Govern every agent action, and prove you did.
NOCTRYS sits inline between your agents and the tools they can touch. It judges each action against your policy, blocks the dangerous ones, watches for malicious behavior no static rule can catch, and seals every decision into an independently-verifiable record — deterministically, self-hosted, at roughly sixteen microseconds per action.
Every action — judged, verdicted, and sealed.
ef3f…0d39The problem NOCTRYS solves
A chatbot returns text. An agent acts: it moves money, reads your customer tables, calls tools, and delegates to other agents — on its own, over untrusted input. The entire industry has rushed to prove who an agent is (identity) and to filter what it says (model guardrails). Almost no one governs what it does at runtime, and no one lets you prove it to a third party.
That gap is where the real damage lives: a prompt-injected agent wiring funds, a compromised tool exfiltrating a customer database, an over-delegated sub-agent escalating its own privileges. NOCTRYS closes it by governing the action plane — the point where intent becomes consequence — and by turning "trust us" into "verify it yourself."
How it works
Every consequential action an agent takes flows through the NOCTRYS interceptor before it runs. The interceptor is deterministic (no AI model in the decision path, so verdicts are reproducible), fail-closed (malformed or unknown actions are blocked, never forwarded), and self-hosted (it runs in your infrastructure and never transmits your data).
Three layers
Deterministic policy
Least-privilege rules on every action — allowlist, argument & output schema, spend caps, rate limits, egress control, path/sequence policies, delegation limits, signed human approval, signed payment mandates. No model in the enforcement path. Explore Govern →
Behavior the rules miss
Two individually-allowed actions can still be an attack. NOCTRYS watches sequences, provenance, and per-agent baselines: exfiltration, prompt & indirect injection, information-flow, drift, memory poisoning, tool rug-pull, tool-shadowing. Explore Detect →
Proof, not promises
A hash-chained ledger anchored on the AERE chain and cosigned by independent witnesses, a public verifier anyone can use, execution receipts, assurance levels, and a collective-defense network. Explore Prove →
Every control, in one place
| Category | Controls |
|---|---|
| Least privilege | allowlist · argument schema · output schema · spend caps · rate limits |
| High-risk gating | signed human approval · signed payment mandates (AP2) · approval thresholds |
| Data & egress | egress/destination control · information-flow control · content-usage (AIPREF) · log redaction |
| Sequences & delegation | path/sequence policies · delegation depth/cycle/attenuation |
| Behavioral detection | exfiltration · prompt & indirect injection · drift · memory poisoning · probing/velocity |
| Supply chain | tool-drift (rug-pull) · tool-shadowing · Unicode/ASCII-smuggling guard · canary tripwires |
| Identity | Ed25519 SVID · signed A2A messages · Web Bot Auth egress signing |
| Proof & accountability | tamper-evident log · AERE anchor · witness cosigning · public verifier · execution receipts · assurance levels · collective defense · compliance report |
Everyone can log an action. Whom must you trust to believe it?
Gating and logging the action plane is now the whole field’s direction. The distinction that decides a regulated deployment is narrower: a trusted record still asks you to trust the vendor’s PKI, the vendor’s cloud, or the operator’s own logs. NOCTRYS produces provable proof that stands even if both the vendor and the operator are assumed hostile.
| When a regulator asks "prove it"… | NOCTRYS | Vendor PKI / attestation | Operator-controlled logs | Cloud-managed governor |
|---|---|---|---|---|
| Enforcement plane | Action plane — the tool-call boundary | Identity & PKI trust | Endpoint / cognition | Action plane (managed) |
| Policy origin | Deterministic, hand-authored — no model in the path | Vendor-managed | Often LLM-authored (probabilistic) | Deterministic, but decided in the vendor's cloud |
| Deployment | Self-hosted — only a 32-byte hash leaves | Vendor service | Vendor sensor + KB | Cloud / managed |
| Audit & proof | Hash-chain + AERE anchor + witness mesh + public verifier | "Cryptographically verifiable" — but vendor PKI | Attribution trail; no anchoring | Managed logs; no neutral audit layer |
| Non-equivocable? | Yes — can't tell two auditors two stories | No | No | No |
| Whom must you trust? | Neither vendor nor operator | The vendor (their roots) | The operator (they hold the log) | The cloud vendor |
| Collective defense | Yes — cross-deployment signature mesh | No | Vendor KB, one-directional | No |
Comparison characterizes competitors' publicly-stated posture (OSINT), not tested behavior; column headers describe categories of approach, not single named products.
Performance & footprint
Governance runs on the critical path of every agent action, so overhead matters. It is negligible: roughly 16 microseconds per action — tens of thousands of actions per second on a single core — against the hundreds of milliseconds an LLM tool call already takes. The on-chain footprint is a single 32-byte hash of the audit log; nothing else leaves your infrastructure.
Be one of our first five design partners
Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →