Cosign signatures
Every release is signed with a KMS-keyed ECDSA P-256 key — offline-verifiable against the public key this portal serves, with no Sigstore TUF or Rekor lookups required.
Distribution portal · cp.autonomize.ai
Genesis installs into your own Kubernetes with ArgoCD,
from charts and images you host in your own registry. This portal
carries the release evidence — SBOMs, HIPAA attestations, the
release public key and the genesis CLI.
Signing in is optional; the install does not depend on it.
Copy both charts and every image they reference from Autonomize's distribution registry into your own — a straight registry-to-registry copy, nothing downloaded as a file. Your Autonomize contact issues a short-lived pull credential scoped to that registry.
Commit your values to your own git repo, register both sources in
ArgoCD, then apply two Applications —
genesis-ops first, genesis-platform
second. selfHeal keeps the platform converged on your
repo from then on. Nothing calls home.
Signing in is optional. A license key gets you the CycloneDX SBOMs, the HIPAA attestation and the release notes for the versions your organisation is entitled to — useful for your scanner and your auditors, not required to install. Request access if you do not have a key.
Every release is signed with a KMS-keyed ECDSA P-256 key — offline-verifiable against the public key this portal serves, with no Sigstore TUF or Rekor lookups required.
CycloneDX SBOM for every release — full container, OS, and Python dependency tree, ready for your vulnerability scanner.
A signed PDF attestation enumerates every change since the last release, including any HIPAA-relevant safeguards.