OSuite Exchange

Plugin Exchange

OSuite extends runtime-neutral governance through a curated plugin exchange. The goal is platform expansion with trust, not an open marketplace that dilutes control.

Curated, not open submission

The exchange is intentionally curated. OSuite modules can be official, curated partner, or strategic watchlist entries. This keeps high-assurance workspaces from inheriting marketplace noise.

Plugin signing and workspace scopes

Every plugin listing resolves to an OSuite plugin manifest and exchange signature. Workspaces enable plugins with explicit scopes such as identity.attest, security.scan, compliance.map, or trust.anchor.

PCAA remains authoritative

Plugins can contribute runtime decisions, trust materials, or compliance signals, but they do not replace the action certificate. Replay, approval routing, proof closure, and export authority remain inside PCAA.

First wave of official packs

The first wave includes OSuite Identity Authority, OSuite Zero-Trust Gateway, OSuite Runtime Security, OSuite Verifiable Trust, OSuite ESG Intelligence, and OSuite Enterprise Governance.

Plugin types

runtime adapters
identity bridges
security packs
compliance packs
trust and wallet providers
vertical packs

Developer path

Build new OSuite modules through the plugin SDK, submit them into the internal review queue, and publish them under signed manifests with workspace-scoped enablement and audit events.

Cookie settings

Essential cookies keep sign-in and workspace routing stable. You can separately choose Analytics cookies and Preference cookies.