Nodra
NODRA TRUST CENTER

Security claims should be provable.

Nodra is built to enforce runtime authority, preserve evidence, contain affected agents, and require controlled recovery. This page separates controls we can demonstrate today from assurance we do not yet claim.

VERIFIED CONTROLS

What Nodra can substantiate today

These statements are grounded in current implementation and regression tests, not future roadmap language.

Signed runtime identity

Agent-scoped credentials, exact-body signing, timestamp freshness and replay-resistant nonces.

Verified control

Least-privilege authority

Explicit resource:action permissions are enforced before consequential execution.

Verified control

Workspace isolation

Workspace-scoped application logic and PostgreSQL row-level security are regression-tested.

Verified control

Tamper-evident evidence

Security events are hash-linked and can be checked with the integrity verifier.

Verified control

Selective containment

Incident blast radius can quarantine the origin while preserving unrelated healthy agents.

Verified control

Credential invalidation

Customer-origin credentials are revoked during containment and rotated during recovery.

Verified control

Evidence-gated recovery

Recovery requires remediation evidence and authorized human approval before safe restart.

Verified control

Automated assurance

CI includes SDK, OpenAPI, database, isolation, approval, delegation, containment and authority tests.

Verified control
RUNTIME BOUNDARY

Customer agent → deterministic Nodra control → customer tool

Nodra does not need to replace the customer's model or orchestration framework. The customer places Nodra authorization before the consequential side effect.

Agent runtimesigned request→Nodraidentity · authority · policy→Customer toolexecute only when permitted
NOT YET CLAIMED

No compliance theatre

Nodra should not present the following as completed until independent evidence exists:

  • SOC 2 certification
  • ISO 27001 certification
  • independent penetration-test attestation
  • SAML / SCIM enterprise identity
  • a contractual uptime SLA unless separately agreed
DESIGN PARTNER

Evaluate Nodra with one real agent—not an enterprise-wide migration.

Start with one consequential workflow, prove authorization and evidence, then run a controlled containment and recovery exercise.

Open 5-minute Demo Lab