Deploy
Runs where your agents already run.
One enforcement core, three ways to run it. The governance, the audit, and the proof are identical across all three — pick the one that fits your runtime and latency budget.
self-hosted always~10-min installNode · Go · Dockerzero dependenciesonly 32 bytes leave
MCP
Proxy / stdio
Installable as an MCP server your agent runtime spawns. Every tools/call is governed before it runs.
HTTP
Sidecar
Agents POST /v1/intercept; a live compliance console streams every decision.
GO
Single binary
One static binary for the latency-critical path. No runtime, no dependencies.
Self-hosted, always. NOCTRYS never sees your data; only a 32-byte hash of the audit log is anchored on-chain. See the install guide →
Same guarantees, whichever you pick
| MCP | HTTP sidecar | Go binary | |
|---|---|---|---|
| Deterministic policy + detection | ✓ | ✓ | ✓ |
| Tamper-evident audit + AERE anchor | ✓ | ✓ | ✓ |
| Live streaming console | — | ✓ | — |
| Lowest latency / no runtime | — | — | ✓ |
| Best for | MCP tool stacks | services & observability | hot path |
Be one of our first five design partners
Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →