Security

Your data never leaves. That’s the design.

A security product that ships your agents’ data to a vendor cloud is a new liability, not a control. NOCTRYS runs entirely in your own infrastructure, governs your agents locally, and never transmits your data. Only a 32-byte hash of the audit log is anchored on-chain.

self-hostedzero-dependency corefail-closedonly 32 bytes leavenothing to breach

Design principles

  • Self-hosted — no NOCTRYS cloud ever sees your prompts, tools, arguments, or data. There is nothing for us to leak.
  • Deterministic & fail-closed — no AI model in the enforcement decision path; malformed or unknown actions are blocked, never forwarded.
  • Small, auditable core — a zero-heavy-dependency enforcement engine you can read and reason about, not a black box.
  • Tamper-evident by construction — a hash-chained log, anchored on a neutral chain and cosigned by independent witnesses.
  • Minimal on-chain footprint — a single 32-byte Merkle root leaves your boundary; nothing else.

What this means for your review

Because NOCTRYS is self-hosted, there is no third-party cloud to put through a security review, no data-processing agreement covering your agents’ traffic, and no new exfiltration path. Your audit scope stays yours. That is deliberate: it lets you pilot NOCTRYS now, without waiting on a vendor’s certifications — and it shrinks the surface an attacker or an auditor has to consider.

Robustness

NOCTRYS is built to fail closed and to never crash on hostile input: malformed arguments, circular structures, oversized payloads, hidden-Unicode smuggling, and unexpected types are handled deterministically rather than trusted. The enforcement core is covered by an automated regression suite (63 tests) and a benchmark that holds a 0% attack-success rate over a battery of real agent attacks.

0
fail-open cases under hostile-input probing
63
automated regression tests, green
0%
attack success across the battery
~16µs
overhead — no reason to bypass it

Be one of our first five design partners

Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.

Request a pilot →