01
Portable content above open standards
We do not invent a new format. The commons curates content on
top of standards that already exist:
CACAO
for response playbooks,
Sigma
for detection rules,
OSCAL
and D3FEND
for controls, and
OCSF
for the shape of data on the wire. The missing layer — curation,
cross-standard mapping, and an open metrics catalogue — is what
the commons contributes back.
02
Bring your own orchestrator
The canonical content compiles into the runtime each operator
already has. Three launch compile targets:
n8n,
Temporal,
and LangGraph.
Community-contributed adapters are welcome for MindStudio, Make,
Zapier, StackAI, CrewAI, and anything else operators bring to
the commons. The commons does not ship a runtime of its own.
03
Sovereign by default
Reference deployments target European-resident, European-governed
infrastructure. The content is written to be coherent with the
European regulatory baseline — NIS2, DORA, CRA — without binding
to any single vendor's interpretation. AI providers are pluggable
and pinned by the operator; the commons takes no position on
which model you choose, only that you can choose.