Changelog
Shipped.
A living record of the NOCTRYS enforcement core and moat.
- noctrys serve: the governor boots as a self-hosted HTTP sidecar with one command from a policy file; Dockerfile and docker-compose included.
- Decision-BOM: a deterministic bill of materials on every governed decision (policy hash, agent identity, tool fingerprint, verdict and reasons, mandate/provenance/delegation refs), hash-chained into the audit.
- NIST SP 800-53 + CSA MAESTRO crosswalk: control-family mapping (AC, AU, CM, IA, IR, SI) and 7-layer alignment in the compliance report, alongside the EU AI Act mapping.
- Content-usage (AIPREF): honor publisher AI opt-outs on agent fetches.
- Web Bot Auth: signed, attributable agent egress (RFC 9421).
- Tool-output schema: govern what a tool returns, not just its inputs.
- Signed human approval: non-repudiable, action-bound sign-off.
- Witness cosigning: non-equivocation for the audit trail.
- Assurance levels L0 to L4: an objective governance grade per agent.
- Execution receipts: prove what actually ran.
- AP2 payment mandates: signed consent chains for money movement.
- Collective defense: a cross-fleet threat network.
- Public verifier + neutral notary: independently verifiable proof.