Nothing ships unsigned.
The Armory Catalog
Signed genome packages, hardened Terraform modules, and canonical framework packs in one governed catalog. Open to browse. Gated to act. Every package is designed to prove its provenance, preview its impact, and go live under the same gates as code.
The Governed Catalog
Available means verified.
Armory is the distribution surface of the compliance control plane. The architecture specifies it as a governed-automation marketplace: signed, provenance-verified packages of skills, policy packs, and remediation actors alongside hardened infrastructure modules and framework packs. Public to browse, gated to act: nothing crosses from catalog to customer without a signature, a sandbox class, and a staged path to live.
What the Armory Holds
Every capability in the platform answers one question. Garrison answers what you have. Sentinel answers what is happening. The Armory answers what is available: the artifacts an organization can take into its estate. The catalog holds three families. Genome packages carry behavior: skills, policy packs, and remediation actors, each a versioned unit of governed automation. Hardened modules carry infrastructure: Terraform that encodes security decisions as exact values. Framework packs carry compliance content: control catalogs ingested to canonical form, the raw material Rampart is designed to project assessments from.
Distribution is where supply chains break, and compliance platforms are not exempt. A module copied from a public registry answers none of the questions that matter. Who wrote it. What can it touch. What changes when it runs. Most marketplaces optimize for listing volume and push verification onto the consumer, which holds up until the consumer is also the party being audited. A catalog that distributes automation distributes behavior, and behavior without provenance is a supply-chain hole in the very layer that exists to prove supply chains.
The Catalog Is Attack Surface
A marketplace inside a compliance control plane cannot hold itself to a lower standard than the posture it serves. Every package counts as untrusted until its signature, its origin class, and its declared reach say otherwise.
Provenance Before Reach
A package's identity is its content. An action contract references its adapter by a content-addressed genome reference, and the signature verifies before anything loads. That settles authorship. A second axis settles reach: every adapter carries an origin class. Trusted first-party. Verified partner. Sandboxed marketplace. The architecture states the division plainly: signing proves who wrote it, and the execution class bounds what it can touch.
Marketplace packages ship sandboxed unless their author is partner-verified. Sandboxed is a defined condition, not a label: a capability-scoped sandbox with no ambient network, no ambient filesystem, and egress only to destinations the package declared at publication. The same discipline covers remediation actors, the packages with the most reach. A codified fix executes under an action contract and an authority envelope, never as a script someone downloaded. Blast radius is assigned when a package is published, not discovered when it runs.
Behavior Change Is Deployment
The platform's skills, rules, prompts, and policies are its engineering DNA: versioned data on the substrate, shared by every actor, Artificer included. The constitution treats any change to that genome as a deployment. A mutation moves from proposed to shadow-evaluated, replayed against historical transactions or run in simulation, then to staged, then to promoted, with rollback armed at every step. Behavior rides the same gate discipline as code, because behavior is code by another name.
That gate discipline is what makes a marketplace of automation survivable. Installing a package from the catalog is a behavior change, and behavior change is deployment. A remediation actor fetched from the Armory does not begin acting on arrival; it enters the staged path like any other mutation. The marketplace is specified as the distribution channel for promoted genome: behavior that has already survived its gates. Beneath it sits a constitutional invariant: no learned behavior is live on arrival, and no drift is silent.
Nothing Live on Arrival
The catalog never hands behavior straight to production. Proposed, shadow-evaluated, staged, promoted: a package earns each grade, and rollback stays armed the whole way. Deployment discipline is the spine of the design, not its paperwork.
Framework Packs, Canonically Ingested
A framework pack begins as someone else's document. NIST publishes catalogs as structured OSCAL. DISA publishes STIGs as XCCDF. Control correlation identifiers, assessment procedures, and provider responsibility matrices each arrive in formats of their own. Ingestion converts all of it to one canonical form and preserves the source text immutably, so the 110 practices of CMMC Level 2 and a NIST 800-53 rev5 baseline resolve to the same schema while the exact regulatory wording survives every transformation.
Publication is a lifecycle, not an upload. A pack is authored, peer-reviewed, schema-validated, version-tagged, and only then published. Deprecation is explicit: a superseded version stays with the assessments pinned to it, and archived versions remain reachable for the historical assessments that cite them. When a framework revision lands, version diffs are computed and propagated through the platform's world model: affected controls, affected evidence, and per-customer deltas known on release day, with generated migration plans. That computation is Rampart's regulatory change intelligence. The catalog's job is to feed it clean, versioned truth.
Pinned, Not Frozen
A revision landing mid-assessment is not an emergency here. The pack you started against stays pinned. The new version lands beside it as a computed diff: controls added, controls changed, evidence affected. Migration happens on your timeline, from a delta, not from a rereading of the whole framework.
Two Module Lines
The module library is specified as two lines with different jobs. The community line is public open source: one module per AWS service, every security-relevant option present in the source and commented, documentation mapped to the controls each option serves. The modules publish as public mirror repositories that the Terraform Registry discovers. No account stands between an engineer and the building blocks, which is the point: the community line is the distribution and discovery funnel, not a teaser.
The hardened line consumes the community layer and closes it. STIG parameters are applied as exact values. Control correlation identifiers ride in module metadata. Security settings are hardcoded so a consumer cannot weaken them, deliberately: a module you can quietly soften is not hardened, it is decorated. Each hardened module carries an OSCAL component definition declaring the controls it satisfies, which makes satisfaction checkable. A deployed resource that matches the declared configuration records the control as satisfied by the module; one that drifts changes status, with detection assigned to Sentinel and re-evaluation to Rampart. The module's claim and the module's code travel together, which is the premise of infrastructure as evidence.
Hardening You Can Read
Hardened modules ship as source. Exact STIG values, mappings in the metadata, an OSCAL declaration of what each module claims to satisfy. Nothing here asks to be taken on faith; the claim and the code are the same artifact.
Browse Open, Act Gated
The catalog is public on purpose. The governing rule: gate the action, not the visibility. No hidden functionality, no coverage claim that takes a sales call to inspect. Anyone can read what exists, which frameworks it maps to, and what version it carries. Acting is different. Deploying a module, applying a pack, or promoting a genome package requires an authenticated identity and an entitlement. The line between reading and acting is exact, and it is the only line there is.
Action also comes with foresight. The design specifies a score-impact preview: before a package changes anything, the catalog shows what it would change. The preview is a posture projection, the current estate plus the candidate package, with the delta reported in controls and score, so a deployment decision is weighed against its consequences rather than its description. After deployment, the artifact joins the platform's standing loops: discovery populates the estate, and change events re-evaluate posture. Platform-executed realization of packs into customer environments is a candidate capability, held for a charter of its own; the specified path puts verified source in your hands.
Distribution Under Discipline
A catalog earns its place in a compliance control plane only if taking something from it cannot silently weaken the posture it serves. That is the specification here: signed on entry, sandboxed by default, previewed before impact, promoted under gates, reversible after. Available means verified.