Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Edge Agents

Governance inside every perimeter

Federal agencies, OT operators, and regulated enterprises run networks that can never open inbound cloud ports. Nuxari Edge Agents extend full governance, continuous evidence collection, approval-gated execution, and immutable audit records, to any environment that can only reach out.

Linux Posture Pack
What you gain

Governance reaches where your tools stopped

Most governance platforms work where there's reliable cloud connectivity. Nuxari Edge Agents work where there isn't.

Governance evidence from environments you couldn't reach before

Classified networks, OT systems, and isolated infrastructure generate the same governance evidence as your cloud environment. The audit chain doesn't stop at your perimeter, it follows the agent.

Zero inbound ports. Your perimeter stays closed.

Agents only make outbound connections. No firewall rule grants the platform access inward. Your air-gapped boundary stays exactly where your security team defined it, and no exception is required.

Approval-gated execution, even when disconnected

No action executes without a signed, approved package from the platform. Disconnection pauses execution, it never creates an unapproved change path. Evidence queues locally and transmits in full when the channel restores.

Designed for restricted environments

Where federal and regulated IT teams operate

Air-gapped, classified, OT, and isolated financial networks all share one requirement: governance that never demands an inbound connection.

Classified Defense Networks

DoD and defense contractor environments where inbound cloud connectivity is prohibited by policy. The agent polls outbound on a defined schedule, collects directory and host evidence, queues locally during restricted windows, and transmits signed receipts when a permitted outbound channel opens.

Air-gappedAD / LDAPOutbound-only

OT / SCADA Environments

Industrial control and operational technology networks where live cloud API calls for every action are operationally unacceptable. Governance covers operator accounts and privileged access rights without touching the OT segment directly or requiring any connectivity change.

Isolated segmentOperator accountsNo OT impact

Regulated Healthcare Networks

PHI-adjacent isolated systems where streaming data to external services creates compliance exposure. The agent processes all host data locally, only structured evidence summaries leave the environment. Raw file contents and log data never cross the boundary.

PHI-adjacentLocal processingStructured evidence only

Financial Isolation Zones

Trading floors and core banking networks with strict controls on external API exposure. Access governance and approval-gated execution operate entirely inside the isolated zone, evidence exits only through the existing outbound channel.

DMZ-compatibleOutbound onlyApproval-gated

Note: Whether a specific classified or accredited environment permits Edge Agent deployment depends on that environment's security controls and authorization process. Nuxari does not claim formal FedRAMP authorization. Contact the team for a technical architecture review.

Architecture

Outbound only. No exceptions.

The agent connects to the Nuxari platform. The platform never connects to the agent. No inbound port. No firewall exception. No exposure surface added to your network.

  • ·All agent-to-platform traffic is outbound, initiated by the agent
  • ·Action packages are cryptographically signed before delivery to the agent
  • ·TLS 1.3 on all connections, evidence is encrypted in transit
  • ·Heartbeat monitoring detects agent failures before evidence gaps form
Nuxari Platform (Cloud)
Workflow EngineApproval OrchestrationEvidence StoreAgent Manager
Outbound only · TLS 1.3 · Signed payloads · Token auth
↑ Agent initiates · Platform never connects inbound
Online
edge-agent-dc01
Domain Controller
Online
edge-agent-airgap
Air-gapped Zone
Online
edge-agent-ot-01
OT Network
Host Evidence Collectionedge-agent-airgap-01 · air-gapped zone
Linux syslog
/var/log/syslog
Security events
Linux audit.log
/var/log/audit/audit.log
Syscall audit
sudoers config
/etc/sudoers.d/*
Privilege policy
SSH config
/etc/ssh/sshd_config
Remote access policy
Local user accounts
/etc/passwd
Identity inventory
Active Directory
LDAP query
On-prem identity
Connectivity: offline · 4 records queued locally · will transmit on next window
Evidence collection

Local processing. Structured output. Nothing raw in transit.

The agent processes host data locally. Only structured evidence summaries leave the environment, raw logs, file contents, and sensitive host data never cross the perimeter.

  • ·Raw data processed on-host, structured summaries transmitted only
  • ·Evidence queued locally during disconnection, transmitted in full on reconnect
  • ·Feeds directly into Linux Posture Pack and custom control evaluations
  • ·Collection events are themselves part of the immutable audit chain
Execution model

Agents only run what has been approved

There is no ad-hoc agent execution. Every action an agent performs arrives as a signed, approved action package from the platform. The agent verifies the signature before executing, in any environment, including air-gapped ones.

