Runtime governance · self-hosted · deterministic

The behavioral black box for AI agents.

Everyone verifies who your agent is. NOCTRYS watches what it does — every action judged in real time, blocked when it's dangerous, and sealed into a record that can't be rewritten.

0%
attack success
13/13
attacks blocked
10/10
OWASP Agentic
~16µs
per action
100%
self-hosted
0
data leaves
The gap

Agents don't answer. They act.

A chatbot returns text. An agent moves money, reads your customer tables, calls tools, and delegates to other agents — on its own, over untrusted input. The industry is busy proving an agent's identity at the perimeter. Almost no one is governing its behavior at runtime. That's the gap NOCTRYS closes: we don't try to read the model's mind — we gate its hands. Deterministic, inline, and fully observable no matter what happens inside the model.

How it works

Three layers between your agents and the damage.

01

Govern

Deterministic least-privilege rules on every action — no model in the enforcement path, so the verdict is reproducible and can't be talked out of the rules.

  • allowlist
  • arg + output schema
  • spend caps
  • rate limits
  • signed human approval
  • egress control
  • path policies
  • delegation limits
  • signed payment mandates
02

Detect

Two individually-allowed actions can still be an attack. NOCTRYS watches sequences, provenance, and per-agent baselines to catch what static rules can't.

  • exfiltration
  • prompt injection
  • indirect injection
  • info-flow control
  • drift
  • memory poisoning
  • tool rug-pull
  • canary tripwires
03

Prove

Every action is sealed into a hash-chained ledger, anchored on AERE and cosigned by independent witnesses — so no one, not even us, can rewrite or equivocate the record. Anyone can verify a NOCTRYS seal for themselves. Every deployment also feeds a shared threat network: an attack blocked at one customer protects them all.

  • tamper-evident log
  • AERE anchor
  • witness cosigning
  • public verifier
  • execution receipts
  • collective defense
  • assurance levels
  • compliance report
Deployment

Runs where your agents already run.

One enforcement core, three ways to run it — all self-hosted, inside your infrastructure. Your agents route through it; only a 32-byte proof ever leaves.

MCP

Proxy / stdio

Installable as an MCP server your agent runtime spawns. Every tools/call is governed before it runs.

HTTP

Sidecar

Agents POST /v1/intercept; a live compliance console streams every decision as it happens.

GO

Single binary

One static binary for the latency-critical path. Trivial to self-host — no runtime, no dependencies.

▪ self-hosted — NOCTRYS never sees your data; only a 32-byte hash of the log is anchored on-chain.
The deadline

High-risk agent rules are live from 2 August 2026.

Automatic logging, human oversight, robustness, six-month retention — and up to €15M or 3% of global turnover for getting it wrong. NOCTRYS maps to the obligations out of the box, so an agent becomes auditable without becoming slow.

Art. 12 — loggingArt. 14 — oversight + killArt. 15 — robustnessArt. 26 — retention
Why NOCTRYS

Not a gateway. Not a model guard. A governor with proof.

GATEWAYS

Route and rate-limit calls. They see traffic — not whether a sequence of allowed actions adds up to theft.

MODEL GUARDRAILS

Read prompts with another model. Probabilistic, and blind the moment the agent leaves the chat box to take an action.

NOCTRYS

Judges behavior on the action plane — deterministically, fail-closed — and cryptographically proves what it did. The part regulators actually ask for.

The pilot

Be one of our first five design partners.

Free pilot terms. A two-week, self-hosted integration. You keep the tamper-evident audit log and the AI Act compliance report from day one. In exchange — your honest feedback.

DESIGN PARTNER COHORT · 2 of 5 slots held · no data leaves