Provable AI governance.
Enforced at runtime.
Nyx protects every prompt, file and agent action with a patent-pending on-device anonymization engine, and turns every decision into cryptographic evidence for the EU AI Act, GDPR and NIS2.
EU AI Act high-risk obligations apply from 2 August 2026.
Invisible Armor
A short film on how Nyx becomes invisible armor for your AI, turning every prompt, file and agent action into provable, runtime-enforced protection.
Stop leaks before they leave the device
Intent analysis and mathematical k-anonymity run locally. Sensitive data is generalized by meaning, a city becomes a region, an age becomes a range, so individuals can't be re-identified and the model keeps its context. Prompts never leave the device to be classified.
How the engine worksTurn enforcement into audit-ready evidence
Every decision lands in a hash-chained, tamper-evident ledger. Evidence packs are generated for the EU AI Act, GDPR, NIS2, ISO 27001, SOC 2, HIPAA and PCI-DSS, produced by the runtime, not reconstructed afterwards.
AI Act evidenceMost AI-governance platforms generate paperwork. Nyx generates proof.
k-anonymity, done as mathematics, not masking
Traditional redaction filters operate like black boxes, breaking context. Nyx generalizes by meaning so individuals can't be re-identified and the model keeps its context.
Traditional Black-Box Redaction
- Removes or masks data completely
- Breaks prompt context and utility
- Binary redaction (all or nothing)
- Limited compliance audit trail
Nyx Semantic Generalization
- Generalizes data while preserving semantic meaning
- Maintains AI processing accuracy
- Configurable k-anonymity thresholds
- Tamper-evident, hash-chained forensic ledger
The core engine is patent-pending; the official prior-art search confirmed novelty and inventive step for all claims.
See Nyx in action
Type or paste text containing sensitive data and watch detection happen in real time. In production, Nyx goes further, generalizing identifiers (a city to a region, an age to a range) to satisfy k-anonymity instead of blunt masking, so the AI keeps its context.
The Nyx Security Fabric
The same NYX protection runs at every point AI traffic leaves your organization, desktop, browser, server-side, and the network edge, all governed by one control plane. The same privacy, policy and audit apply wherever the interception happens.
Central Orchestrator
Edge Shield
Sidecar Guardian
Edge Shield
Central Orchestrator
Sidecar Guardian
Core Components
NyxCommand
The central orchestrator. Distributes signed policies to the fleet, manages agents and incidents, and maintains the tamper-evident forensic ledger.
NyxEndpoint
The edge shield. Protects human users, identifying sensitive data by meaning, applying k-anonymity, and analyzing intent on-device before requests reach an external model.
NyxSidecar
The agent guardian. Runs alongside your services to govern autonomous agents, binding every tool call and data access to the agent's approved mission.
NyxBrowser
Browser coverage for managed environments where the desktop agent can't run, protecting AI chat directly inside the browser.
NyxEdge
A network-perimeter appliance that extends the same protection to unmanaged devices and apps, BYOD, IoT and OT, that no agent or browser can reach.
Security Pipeline
Semantic Anonymization
Sensitive data is identified by meaning and generalized so it can't be re-identified, without breaking the AI's context.
Intent & Mission Checks
Intent is analyzed on-device; for autonomous agents, every action is checked against its approved mission.
Allow or Sever
Compliant requests proceed to the model. Violations are blocked and the session is severed.
Forensic Audit
Every decision is recorded in a tamper-evident audit trail, evidence for EU AI Act, GDPR and ISO 27001.
Runs where your data is allowed to live
SaaS, private cloud, on-premise or fully air-gapped, no telemetry leaves your enclave in sovereign deployments.
Built for the sectors the AI Act calls high-risk
Healthcare & life sciences
Patient data is generalized on-device before any prompt reaches a model, see the live demo. Prompts and attached clinical documents are analyzed jointly, so a safe-looking file and a safe-looking prompt can't combine into an identifying leak. Evidence packs cover the EU AI Act, GDPR and HIPAA.
Financial services & insurance
Customer data is k-anonymized while preserving the context models need for assessment. Automated decisions get human-in-the-loop review (GDPR Art. 22), and AI agents acting on accounts are bound to mission policies at the level of every tool call. Evidence packs cover the EU AI Act, GDPR and PCI-DSS.
Public sector
Citizen data never leaves the administration's infrastructure, on-premise and sovereign deployments with customer-hosted NyxCommand. The tamper-evident ledger gives auditors and oversight bodies verifiable records of every automated decision.
Manufacturing, critical infrastructure & defense
Fully air-gapped operation for isolated networks, no telemetry leaves the enclave. Industrial IP, process parameters and supplier data in prompts are protected on-device. A network-edge appliance (NyxEdge) extends the same protection to unmanaged OT/IoT devices.
Different regulators, one mechanism: enforcement that documents itself.
Ship AI governance under your brand.
Nyx is built to be embedded: white-label, OEM and managed-service models for system integrators, cloud providers and software vendors.
Frequently Asked Questions
Technical answers for CTOs and CISOs evaluating enterprise AI governance.
Platform
Privacy & AI Defense
Deployment
Compliance & Audit
Regulation & company
Still have questions? Our engineering team is ready to help.
Nyx is deployed with your team.
There's no self-serve sign-up. We scope every deployment, cloud, on-premise or air-gapped, with you. Book a demo or request the technical whitepaper and we'll respond within one business day.