Enterprise

Security that scales with you.

Agents that touch your tools need the same trust as a teammate. Nova treats every run as a reviewable decision — scoped, logged, and gated.

Talk to sales

Custom redlines, residency, and scale. We will map your stack and send a rollout plan within 24 hours.

Trust points.

Six commitments, concrete. No vague “enterprise-grade” claims — these are the mechanisms auditors actually check.

Runs where you do

Store data in Firestore, Cloudflare D1, or Postgres. Keep files in S3, R2, GCS, or Azure Blob. Deploy to Cloudflare, GCP, AWS, or your own hardware.

Per-user memory scoping

Agent memory is scoped per user by default. What one user teaches an agent never leaks to another. Memory is editable and erasable.

Audit trails + trace replay

Every message, tool call, and decision is logged. Replay any run, export any trace, and prove what happened when auditors ask.

Role + per-entity auth

Workspace roles plus per-entity checks. An agent can only do what its owner can do — down to individual records and channels.

Approvals where it matters

Approval gates pause before high-stakes actions: sending, spending, publishing. Your team approves; Nova executes.

Private by design

We do not train on your data. Workspaces never share memory or traces. Bring your own model keys when you need to.

What you get on day one

  • Dedicated workspace, isolated datastore
  • Per-user agent memory with edit + erase controls
  • Full trace export (JSONL) + in-app replay
  • Role + entity auth that mirrors your app

Questions procurement actually asks.

What is your compliance posture?

Nova inherits the platform controls of the cloud you run it on. Today you get audit-ready trace exports, scoped memory, and role-aware logs. Ask sales where formal certification stands before you plan around it.

Where does data reside?

You pick the datastore and the region. Firestore, Cloudflare D1, and Postgres are all supported, and traces and artifacts follow the same residency. Tell sales your requirement and we will confirm what we can commit to.

How do you handle SSO and provisioning?

SSO and directory provisioning are on the Enterprise roadmap. Roles map from your IdP; agents inherit only what their owner can access. Ask sales about timing for your provider.

Can we self-host or bring our own cloud?

Yes. Nova ships Terraform for AWS and GCP, Bicep for Azure, and a Compose file for your own hardware. We have deployed and served traffic on Cloudflare, GCP, AWS, and a self-hosted stack of Postgres, Redis, and S3-compatible storage. The Azure manifests deploy but are not yet smoke-tested end to end.

Need paperwork before you can pilot? Talk to sales.