  • ·Action packages are created by the platform only after approval completes
  • ·Packages are cryptographically signed, agents reject unsigned or tampered packages
  • ·Every execution produces a signed receipt transmitted back to the platform
  • ·Receipt is included in the workflow evidence chain regardless of when it arrives
execution_receipt.json
{
"receiptId":"rcpt_01jxb3c4d5e6",
"agentId":"agent_airgap_dc01",
"agentHost":"dc01.classified.internal",
"actionPackageId":"pkg_01jxa2b3c4",
"action":"remove_sudoers_entry",
"target":"user:contractor_id",
"status":"success",
"executedAt":"2026-06-07T09:04:12Z",
"queuedDuration":"PT4H18M",
"workflowRunId":"wfr_01jxa2k9",
"platformVerified": true,
"signature":"ed25519:7f4a9b...",
"hash":"sha256:c9d2e1f3a4b5..."
}
Outcomes

What your security team gains

Governance that reaches inside the perimeter instead of stopping at it.

0
inbound ports required

No firewall rule opens a path into your environment. The perimeter stays exactly as your security team designed it.

100%
of changes approval-gated

Every action an agent executes traces back to a signed, human-authorized approval record in the platform.

Full
audit chain continuity

Evidence queues locally during network partitions and transmits in full when the channel restores. No gaps in the governance record.

Any
environment supported

Classified, OT, regulated healthcare, on-premises, or hybrid, the governance model is identical regardless of connectivity.

Agent monitoring

Visibility across every deployed agent

The platform tracks every agent's health, evidence queue depth, last successful transmission, and connectivity status, including agents in air-gapped and offline environments.

  • ·Heartbeat monitoring with configurable alert thresholds per environment
  • ·Evidence queue depth visible per agent, never lose track of what's pending
  • ·Connectivity gap events recorded in the audit chain automatically
  • ·Token rotation status and expiry visible to administrators at all times
Agent Fleet4 of 5 online
edge-agent-dc01
Domain Controller · Classified Zone A
Last: 42s ago
0 pending
edge-agent-airgap-01
Linux Host · Air-gapped OT Network
Last: 8m ago
4 queued
edge-agent-dmz-web
Linux Host · DMZ Web Tier
Last: 1m ago
0 pending
edge-agent-fin-01
Domain Controller · Financial Isolation Zone
Last: 3h ago
12 queued
edge-agent-health-01
Linux Host · Regulated Healthcare Network
Last: 22s ago
0 pending
1 agent offline · 16 evidence records queued across fleet · alerts active
FAQ

Common questions

What operating systems does the Edge Agent support?

The current agent supports Linux (Ubuntu, RHEL, Debian) and connects to Windows Active Directory via LDAP queries. Windows host agent support is on the roadmap. Edge Agents do not require a GUI environment.

Can agents work in air-gapped environments?

Yes. Agents operate autonomously at the edge and queue evidence locally when connectivity to the platform is unavailable. Evidence is transmitted in bulk when connectivity is restored. No evidence is discarded due to temporary disconnection.

What happens if an agent loses connectivity?

Missed heartbeats trigger an alert in the platform. The agent continues collecting evidence locally. A connectivity gap event is recorded so the evidence chain shows exactly when the agent was unreachable, the gap itself becomes part of the audit record.

How are agent tokens managed?

Agents authenticate using scoped, time-limited tokens with a configurable TTL (default: 24 hours). Tokens are stored hashed, the plaintext is never persisted on the agent host or in the platform database. Rotation is automated.

Can an agent take actions without platform approval?

No. Agents only execute action packages that have been approved through the Nuxari workflow engine and cryptographically signed. There is no mechanism for ad-hoc or unapproved agent execution. Unsigned or tampered packages are rejected.

What data does the agent transmit to the platform?

Agents transmit evidence records (structured summaries of collected data) and execution receipts. Raw host data is processed locally, the agent does not stream raw logs or sensitive file contents to the cloud.

Is this suitable for classified or ITAR-controlled environments?

Nuxari Edge Agents are designed for environments with strict outbound-only network policies and require no inbound ports. Data is processed locally before structured summaries are transmitted. Whether a specific classified environment permits Edge Agent deployment depends on that environment's security controls and accreditation process. Contact the team for a technical architecture review.

Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.