Security
Designed for production AI from day one.
Security teams cannot adopt a governance tool they cannot trust. Nettriva is designed to be observe-only by default, keep credentials and sensitive content in your environment, record everything it does, and never take disruptive action without explicit approval.
Controls
Security model
The controls below describe how Nettriva is designed to operate. Specific configuration is agreed with each team.
Observe-only by default
Connectors start in observe mode. Discovery, monitoring, risk assessment and investigation never require Nettriva to change agent behavior.
Credential isolation
API keys and service credentials are referenced from your secrets store and used only by components inside your environment. They are never shown to users or to the analysis layer.
Data minimization
Prompts, responses and tool payloads can be redacted, hashed or dropped at the source. Retention is configurable per data type.
RBAC
Roles control who can see which agents and content, edit which policies and approve which actions, aligned with your identity provider.
Approval workflows
Any containment step or enforcement change shows the exact change, affected agents, verification plan and rollback, and requires approval from an authorized person.
Audit logs
Every query run, finding raised, policy decision, approval given and verification result is recorded with actor and time, and can be exported.
Private deployment
The platform can run on-premise or in your private cloud. Sensors connect outbound, so no inbound access to your environment is required.
Encrypted transport
Traffic between sensors, gateways and the platform is encrypted in transit with TLS.
No automatic disruptive actions
Nettriva does not pause agents, revoke access or start blocking on its own. Enforcement is opt-in, scoped to the policies and agents you choose, and every change to it is approved.
Human in the loop
You decide how far automation goes.
Autonomy is configured per environment. Most teams start in observe mode and add alerts, approvals and enforcement as trust grows.
01Observe Only
Default for every connectorRecord agent activity and evaluate policies without changing agent behavior.
02Alert & Recommend
Nettriva generatesNotify owners of violations and propose containment with evidence, blast radius and rollback.
03Approval Required
Person decidesSensitive actions and containment steps wait for a named approver with the right role.
04Enforce Approved Policy
Scoped policyoff by defaultBlock or redact actions that violate an approved policy, scoped to the agents and tools it covers.
05Verify Result
Nettriva verifiesRe-run the evidence checks and confirm the policy behaves as intended without breaking legitimate work.
06Rollback Guidance
Person decidesIf verification fails, present the prepared rollback and its expected effect.
Approval required
ct-118 · INC-2206Revoke MCP-WEB from finance-copilot
Remove the general-purpose web tool from finance-copilot until egress policy EGR-01 covers it. Invoice extraction keeps working through the approved document connector.
[agent finance-copilot · tools] - mcp: MCP-WEB # http.get, http.post + # MCP-WEB removed (ct-118) pending egress review
- Blast radius
- 1 agent · 1 tool server
- Workflows affected
- 1 of 14
- Method
- staged · 15 min monitor
- Rollback
- one-step restore
Verification plan
- No egress to unapproved domains for 15 minutes
- Invoice extraction workflow still succeeds
- No new tool errors for finance-copilot
Requires role: security-lead · 1 of 1 approvals
Audit log · INC-2206
- 10:18:52
investigator · Generated recommendation
Revoke MCP-WEB from finance-copilot
- 10:19:30
secops-oncall · Requested approval
Containment candidate ct-118
- 10:21:12
security-lead · Approved change
ct-118 · staged · 15 min monitor
- 10:21:20
policy-engine (scoped) · Applied tool revocation
finance-copilot · 1 MCP server
- 10:36:41
investigator · Verified result
0 egress to unapproved domains · workflow OK
- 10:37:02
secops-oncall · Resolved incident
INC-2206 · root cause linked
Data flow
Credentials and sensitive content stay inside your boundary.
- 01
Secrets store
Your vault holds API keys and service credentials. Nettriva references them; it does not copy them.
- 02
Sensor
Runs inside your environment next to your agents or gateway, applies redaction and retrieves credentials at run time.
- 03
AI systems
Agents, gateways and tool servers emit traces and events. With enforcement enabled, policy is checked before tool calls proceed.
- 04
Platform
Receives redacted evidence over an outbound, encrypted connection — never the credentials.
FAQ
Questions security teams ask
Does Nettriva have to sit inline with my agents?
No. Discovery, monitoring, risk assessment and investigation work from traces, logs and APIs. Inline components such as an MCP or egress proxy are only needed if you choose to enforce policy at runtime, and can be deployed for selected agents only.
Where do API keys and credentials live?
In your environment — typically your existing secrets manager. Sensors retrieve them at run time; they are not stored in investigation records or exposed to users.
What data leaves my environment?
With an on-premise or private-cloud deployment, nothing needs to. With a managed deployment, collected metadata — and prompt or payload content only if you enable it — is sent over encrypted connections; we agree scope, redaction and retention with you up front.
Is Nettriva certified against a compliance framework?
Nettriva is an early-stage company and has not yet completed third-party certifications. We are glad to walk your security team through our design and answer security questionnaires.
Can we limit what Nettriva can see?
Yes. Collection scope is configured per connector — which agents, which fields, and whether content is captured at all — and every query Nettriva runs appears in the audit log.
Review our security design with our team.
We'll walk your security, platform and AI teams through connectivity, credentials, data handling and approval workflows for your environment.