Standardize the build
Define the OS, policy, software, and publish targets once. Primcoat turns that configuration into a repeatable golden image workflow.
The protective base. Built into every image.
Primcoat is a fully managed VM image factory. Describe the image you want — operating system, hardening policy, software, and destinations — and Primcoat builds it, hardens it, scans it, signs it, and ships it to your cloud.
Get started now and have your first hardened image in about 15 minutes — a typical estimate, before publishing to your clouds.
From request to release
Define the OS, policy, software, and publish targets once. Primcoat turns that configuration into a repeatable golden image workflow.
Every build emits a compliance signal, an SBOM, a CVE scan, a Cosign signature, and SLSA provenance so your security team sees the same artifact you ship.
Primcoat converts and publishes the same hardened definition to each destination you target, preserving a single compliance baseline.
No Packer HCL to write. No Ansible playbooks to maintain. No build fleet to babysit. Define the OS, the hardening policy, the software, and the destinations — Primcoat owns everything in between.
Ubuntu, RHEL, Debian, AlmaLinux, Rocky, Windows Server. Hardening a golden image should not require migrating to somebody else's base operating system.
Every build produces a compliance report, a CycloneDX and SPDX SBOM, a CVE scan, a Cosign signature, and SLSA provenance. When an auditor asks what is in the image, you have the answer already.
Not a registry that tracks images somebody else built. Primcoat runs the build itself — hardening, scanning, and signing, with publishing to your clouds on top.
Pull a verified upstream cloud image or ISO.
Install your packages and run your Ansible hooks.
Apply CIS L1/L2 or STIG with OpenSCAP auto-remediation.
Re-scan for a compliance score, then scan for CVEs.
Produce an SBOM, sign with Cosign, attach SLSA provenance.
Convert per destination and ship to your clouds.
Primcoat builds a single hardened base image, then converts and publishes it to each target — injecting the right guest agent and the right disk format for each one.
Request access, describe the image you want, and have your first hardened image in about 15 minutes — a typical estimate, before publishing to your clouds. Primcoat builds, hardens, scans, signs, and publishes it, on the operating systems you already run.