Security for agent-caused production change
Novyx security starts with controlling what agents can change, preserving evidence, and keeping recovery paths attached to risky actions.
Current posture
Novyx is a bootstrapped product. It should be evaluated as present controls plus a clear roadmap, not as a mature enterprise compliance program. SOC 2 Type II is planned, not complete.
Action evidence
Record the requested effect, parsed migration statements, affected objects, verdict, reviewer decision, and execution result.
Tamper-evident audit
Use hash-linked evidence so request, approval, and execution records are not silently rewritten after an incident.
Least-privilege connectors
Agents should request governed actions through Novyx instead of holding direct production credentials.
Recovery readiness
Capture rollback, compensation, or incident-review notes with the action before the change ships.
Data protection
Encrypt data in transit and at rest, keep API keys hashed, and isolate tenants at the storage boundary.
Honest compliance posture
SOC 2 is planned. Until certification is complete, the site should not imply certification or mature enterprise controls.
The audit question
After an agent touches production, security and engineering need the same answers: what changed, why was it allowed, who approved it, and how do we unwind it?