Patent-pending · On-device · Fail-closed

    Provable AI governance.
    Enforced at runtime.

    Nyx protects every prompt, file and agent action with a patent-pending on-device anonymization engine, and turns every decision into cryptographic evidence for the EU AI Act, GDPR and NIS2.

    Mike Ross, 62, New York
    → male patient · 60 to 65 · East-Coast metro area

    EU AI Act high-risk obligations apply from 2 August 2026.

    Evidence packs for
    EU AI Act
    GDPR
    NIS2
    ISO 27001
    SOC 2
    HIPAA
    PCI-DSS
    The Film

    Invisible Armor

    A short film on how Nyx becomes invisible armor for your AI, turning every prompt, file and agent action into provable, runtime-enforced protection.

    Protect

    Stop leaks before they leave the device

    Intent analysis and mathematical k-anonymity run locally. Sensitive data is generalized by meaning, a city becomes a region, an age becomes a range, so individuals can't be re-identified and the model keeps its context. Prompts never leave the device to be classified.

    How the engine works
    Prove

    Turn enforcement into audit-ready evidence

    Every decision lands in a hash-chained, tamper-evident ledger. Evidence packs are generated for the EU AI Act, GDPR, NIS2, ISO 27001, SOC 2, HIPAA and PCI-DSS, produced by the runtime, not reconstructed afterwards.

    AI Act evidence

    Most AI-governance platforms generate paperwork. Nyx generates proof.

    On-Device
    Intent Analysis
    Prompts are analyzed locally, never sent to a third-party classifier
    k-Anonymity
    Mathematical Privacy
    Resists re-identification from combined attributes
    AES-256
    Encrypted at Rest
    Forensic data and originals sealed on disk
    On-Prem
    & Air-Gapped Ready
    Your data never leaves your network
    The engine

    k-anonymity, done as mathematics, not masking

    Traditional redaction filters operate like black boxes, breaking context. Nyx generalizes by meaning so individuals can't be re-identified and the model keeps its context.

    Traditional Black-Box Redaction

    • Removes or masks data completely
    • Breaks prompt context and utility
    • Binary redaction (all or nothing)
    • Limited compliance audit trail

    Nyx Semantic Generalization

    • Generalizes data while preserving semantic meaning
    • Maintains AI processing accuracy
    • Configurable k-anonymity thresholds
    • Tamper-evident, hash-chained forensic ledger
    Evidence packs for
    EU AI ActGDPRNIS2ISO 27001SOC 2HIPAAPCI-DSS

    The core engine is patent-pending; the official prior-art search confirmed novelty and inventive step for all claims.

    Interactive Demo

    See Nyx in action

    Type or paste text containing sensitive data and watch detection happen in real time. In production, Nyx goes further, generalizing identifiers (a city to a region, an age to a range) to satisfy k-anonymity instead of blunt masking, so the AI keeps its context.

    Try examples:
    Raw Input (Unsafe)
    Nyx Output (Sanitized)
    Sanitized output will appear here...
    Enter text to see detection
    PII Redacted:0
    Locations:0
    K-Anon:0
    Blocked:0
    One control plane

    The Nyx Security Fabric

    The same NYX protection runs at every point AI traffic leaves your organization, desktop, browser, server-side, and the network edge, all governed by one control plane. The same privacy, policy and audit apply wherever the interception happens.

    Hard Redaction
    Semantic Transformation
    Mission Binding
    Kill-Switch
    NyxCommand

    Central Orchestrator

    Policy Distribution Network
    Immutable Forensic Ledger
    Encrypted Policy Tunnels
    Human Interface Layer
    Human UserEmployee / Developer
    NyxEndpoint

    Edge Shield

    SSN: 123-45-6789
    [REDACTED]
    Mike Ross, 62yo
    [GENERALIZED]
    Send $50k to...
    BLOCKED
    Privacy-Safe Request
    Autonomous Agent Control
    AI AgentAutonomous System
    NyxSidecar

    Sidecar Guardian

    Delete user records
    HALTED
    Tool: drop_database
    OUT OF SCOPE
    Action in scope
    ✓ APPROVED
    Mission-Bound Action
    Remote LLMGPT-4 / Claude / Gemini
    Zero PII Exposure • Full AI Capability

    Core Components

    NyxCommand

    The central orchestrator. Distributes signed policies to the fleet, manages agents and incidents, and maintains the tamper-evident forensic ledger.

