Governance inside every perimeter
Federal agencies, OT operators, and regulated enterprises run networks that can never open inbound cloud ports. Nuxari Edge Agents extend full governance, continuous evidence collection, approval-gated execution, and immutable audit records, to any environment that can only reach out.
Governance reaches where your tools stopped
Most governance platforms work where there's reliable cloud connectivity. Nuxari Edge Agents work where there isn't.
Governance evidence from environments you couldn't reach before
Classified networks, OT systems, and isolated infrastructure generate the same governance evidence as your cloud environment. The audit chain doesn't stop at your perimeter, it follows the agent.
Zero inbound ports. Your perimeter stays closed.
Agents only make outbound connections. No firewall rule grants the platform access inward. Your air-gapped boundary stays exactly where your security team defined it, and no exception is required.
Approval-gated execution, even when disconnected
No action executes without a signed, approved package from the platform. Disconnection pauses execution, it never creates an unapproved change path. Evidence queues locally and transmits in full when the channel restores.
Where federal and regulated IT teams operate
Air-gapped, classified, OT, and isolated financial networks all share one requirement: governance that never demands an inbound connection.
Classified Defense Networks
DoD and defense contractor environments where inbound cloud connectivity is prohibited by policy. The agent polls outbound on a defined schedule, collects directory and host evidence, queues locally during restricted windows, and transmits signed receipts when a permitted outbound channel opens.
OT / SCADA Environments
Industrial control and operational technology networks where live cloud API calls for every action are operationally unacceptable. Governance covers operator accounts and privileged access rights without touching the OT segment directly or requiring any connectivity change.
Regulated Healthcare Networks
PHI-adjacent isolated systems where streaming data to external services creates compliance exposure. The agent processes all host data locally, only structured evidence summaries leave the environment. Raw file contents and log data never cross the boundary.
Financial Isolation Zones
Trading floors and core banking networks with strict controls on external API exposure. Access governance and approval-gated execution operate entirely inside the isolated zone, evidence exits only through the existing outbound channel.
Note: Whether a specific classified or accredited environment permits Edge Agent deployment depends on that environment's security controls and authorization process. Nuxari does not claim formal FedRAMP authorization. Contact the team for a technical architecture review.
Outbound only. No exceptions.
The agent connects to the Nuxari platform. The platform never connects to the agent. No inbound port. No firewall exception. No exposure surface added to your network.
- ·All agent-to-platform traffic is outbound, initiated by the agent
- ·Action packages are cryptographically signed before delivery to the agent
- ·TLS 1.3 on all connections, evidence is encrypted in transit
- ·Heartbeat monitoring detects agent failures before evidence gaps form
Local processing. Structured output. Nothing raw in transit.
The agent processes host data locally. Only structured evidence summaries leave the environment, raw logs, file contents, and sensitive host data never cross the perimeter.
- ·Raw data processed on-host, structured summaries transmitted only
- ·Evidence queued locally during disconnection, transmitted in full on reconnect
- ·Feeds directly into Linux Posture Pack and custom control evaluations
- ·Collection events are themselves part of the immutable audit chain
Agents only run what has been approved
There is no ad-hoc agent execution. Every action an agent performs arrives as a signed, approved action package from the platform. The agent verifies the signature before executing, in any environment, including air-gapped ones.
- ·Action packages are created by the platform only after approval completes
- ·Packages are cryptographically signed, agents reject unsigned or tampered packages
- ·Every execution produces a signed receipt transmitted back to the platform
- ·Receipt is included in the workflow evidence chain regardless of when it arrives
{
"receiptId":"rcpt_01jxb3c4d5e6",
"agentId":"agent_airgap_dc01",
"agentHost":"dc01.classified.internal",
"actionPackageId":"pkg_01jxa2b3c4",
"action":"remove_sudoers_entry",
"target":"user:contractor_id",
"status":"success",
"executedAt":"2026-06-07T09:04:12Z",
"queuedDuration":"PT4H18M",
"workflowRunId":"wfr_01jxa2k9",
"platformVerified": true,
"signature":"ed25519:7f4a9b...",
"hash":"sha256:c9d2e1f3a4b5..."
}What your security team gains
Governance that reaches inside the perimeter instead of stopping at it.
No firewall rule opens a path into your environment. The perimeter stays exactly as your security team designed it.
Every action an agent executes traces back to a signed, human-authorized approval record in the platform.
Evidence queues locally during network partitions and transmits in full when the channel restores. No gaps in the governance record.
Classified, OT, regulated healthcare, on-premises, or hybrid, the governance model is identical regardless of connectivity.
Visibility across every deployed agent
The platform tracks every agent's health, evidence queue depth, last successful transmission, and connectivity status, including agents in air-gapped and offline environments.
- ·Heartbeat monitoring with configurable alert thresholds per environment
- ·Evidence queue depth visible per agent, never lose track of what's pending
- ·Connectivity gap events recorded in the audit chain automatically
- ·Token rotation status and expiry visible to administrators at all times
Common questions
What operating systems does the Edge Agent support?
The current agent supports Linux (Ubuntu, RHEL, Debian) and connects to Windows Active Directory via LDAP queries. Windows host agent support is on the roadmap. Edge Agents do not require a GUI environment.
Can agents work in air-gapped environments?
Yes. Agents operate autonomously at the edge and queue evidence locally when connectivity to the platform is unavailable. Evidence is transmitted in bulk when connectivity is restored. No evidence is discarded due to temporary disconnection.
What happens if an agent loses connectivity?
Missed heartbeats trigger an alert in the platform. The agent continues collecting evidence locally. A connectivity gap event is recorded so the evidence chain shows exactly when the agent was unreachable, the gap itself becomes part of the audit record.
How are agent tokens managed?
Agents authenticate using scoped, time-limited tokens with a configurable TTL (default: 24 hours). Tokens are stored hashed, the plaintext is never persisted on the agent host or in the platform database. Rotation is automated.
Can an agent take actions without platform approval?
No. Agents only execute action packages that have been approved through the Nuxari workflow engine and cryptographically signed. There is no mechanism for ad-hoc or unapproved agent execution. Unsigned or tampered packages are rejected.
What data does the agent transmit to the platform?
Agents transmit evidence records (structured summaries of collected data) and execution receipts. Raw host data is processed locally, the agent does not stream raw logs or sensitive file contents to the cloud.
Is this suitable for classified or ITAR-controlled environments?
Nuxari Edge Agents are designed for environments with strict outbound-only network policies and require no inbound ports. Data is processed locally before structured summaries are transmitted. Whether a specific classified environment permits Edge Agent deployment depends on that environment's security controls and accreditation process. Contact the team for a technical architecture review.
The full governance stack
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.