# ArmorCode

**Canonical:** https://apis.io/providers/armorcode/  
**Website:** https://www.armorcode.com/  
**APIs profiled:** 1

ArmorCode is a unified exposure and application security posture management (ASPM) platform that consolidates vulnerability and security findings from 350+ security tools and scanners into a single control plane. It uses a Context Risk Graph and agentic AI workflows (Anya agents) to prioritize risk and automate remediation across application, cloud, software supply-chain, and AI security. ArmorCode exposes a REST API on app.armorcode.com (US) and eu.armorcode.com (EU) for programmatic access to findings, integrations, and remediation workflows, secured with bearer API tokens. Originally surfaced as a Sierra Ventures portfolio company and enriched here from ArmorCode's public developer and trust surfaces.

## Kin Score — 27.6 / 100 (thin)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 27.6).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 0.0 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 28.6 |
| Commercial Clarity | 43.4 |
| Access Clarity | 43.4 |

## Agent readiness — 2.5 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **ArmorCode API** — ArmorCode's REST API for programmatic access to findings, integrations, and remediation workflows across the unified exposure-management platform. Secured with bearer API tokens...

## Security (4)

- **Armorcode Authentication** — http · 1 scheme
- **Armorcode Domain Security** — TLSv1.3 · HSTS · DMARC
- **Armorcode Vulnerability Disclosure** — Hackerone · contact published
- **Armorcode Trust Center** — SOC 2 Type 2

## Tags

Company, Security, Application Security, Vulnerability Management, ASPM, Exposure Management, DevSecOps, Compliance

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/armorcode/). Scores are computed from the provider's own public artifacts under a published rubric.
