue, the generated Django secret key and every uploaded piece of
evidence.

The admin account is created during boot, before the API accepts its first
request, from the generated `DJANGO_SUPERUSER_PASSWORD`. Log in with that value
from the Variables tab. If you change it and redeploy, the password is reset to
the new value — upstream's own bootstrap only ever runs once and silently fails
afterwards. The backend refuses to start with an empty password rather than
publish an instance nobody can log in to; CISO Assistant has no sign-up page, so
that state has no way out.

Login requests are rate limited to 10 per minute per client address at the
gateway, keyed on the real client behind Railway's proxy. Upstream ships no
login throttle at all.

Both images are pinned to the 3.21.0 release. The backend applies Django
migrations forward on every start and never reverses them, so tracking `latest`
would make each redeploy an unrequested, one-way upgrade.

## Common Use Cases

- Running an ISO 27001 or SOC 2 programme: controls, evidence and audit progress in one place
- A risk register with quantified assessments and a review workflow
- Third-party and supplier assessments, incidents and findings tracked against the same frameworks

## Dependencies for CISO Assistant Hosting

- CISO Assistant 3.21.0 backend (`ghcr.io/bon5co/ciso-assistant-railway-backend`)
- CISO Assistant 3.21.0 frontend + nginx gateway (`ghcr.io/bon5co/ciso-assistant-railway-frontend`)
- One persistent volume on the backend service

### Deployment Dependencies

- Upstream project: https://github.com/intuitem/ciso-assistant-community
- Wrapper images: https://github.com/bon5co/ciso-assistant-railway
- Documentation: https://intuitem.gitbook.io/ciso-assistant

### Implementation Details

The first boot applies the full migration set and imports the built-in library
of frameworks, which takes several minutes; the app answers on its domain as
soon as the UI is up and the API follows. No external services, API keys or SMTP
configuration are required.


## Similar templates

- [Rocky Linux](https://railway.com/deploy/rocky-linux) — [Jul'26] Hosted Rocky Linux 9 workspace with SSH and persistent storage. 🚀
- [Foundry Virtual Tabletop](https://railway.com/deploy/X5tR6G) — A Self-Hosted & Modern Roleplaying Platform
- [Letta Code Remote](https://railway.com/deploy/letta-code-remote) — Run a Letta Code agent 24/7. No inbound ports, just deploy.

Open this page in a browser: https://railway.com/deploy/ciso-assistant-v3210-or-grc-you-can-actu