    NyxEndpoint

    The edge shield. Protects human users, identifying sensitive data by meaning, applying k-anonymity, and analyzing intent on-device before requests reach an external model.

    NyxSidecar

    The agent guardian. Runs alongside your services to govern autonomous agents, binding every tool call and data access to the agent's approved mission.

    NyxBrowser

    Browser coverage for managed environments where the desktop agent can't run, protecting AI chat directly inside the browser.

    NyxEdge

    A network-perimeter appliance that extends the same protection to unmanaged devices and apps, BYOD, IoT and OT, that no agent or browser can reach.

    Security Pipeline

    1

    Semantic Anonymization

    Sensitive data is identified by meaning and generalized so it can't be re-identified, without breaking the AI's context.

    2

    Intent & Mission Checks

    Intent is analyzed on-device; for autonomous agents, every action is checked against its approved mission.

    3

    Allow or Sever

    Compliant requests proceed to the model. Violations are blocked and the session is severed.

    4

    Forensic Audit

    Every decision is recorded in a tamper-evident audit trail, evidence for EU AI Act, GDPR and ISO 27001.

    100%
    PII Never Reaches the Model
    On-Device
    Analysis, No Prompt Egress
    AES-256
    Encrypted in Transit & at Rest
    Tamper-Evident
    Forensic Audit Trail
    Deployment

    Runs where your data is allowed to live

    SaaS, private cloud, on-premise or fully air-gapped, no telemetry leaves your enclave in sovereign deployments.

    SaaS
    Cloud-hosted NyxCommand, fastest to deploy.
    Private cloud / on-premise
    Inside your VPC or data center, customer-hosted NyxCommand.
    Air-gapped
    Fully isolated networks; updates via secure offline channels.
    Sovereign
    No telemetry leaves your enclave; data stays in-jurisdiction.
    Who it's for

    Built for the sectors the AI Act calls high-risk

    Healthcare & life sciences

    Clinical AI is high-risk by definition.

    Patient data is generalized on-device before any prompt reaches a model, see the live demo. Prompts and attached clinical documents are analyzed jointly, so a safe-looking file and a safe-looking prompt can't combine into an identifying leak. Evidence packs cover the EU AI Act, GDPR and HIPAA.

    Financial services & insurance

    Credit scoring and risk pricing are named in Annex III.

    Customer data is k-anonymized while preserving the context models need for assessment. Automated decisions get human-in-the-loop review (GDPR Art. 22), and AI agents acting on accounts are bound to mission policies at the level of every tool call. Evidence packs cover the EU AI Act, GDPR and PCI-DSS.

    Public sector

    Citizen-facing AI requires a fundamental-rights impact assessment (Art. 27 FRIA).

    Citizen data never leaves the administration's infrastructure, on-premise and sovereign deployments with customer-hosted NyxCommand. The tamper-evident ledger gives auditors and oversight bodies verifiable records of every automated decision.

    Manufacturing, critical infrastructure & defense

    NIS2 and the AI Act now overlap on the factory floor.

    Fully air-gapped operation for isolated networks, no telemetry leaves the enclave. Industrial IP, process parameters and supplier data in prompts are protected on-device. A network-edge appliance (NyxEdge) extends the same protection to unmanaged OT/IoT devices.

    Different regulators, one mechanism: enforcement that documents itself.

    Patent-pending core
    Prior-art search confirmed novelty and inventive step for all claims.
    Critical-infrastructure DNA
    Engineered by practitioners with a decade of OT and critical-infrastructure security experience (IEC 62443).

    Ship AI governance under your brand.

    Nyx is built to be embedded: white-label, OEM and managed-service models for system integrators, cloud providers and software vendors.

    Explore the partner program
    Common Questions

    Frequently Asked Questions

    Technical answers for CTOs and CISOs evaluating enterprise AI governance.

    Platform

    Privacy & AI Defense

    Deployment

    Compliance & Audit

    Regulation & company

    Still have questions? Our engineering team is ready to help.

    Nyx is deployed with your team.

    There's no self-serve sign-up. We scope every deployment, cloud, on-premise or air-gapped, with you. Book a demo or request the technical whitepaper and we'll respond within one business day.