Trust

Licensing, attribution & provenance

Every package states where its content came from, what licence governs it, and whether the Marketplace can distribute it. Nothing is repackaged without the right to do so.

Two kinds of package

Included content

Openly licensed material (CC BY, Apache-2.0, MIT, public domain, US government work) that the Marketplace distributes directly, with attribution preserved.

Link-only / mapping

Proprietary or purchase-required standards (ISO, IEC, ASTM, SOC 2, PCI DSS). The package ships mappings, crosswalks and integration scaffolding; the content itself is obtained from the standards body under its own terms.

Attribution

Packages that require attribution carry the exact attribution string in their metadata and manifest, so Nimble can surface it wherever the content is used. Removing attribution from a derived twin is a licence violation, not a formatting choice.

Provenance

Every package records a source authority and canonical source URL — NIST, MITRE, CISA, NASA, W3C, OMG, an industry consortium or the publisher itself. Seed content in this catalog is drawn from real, citable sources; nothing is invented to make the catalog look fuller.

Publisher types

  • First-party — published and maintained by the Nimble team.
  • Community — contributed and maintained by users, reviewed before publication.
  • Standards body — derived from an authoritative organisation's published material.