Platform
From raw agent activity to governed, verifiable decisions.
Nettriva is designed as a layered system: sensors collect from your existing AI stack, a live agent graph gives that activity context, and analysis and policy turn it into explained findings, enforced rules and a complete audit trail.
Architecture
Eight layers, one direction of travel.
Activity flows upward from your agents into context, analysis and policy. Control flows back down only through approvals.
- Sensors deploy next to your agents and connect outbound
- Original traces are preserved alongside the normalized model
- The agent graph is maintained continuously, not per incident
- Enforcement and containment are gated by approval and verified
This is a conceptual view of the platform. Specific deployment topologies are agreed with each team based on their environment and security requirements.
Your AI Environment
L1The agents, models, tools and data you already run. Nothing is rebuilt or replaced.
- Agents & copilots
- Agent frameworks
- Model providers
- Model gateways
- MCP servers
- Tools & APIs
- Data stores
- Identity provider
Nettriva Connectors / Sensors
L2Lightweight components deployed next to your agents and gateways, with redaction applied before anything leaves.
- SDKs
- OpenTelemetry
- Gateway integration
- MCP proxy
- Egress proxy
- Audit log ingest
- IdP sync (SCIM)
- SaaS & cloud APIs
Activity + Identity + Permissions + Data
L3Normalized into a common model while keeping the original traces and events as evidence.
Agent activity
- Model calls
- Tool calls · arguments
- Prompts (redactable)
Identity
- Agent identities
- Owners · teams
- On-behalf-of users
Permissions
- Granted tools
- OAuth / API scopes
- Change history
Data context
- Classifications
- Sensitivity labels
- Destinations
Agent Inventory & Graph
L4A live model of which agents exist, who owns them and what they can reach — built before anything goes wrong.
- Agents
- Owners
- Models & gateways
- MCP servers & tools
- Data resources
- External destinations
Risk Assessment & Investigation
L5Scores agents by reach and behavior, and investigates incidents by testing explanations against the evidence.
- Permission analysis
- Behavioral baselines
- Prompt-injection signals
- Data-flow analysis
- Change correlation
Policy Enforcement
L6Policies evaluated per action — allow, redact, require approval or block — in monitor or enforce mode.
Approvals & Response
L7Proposed containment with blast radius, a verification plan and a rollback — gated by approval.
Audit Trail
L8Every agent action, policy decision, approval and change recorded with actor and time, and exportable.
Connectivity
Designed to use the interfaces your AI stack already exposes.
Nettriva prefers lightweight instrumentation and existing gateways, and adds proxies only where you want runtime enforcement — so agents do not need to be rebuilt.
What Nettriva is designed to analyze
- Agent inventory
- Agent owners
- System prompts
- Prompts & responses (redactable)
- Model calls
- Tool calls
- Tool arguments & results
- MCP server manifests
- OAuth & API scopes
- Service accounts
- Delegated user identity
- Retrieved documents
- Data classifications
- Outbound destinations
- Policy decisions
- Approvals
- Permission changes
- Deployment changes
- Errors & refusals
- Token usage
- Secrets in content
Design principles
Built to be trusted next to production AI.
Observe before anything else
Connectors are observe-only by default. Discovery, monitoring and investigation never require Nettriva to change agent behavior.
Evidence over assertions
Every finding links to the trace, tool call, permission or event that supports it. Nothing is a black box.
Context before analysis
The agent graph exists before an incident starts, so assessments follow real permissions and real data flows.
Model- and framework-neutral
Activity from different providers and frameworks is normalized into common concepts while the original traces are kept as evidence.
Runs where your agents are
Sensors sit inside your environment and connect outbound. The platform can be deployed privately.
People approve change
Recommendations are proposals. Containment and enforcement changes require an authorized person and are verified afterwards.
Deployment
Deploy where your security model needs it.
Nettriva is designed for environments where prompts and data cannot leave the building, as well as teams that prefer a managed service.
On-premise
The full platform and sensors inside your own facilities.
- Runs entirely in your data center
- Air-gap friendly design
- Your identity provider and vault
Private cloud
Deployed into infrastructure you control in your cloud provider.
- Your cloud account and VPC
- Private connectivity to sensors
- Your keys and retention policy
Managed
Nettriva operates the platform; sensors and credentials stay with you.
- Sensors stay in your environment
- Outbound-only connectivity
- Redaction before data leaves
Adopt AI agents without losing control.
See Nettriva investigate a simulated agent incident end to end, and talk with the team building it about your AI environment.