Changelog

Shipped.

A living record of the NOCTRYS enforcement core and moat.

  • noctrys serve: the governor boots as a self-hosted HTTP sidecar with one command from a policy file; Dockerfile and docker-compose included.
  • Decision-BOM: a deterministic bill of materials on every governed decision (policy hash, agent identity, tool fingerprint, verdict and reasons, mandate/provenance/delegation refs), hash-chained into the audit.
  • NIST SP 800-53 + CSA MAESTRO crosswalk: control-family mapping (AC, AU, CM, IA, IR, SI) and 7-layer alignment in the compliance report, alongside the EU AI Act mapping.
  • Content-usage (AIPREF): honor publisher AI opt-outs on agent fetches.
  • Web Bot Auth: signed, attributable agent egress (RFC 9421).
  • Tool-output schema: govern what a tool returns, not just its inputs.
  • Signed human approval: non-repudiable, action-bound sign-off.
  • Witness cosigning: non-equivocation for the audit trail.
  • Assurance levels L0 to L4: an objective governance grade per agent.
  • Execution receipts: prove what actually ran.
  • AP2 payment mandates: signed consent chains for money movement.
  • Collective defense: a cross-fleet threat network.
  • Public verifier + neutral notary: independently verifiable proof.