Deploy

Runs where your agents already run.

One enforcement core, three ways to run it. The governance, the audit, and the proof are identical across all three — pick the one that fits your runtime and latency budget.

self-hosted always~10-min installNode · Go · Dockerzero dependenciesonly 32 bytes leave
MCP

Proxy / stdio

Installable as an MCP server your agent runtime spawns. Every tools/call is governed before it runs.

HTTP

Sidecar

Agents POST /v1/intercept; a live compliance console streams every decision.

GO

Single binary

One static binary for the latency-critical path. No runtime, no dependencies.

Self-hosted, always. NOCTRYS never sees your data; only a 32-byte hash of the audit log is anchored on-chain. See the install guide →

Same guarantees, whichever you pick

 MCPHTTP sidecarGo binary
Deterministic policy + detection
Tamper-evident audit + AERE anchor
Live streaming console
Lowest latency / no runtime
Best forMCP tool stacksservices & observabilityhot path

Be one of our first five design partners

Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.

Request a pilot →