Security

Built for security teams before developers.

Most AI tools are designed to delight developers, then argued past security. NeueCode is built the other way around: an architecture your security team can diagram and verify — that developers then get to enjoy.

In hybrid and open modes, you decide what crosses the boundary — and every crossing is recorded and signed.

No required vendor cloud

The agent, models, memory, and audit all run on your servers. No core path depends on an external service.

Deny-by-default egress broker

Every outbound call the agent makes passes a broker that blocks anything not explicitly allowed and signs a per-run manifest. In strict mode the agent's own network paths become structurally unreachable — an app-level control over its code paths. A packet-level guarantee comes from the OS tier (off by default); until then, residency rests on this broker plus on-prem isolation.

OS-tier egress self-test

Beyond the app layer, NeueCode measures the live host firewall (nftables) out-of-band and runs an enforcement self-test — a canary connect that must be refused — so "configured" becomes "enforcement observed" only when a packet is actually blocked. The strongest tier places the agent in a loopback-only network namespace with no route out. Needs host sudo to arm; off by default.

Human approval where it matters

Plan mode shows the steps before work starts, code changes ship as reviewable diffs, and risky commands wait for human sign-off.

Autonomous goal mode — bounded, off by default

Beyond request/response, the agent can pursue high-level goals unattended on a bounded, risky-tool-denied loop under hard step, token, and wall-clock budgets. Shipped off by default, so autonomy is a deliberate switch, never a surprise.

Identity & least privilege

On the web workbench, SSO uses SAML 2.0 to on-prem IdPs (ADFS, Keycloak, Active Directory); cloud SaaS IdPs are refused in strict mode. The desktop and VS Code clients sign in locally and over Active Directory / LDAP. Directory passwords are never stored. Each privileged action carries a per-invocation, RSA-PSS-signed capability token the developer's client verifies offline with only the box public key — with least-privilege checks on every tool call and fail-closed policy.

Deny-by-default capability registry

Anything with real blast radius ships OFF, and a fresh install is locked with zero configuration behind a fail-closed policy floor. Admins grant capabilities deliberately — org-wide, per role, and per principal, for human users and machine API clients alike — class by class from the Feature Governance console, with no config-file editing and no accidental "on."

Governed superuser

The admin's own actions are logged in the same tamper-evident trail, and anti-lockout, least-privilege invariants hold even against a rogue admin.

Break-glass dual control

The most dangerous actions can require a second admin's approval — a two-person rule enforced by the appliance, not by policy alone. A single-admin deployment can self-approve, but that is recorded distinctly in the tamper-evident ledger and raises an alert, so nothing high-risk happens quietly.

Prompt-injection defenses

Defense against instructions injected through external content, poisoning-resistant memory, and a deterministic verifier that checks claims against what tools actually returned.

Secrets stay secret

Secret scanning to keep credentials from leaking, plus an admin-managed settings vault: keys entered once, write-only, and masked.

Governed external access over MCP

External agents (Claude Code, Codex, Cursor) can drive the sovereign agent over MCP behind an admin-issued connection key — stored as a SHA-256 hash and revocable at any time. A governed on-prem endpoint with no adapter code.

AI Governance Gateway

Put NeueCode in front of third-party coding agents — Copilot, Cursor, Claude Code — as their model endpoint. Every outbound prompt is scanned, classified, and policy-checked (allow, redact, or block) and signed into the audit trail before any upstream call leaves. The tools your developers already use inherit your egress policy and your record.

Governed peer mesh

NeueCode instances can register, trust, and test one another over MCP — so teams and sites collaborate through a governed channel rather than a shared cloud. Strict mode blocks peer egress exactly like any other outbound path.

Tamper-evident audit trail

Every step, tool call, and approval lands in the Agent Flight Recorder — a hash-chained, signed trail that records actions and byte-sizes only, never file contents, prompts, or reasoning. Any later edit breaks the chain, and the auditor runs the offline verifier themselves.

Air-gapped deployment

A repeatable install that doesn't phone home, offline license validation, and internet-reaching apps auto-locked in strict mode.

Proof, not assurances

In strict mode, every run emits signed, integrity-tiered manifests you can verify offline — app-level proof that the agent's own code paths sent nothing out. A no-packet-left guarantee comes from the OS tier (off by default); until then the evidence is scoped to the broker plus on-prem isolation, and the manifest says exactly that.

Compliance portal & auditor pass

A read-only auditor pass lets a reviewer inspect the evidence without operator access, backed by a hardware-bound sovereignty certificate and a signed, integrity-tiered evidence-export endpoint. Evidence is mapped to control frameworks — we hand you proof to make your case, not a certification we don't hold.

Built for regulated environments. Auditable like it.

“Verify it yourself” beats “trust our badge.”

Blocks outbound traffic by default

A deny-by-default egress broker stops anything not explicitly allowed — in strict mode, cloud egress is locked off entirely.

Signs a manifest of every run

Each session emits a signed record of what was reachable and what left — if anything left at all.

Records every action in a tamper-evident chain

The Flight Recorder hash-chains every step, tool call, and approval — any later edit breaks the chain.

Verifiable by your auditors — offline

Verifier tools the auditor runs themselves; neither we nor your operators sit in the trust path.

Compliance evidence export mapped to EU AI Act Articles 12 & 14, DORA, NIS2, SOC 2 CC6 controls, ISO 42001, and SAMA/NCA.

NeueCode is not certified against these frameworks — we give you the evidence to make your case.

Documents for your review

Sent to your work email on request.

Security Architecture Brief

Data flow, trust boundaries, and the governance model — for your security team's review.

Request it

Air-Gapped Deployment Checklist

What it takes to install and operate the platform with no internet path at all.

Request it

Audit Evidence Sample

A sample of the Flight Recorder log and signed manifests as an auditor sees them.

Request it

Put your security team in front of our architecture.

A direct technical session with the team that built the platform — bring your hardest questions.

Talk to our security team