Architecture validator
Loft
Validate system designs against compliance policy before any code is approved. Works with public control catalogs out of the box — no policy authoring required to get started.
What it does
Loft is Meridian's architecture governance component. It lets Cloud Architects design systems using CALM — the Common Architecture Language Model — and validates those designs against an active control set before approval. If a proposed architecture violates a security constraint or fails to satisfy a compliance requirement, Loft flags it at design time, when it is cheapest to fix. If the design passes, it is recorded as an approved, immutable architecture artifact that the rest of the platform can reference.
Loft ships pre-loaded with the FINOS Common Cloud Controls and OpenSSF OSPS Baseline as default validation sets. Architectures are checked against these catalogs without any additional configuration. When Meridian Chancery is present, Loft automatically ingests organisation-specific policies and validates against those instead of — or in addition to — the public catalogs.
Who it's for
Loft is used by Cloud Architects responsible for designing systems that must satisfy security and compliance requirements. It is also relevant to Security Engineers who need a structured record of approved architectures and the assurance that nothing is deployed without design-time validation.
Start here if…
Your architecture team wants to govern system designs against a common control set — but your organisation does not yet have a formal machine-readable policy programme. Loft can be deployed as a standalone architecture governance tool using the FINOS CCC and OSPS Baseline catalogs as its validation set. Architects design in CALM, Loft validates against the public catalogs, and approved designs are recorded as auditable artifacts.
Add Meridian Chancery when your organisation needs to validate against proprietary policies, custom control mappings, or regulatory requirements not covered by the public catalogs. Add Meridian Slipway when you want deployment to be gated on Loft approval — so nothing reaches production without a validated, approved architecture on record.
Works best with
-
Meridian Chancery
Adds organisation-specific policy to Loft's validation set. Without Meridian Chancery, Loft validates against public catalogs. With Meridian Chancery, it validates against your policies.
-
Meridian Slipway
Approved Loft architectures gate Meridian Slipway deployments. Add Meridian Slipway when you want the deployment pipeline to enforce architecture approval before any resource is provisioned.
-
Meridian Patrol
Approved CALM architectures become the reference state that Meridian Patrol monitors against at runtime. Add Meridian Patrol when you need continuous assurance that production systems match their approved design.
How it fits the platform
Loft occupies the design-time layer of the compliance loop — between policy definition and deployment. It is the point where human architectural decisions become machine-validated, auditable commitments. An architecture approved by Loft is not just a diagram in a repository; it is a structured artifact that every downstream component can reference. Meridian Slipway deploys it. Meridian Patrol monitors against it. Meridian Admiralty reports on it.
Meridian