Skip to content

Security for agent-caused production change

Novyx security starts with controlling what agents can change, preserving evidence, and keeping recovery paths attached to risky actions.

Current posture

Novyx is a bootstrapped product. It should be evaluated as present controls plus a clear roadmap, not as a mature enterprise compliance program. SOC 2 Type II is planned, not complete.

Action evidence

Record the requested effect, parsed migration statements, affected objects, verdict, reviewer decision, and execution result.

Tamper-evident audit

Use hash-linked evidence so request, approval, and execution records are not silently rewritten after an incident.

Least-privilege connectors

Agents should request governed actions through Novyx instead of holding direct production credentials.

Recovery readiness

Capture rollback, compensation, or incident-review notes with the action before the change ships.

Data protection

Encrypt data in transit and at rest, keep API keys hashed, and isolate tenants at the storage boundary.

Honest compliance posture

SOC 2 is planned. Until certification is complete, the site should not imply certification or mature enterprise controls.

The audit question

After an agent touches production, security and engineering need the same answers: what changed, why was it allowed, who approved it, and how do we unwind it?

Exact agent request
Blast-radius facts
Approval or block decision
Execution result
Recovery path
Exportable evidence