Your data never leaves. That’s the design.
A security product that ships your agents’ data to a vendor cloud is a new liability, not a control. NOCTRYS runs entirely in your own infrastructure, governs your agents locally, and never transmits your data. Only a 32-byte hash of the audit log is anchored on-chain.
Design principles
- Self-hosted: no NOCTRYS cloud ever sees your prompts, tools, arguments, or data. There is nothing for us to leak.
- Deterministic & fail-closed: no AI model in the enforcement decision path; malformed or unknown actions are blocked, never forwarded.
- Small, auditable core: a lean enforcement engine with no heavy dependencies, one you can read and reason about, not a black box.
- Tamper-evident by construction: a hash-chained log, anchored on a neutral chain and cosigned by independent witnesses.
- Minimal on-chain footprint: a single 32-byte Merkle root leaves your boundary; nothing else.
What this means for your review
Because NOCTRYS is self-hosted, there is no third-party cloud to put through a security review, no data-processing agreement covering your agents’ traffic, and no new exfiltration path. Your audit scope stays yours. That is deliberate: it lets you pilot NOCTRYS now, without waiting on a vendor’s certifications, and it shrinks the surface an attacker or an auditor has to consider.
Robustness
NOCTRYS is built to fail closed and to never crash on hostile input: malformed arguments, circular structures, oversized payloads, hidden-Unicode smuggling, and unexpected types are handled deterministically rather than trusted. The enforcement core is covered by an automated regression suite (142 tests) and an internal benchmark that holds a 0% attack-success rate over a 13-attack battery.
How we report benchmark numbers
Every security and performance number we publish today is internal: the attack battery is self-authored (so a 0% attack-success rate against it is a consistency check, not proof of security), the ~16µs figure is a mean from one machine, and the OWASP coverage map is a self-assessed mapping, because OWASP ships no scored harness. Those limits are stated plainly in our public benchmark methodology, and a defense-adapter surface ships in the repo so third-party harnesses such as AgentDojo and OASB can run the governor without our involvement. We claim no public-benchmark numbers until pinned-version, third-party-reproducible runs exist.
Be one of our first five design partners
Free pilot. A two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →