Every publisher is a verified identity. No anonymous uploads, no ghost accounts. Five tiers (○ ◐ ● ◆ ★) make trust visible at a glance.
A first blueprint from an unknown operator ships with a named sponsor who has read the code and put their reputation behind it.
Filesystem, network, shell, secrets: each capability a blueprint needs is listed, justified, and audited before install.
Every release is content-addressed by SHA-256. If a tarball doesn't match the registry, arc refuses to install it.
Every release index is signed by metafactory. When arc fetches the index, it verifies the signature against a key it already knows. A compromised mirror can't slip a fingerprint into the list.
Each release carries a cryptographic attestation tied to the author's identity, recorded in a public transparency log. You can verify not just that metafactory approved it, but that a specific person built it.