Skip to content

The protective base. Built into every image.

Hardened golden images, built and published automatically.

Primcoat is a fully managed VM image factory. Describe the image you want — operating system, hardening policy, software, and destinations — and Primcoat builds it, hardens it, scans it, signs it, and ships it to your cloud.

Get started now and have your first hardened image in about 15 minutes — a typical estimate, before publishing to your clouds.

From request to release

One image definition, one evidence trail.

See how the pipeline runs →
01

Standardize the build

Define the OS, policy, software, and publish targets once. Primcoat turns that configuration into a repeatable golden image workflow.

02

Keep the evidence

Every build emits a compliance signal, an SBOM, a CVE scan, a Cosign signature, and SLSA provenance so your security team sees the same artifact you ship.

03

Publish to each cloud

Primcoat converts and publishes the same hardened definition to each destination you target, preserving a single compliance baseline.

You bring configuration, not code

No Packer HCL to write. No Ansible playbooks to maintain. No build fleet to babysit. Define the OS, the hardening policy, the software, and the destinations — Primcoat owns everything in between.

The OS you already run

Ubuntu, RHEL, Debian, AlmaLinux, Rocky, Windows Server. Hardening a golden image should not require migrating to somebody else's base operating system.

Evidence, not assurances

Every build produces a compliance report, a CycloneDX and SPDX SBOM, a CVE scan, a Cosign signature, and SLSA provenance. When an auditor asks what is in the image, you have the answer already.

Every build runs the same pipeline.

Not a registry that tracks images somebody else built. Primcoat runs the build itself — hardening, scanning, and signing, with publishing to your clouds on top.

  1. 01

    Fetch

    Pull a verified upstream cloud image or ISO.

  2. 02

    Provision

    Install your packages and run your Ansible hooks.

  3. 03

    Harden

    Apply CIS L1/L2 or STIG with OpenSCAP auto-remediation.

  4. 04

    Validate

    Re-scan for a compliance score, then scan for CVEs.

  5. 05

    Attest

    Produce an SBOM, sign with Cosign, attach SLSA provenance.

  6. 06

    Publish

    Convert per destination and ship to your clouds.

Read the full pipeline →

One definition. Every destination.

Primcoat builds a single hardened base image, then converts and publishes it to each target — injecting the right guest agent and the right disk format for each one.

Get started now.

Request access, describe the image you want, and have your first hardened image in about 15 minutes — a typical estimate, before publishing to your clouds. Primcoat builds, hardens, scans, signs, and publishes it, on the operating systems you already run.