Skip to content
Nettriva

Platform

From raw agent activity to governed, verifiable decisions.

Nettriva is designed as a layered system: sensors collect from your existing AI stack, a live agent graph gives that activity context, and analysis and policy turn it into explained findings, enforced rules and a complete audit trail.

Architecture

Eight layers, one direction of travel.

Activity flows upward from your agents into context, analysis and policy. Control flows back down only through approvals.

  • Sensors deploy next to your agents and connect outbound
  • Original traces are preserved alongside the normalized model
  • The agent graph is maintained continuously, not per incident
  • Enforcement and containment are gated by approval and verified

This is a conceptual view of the platform. Specific deployment topologies are agreed with each team based on their environment and security requirements.

  1. Your AI Environment

    L1

    The agents, models, tools and data you already run. Nothing is rebuilt or replaced.

    • Agents & copilots
    • Agent frameworks
    • Model providers
    • Model gateways
    • MCP servers
    • Tools & APIs
    • Data stores
    • Identity provider
  2. Nettriva Connectors / Sensors

    L2

    Lightweight components deployed next to your agents and gateways, with redaction applied before anything leaves.

    • SDKs
    • OpenTelemetry
    • Gateway integration
    • MCP proxy
    • Egress proxy
    • Audit log ingest
    • IdP sync (SCIM)
    • SaaS & cloud APIs
  3. Activity + Identity + Permissions + Data

    L3

    Normalized into a common model while keeping the original traces and events as evidence.

    Agent activity

    • Model calls
    • Tool calls · arguments
    • Prompts (redactable)

    Identity

    • Agent identities
    • Owners · teams
    • On-behalf-of users

    Permissions

    • Granted tools
    • OAuth / API scopes
    • Change history

    Data context

    • Classifications
    • Sensitivity labels
    • Destinations
  4. Agent Inventory & Graph

    L4

    A live model of which agents exist, who owns them and what they can reach — built before anything goes wrong.

    • Agents
    • Owners
    • Models & gateways
    • MCP servers & tools
    • Data resources
    • External destinations
  5. Risk Assessment & Investigation

    L5

    Scores agents by reach and behavior, and investigates incidents by testing explanations against the evidence.

    • Permission analysis
    • Behavioral baselines
    • Prompt-injection signals
    • Data-flow analysis
    • Change correlation
  6. Policy Enforcement

    L6

    Policies evaluated per action — allow, redact, require approval or block — in monitor or enforce mode.

  7. Approvals & Response

    L7

    Proposed containment with blast radius, a verification plan and a rollback — gated by approval.

  8. Audit Trail

    L8

    Every agent action, policy decision, approval and change recorded with actor and time, and exportable.

Connectivity

Designed to use the interfaces your AI stack already exposes.

Nettriva prefers lightweight instrumentation and existing gateways, and adds proxies only where you want runtime enforcement — so agents do not need to be rebuilt.

Connectivity methods and the data collected through them
InterfaceUsed forTypical data
SDKsInstrument agents built in-house, in the languages your teams useModel calls, tool calls, identity context
OpenTelemetryIngest GenAI traces and spans from instrumented applicationsSpans, model and tool calls, latency, errors
Model gatewaysIntegrate with the gateways and proxies that route model trafficPrompts and responses (redactable), models, tokens
MCP proxyObserve — and optionally enforce policy on — Model Context Protocol tool callsTool names, arguments, results, server identity
Egress proxySee and control where agent tools send dataDestinations, volume, classification
Identity providersMap agents and users to identities, groups and owners via OIDC and SCIMUsers, groups, service accounts, entitlements
SaaS & cloud audit logsCorrelate agent actions with the systems they touchAPI calls, data access, admin events
SIEM & ticketingSend findings, decisions and approvals to existing toolsFindings, audit events, remediation tasks

What Nettriva is designed to analyze

  • Agent inventory
  • Agent owners
  • System prompts
  • Prompts & responses (redactable)
  • Model calls
  • Tool calls
  • Tool arguments & results
  • MCP server manifests
  • OAuth & API scopes
  • Service accounts
  • Delegated user identity
  • Retrieved documents
  • Data classifications
  • Outbound destinations
  • Policy decisions
  • Approvals
  • Permission changes
  • Deployment changes
  • Errors & refusals
  • Token usage
  • Secrets in content

Design principles

Built to be trusted next to production AI.

Observe before anything else

Connectors are observe-only by default. Discovery, monitoring and investigation never require Nettriva to change agent behavior.

Evidence over assertions

Every finding links to the trace, tool call, permission or event that supports it. Nothing is a black box.

Context before analysis

The agent graph exists before an incident starts, so assessments follow real permissions and real data flows.

Model- and framework-neutral

Activity from different providers and frameworks is normalized into common concepts while the original traces are kept as evidence.

Runs where your agents are

Sensors sit inside your environment and connect outbound. The platform can be deployed privately.

People approve change

Recommendations are proposals. Containment and enforcement changes require an authorized person and are verified afterwards.

Deployment

Deploy where your security model needs it.

Nettriva is designed for environments where prompts and data cannot leave the building, as well as teams that prefer a managed service.

On-premise

The full platform and sensors inside your own facilities.

  • Runs entirely in your data center
  • Air-gap friendly design
  • Your identity provider and vault

Private cloud

Deployed into infrastructure you control in your cloud provider.

  • Your cloud account and VPC
  • Private connectivity to sensors
  • Your keys and retention policy

Managed

Nettriva operates the platform; sensors and credentials stay with you.

  • Sensors stay in your environment
  • Outbound-only connectivity
  • Redaction before data leaves

Adopt AI agents without losing control.

See Nettriva investigate a simulated agent incident end to end, and talk with the team building it about your AI environment.