Armory
United States · www.armory.io · 25 vendors
Armory, Inc. develops a software delivery platform that automates software deployment, enabling companies to quickly and safely deploy software into multiple clouds from code. The company provides continuous deployment solutions, often built on open-source Spinnaker, to accelerate time-to-market and increase stability for enterprises.
Resilience scores
- Digital Sovereignty: 84
- Digital Resilience: 8
- Financial Resilience: 5
Technology vendors
- Adobe Inc. — Technology — United States
- Jobvite — Technology — United States
- Pulumi — Technology — United States
- and 22 more
Services catalogue
1 service in catalogue across 1 category; runs on 25 sub-vendors.
- Spinnaker
Insights
Last updated 2026-08-14 · revision 2
25 direct vendors, 267 subvendors
Direct vendors by controlling owner country (sample)
- United States: 21
- UK: 1
- Canada: 1
Subvendors by controlling owner country (sample)
- New Zealand: 1
- Japan: 3
- Norway: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Armory exhibits exceptionally high migration readiness, largely due to its cutting-edge, cloud-native, and containerized technology stack. The company extensively uses Kubernetes, Docker, AWS, and GCP, demonstrating a strong foundation in multi-cloud environments. Their expertise in Continuous Delivery (CD), Progressive Delivery, GitOps, and automated deployment strategies (canary, blue/green) means their systems are designed for agility and portability. The adoption of Open Policy Agent (OPA) for policy enforcement and tools like Helm and Terraform for infrastructure as code further streamline deployment and configuration management, making migrations significantly easier. The absence of specified data residency requirements also simplifies potential migration efforts. Their core business of providing modern deployment solutions (Spinnaker-based and Project Aurora) implies a deep internal understanding and capability for such transitions. The primary gaps in assessing migration readiness are the lack of financial stability data (revenue, growth history) which could impact the funding of large-scale migrations, and the absence of information on the regulatory environment, which might introduce unforeseen compliance complexities. While the tech stack points to low technical lock-in, the 'Total Vendors: 0' data point, contrasted with 33 services and diverse vendor HQs, creates ambiguity regarding their actual vendor relationships and potential contractual complexities or dependencies that could affect migration. The 'Vendor Lock-in Risk: Unknown' also leaves a blind spot.
Compliance
6 in-scope frameworks identified; showing 3.
FedRAMP — Assessment Required
FedRAMP (Federal Risk and Authorization Management Program) is required for cloud service providers that offer services to US federal government agencies. Armory/Harness serves enterprise customers across industries, and given the nature of CI/CD platform services, US government agencies may be among their customers. If Armory/Harness has or seeks US federal government contracts, FedRAMP authorization would be required. Risk is Medium because: (1) the DevOps/CI-CD market increasingly includes government customers; (2) without FedRAMP authorization, the company cannot legally provide cloud services to federal agencies; (3) FedRAMP authorization is a lengthy and costly process; (4) no public evidence of FedRAMP authorization was found. The risk is not High because there is no confirmed evidence of federal government customer relationships.
Evidence: https://www.harness.io/security, https://marketplace.fedramp.gov/
CCPA — Compliant
Armory was headquartered in San Jose, California, USA. As a California-based technology company serving consumers and businesses, CCPA/CPRA (California Privacy Rights Act) applies. Harness explicitly states compliance with CCPA on its security page. Risk is Low because: (1) compliance is publicly confirmed; (2) an opt-out mechanism ('Do Not Sell / Share My Personal Information') is provided via harness-privacy.relyance.ai; (3) a Privacy Statement is published; (4) the company has a Privacy Request mechanism. CCPA fines are up to $7,500 per intentional violation, but the company's demonstrated compliance posture reduces enforcement risk.
Evidence: https://www.harness.io/security, https://www.harness.io/legal/privacy, https://harness-privacy.relyance.ai/
ISO 27001 (source) — Compliant
Harness (acquirer of Armory) explicitly states ISO 27001 certification on its security page, alongside ISO 27017 (cloud security) and ISO 27018 (protection of PII in public clouds). ISO 27001 is the international standard for Information Security Management Systems (ISMS). Risk is Low because: (1) certification is publicly confirmed; (2) ISO 27001 requires annual surveillance audits and triennial recertification by accredited certification bodies; (3) the additional ISO 27017 and 27018 certifications demonstrate a mature, cloud-specific security posture; (4) the certification covers the organizational controls that underpin all other compliance frameworks. The main uncertainty is whether the certification was obtained by Harness as a whole entity post-acquisition of Armory, or whether Armory had its own pre-acquisition certification.
Evidence: https://www.harness.io/security, https://trust.harness.io/
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 5/10
Armory was a venture-backed private US software company (2016-2023) whose financials were never publicly filed. Third-party estimates suggest revenue in the low tens of millions of dollars annually (US$20-40M range), but no primary source confirms specific figures. The company raised roughly US$82M in venture capital across seed through Series C rounds, providing meaningful runway but also indicating it was operating at a loss like most late-stage venture-backed SaaS companies. The company faced intense competition from Harness, GitLab, CircleCI, JFrog, CloudBees, and open-source alternatives (ArgoCD, Flux, Tekton), plus hyperscaler-native tooling. Spinnaker's operational complexity had become a well-known adoption barrier, pressuring Armory's growth story. Two rounds of layoffs in mid-2022 and 2023 indicate cash-burn discipline was required and that the company was managing runway pressures. Ultimately, financial resilience issues were resolved by being absorbed into Harness in December 2023 for undisclosed terms. As part of Harness (which raised a $240M Series E in 2025 at ~$5+ billion valuation), Armory's technology and customer contracts now sit inside a much better-capitalized parent. Standalone financial resilience of Armory is no longer a meaningful concept.
Key strengths: Raised approximately US$82M in venture capital across seed through Series C, Leading commercial steward of Spinnaker open-source CD platform, Blue-chip enterprise customer base (JPMorgan Chase, Salesforce, Autodesk, Comcast, Home Depot), Reputable investor backing (B Capital, Insight Partners, Bain Capital Ventures, Crosslink Capital, Google Ventures), Recurring SaaS/subscription revenue model, Acquired by well-capitalized Harness in December 2023
Risk factors: Intense competition from Harness, GitLab, CircleCI, JFrog, CloudBees, Competition from open-source alternatives (ArgoCD, Flux, Tekton), Competition from hyperscaler-native tooling (AWS CodePipeline, Google Cloud Deploy), Spinnaker operational complexity as adoption barrier, Two rounds of layoffs in 2022 and 2023 indicating cash burn pressure, Never disclosed profitability; likely operating at a loss, Loss of standalone identity following Harness acquisition
Revenue by geography
- North America (United States): 85%
- EMEA and APAC: 15%
Revenue by product/service
- Armory Enterprise for Spinnaker: 70%
- Armory Continuous Deployment-as-a-Service (CDaaS): 20%
- Professional Services / Training / Support: 10%
Workforce by country
- United States: 135
- EMEA: 0
- India: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.