Integrations

Fits the stack you already have.

NOCTRYS speaks the protocols your agents and your security team already use. It slots in where agents call tools, and streams evidence to where your ops and compliance teams already look — no re-platforming.

MCP proxy + stdioHTTP / SSE sidecarGo binarySIEM exportPrometheus /metricsAERE anchor
Where agents call tools

Governance points

MCP

Model Context Protocol

Govern any MCP tools/call — installed as a proxy or a stdio server your runtime spawns. Blocks never reach the tool.

HTTP

HTTP / SSE sidecar

Agents POST /v1/intercept; a live console streams every decision over Server-Sent Events as it happens.

GO

Single static binary

Drop the Go binary on the latency-critical path. No runtime, no dependencies, same verdicts.

Where evidence flows

Observability & proof

SIEM

SIEM & webhooks

Forward every decision to Splunk, Elastic, or any SIEM via webhook — your existing detection and IR workflows keep working.

METRICS

Prometheus

Scrape /metrics for noctrys_actions_total, decisions by verdict, and subscriber counts.

AERE

AERE anchor

The tamper-evident audit root is anchored on the post-quantum AERE chain — the neutral notary you don’t control.

RFC 9421

Web Bot Auth

Every governed agent signs its egress as a verified bot (HTTP Message Signatures), reusing its SVID key.

IDENTITY

SPIFFE / A2A

Interoperates on top of your identity plane — Ed25519 SVIDs and signed A2A agent messages.

AP2

Payment mandates

Verifies signed AP2 consent chains before a money-moving tool call is allowed to run.

One enforcement core, many surfaces. The governance decision, the tamper-evident record, and the independently-verifiable proof are identical no matter which integration you run.

Be one of our first five design partners

Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.

Request a pilot →