Skip to contentWitnora
Menu

Your Agent stays yours.

Witnora does not need open-ended access to your source, prompts, credentials, or raw business data. Customer-owned components enforce and observe locally; Nora explains only the minimal verified facts returned to Witnora.

Customer environmentAgent · source · prompts · credentials · raw data

The write boundary and independent result check operate with customer-held authority.

Witnora HostedSigned metadata · decisions · evidence · limitations

Nora cannot turn a recommendation into policy, approval, or execution.

What stays with you

  • Default capability discovery does not require or upload source code
  • Raw prompts, credentials, action arguments, and target responses remain local by default
  • Only signed capability metadata and digests leave the local discovery boundary
  • Source-assisted analysis is off until explicitly authorized

What Witnora can authorize

  • Agent identity remains separate from the write credential
  • A customer decision and short-lived single-use grant bind the exact action
  • The registered customer-owned Gateway is the covered write boundary
  • Nora cannot approve, change policy, or bypass the Gateway

How you can verify it

  • Canonical JSON, SHA-256 manifests, and role-separated signatures
  • A customer-operated read path observes the declared target outcome
  • Offline verification uses a separately pinned trust root
  • Coverage, binding, completeness, and review strength remain distinct

What Witnora can prove

For a declared covered path, Witnora can verify the signed authority chain, exact action binding, Gateway dispatch record, customer-operated observation, packet integrity, and stated evidence strength.

What it cannot prove

Witnora cannot prove control of undeclared or bypass paths, guarantee future Agent behavior, establish organizational independence by itself, or certify a vendor's compliance program.

If the Hosted service is unavailable

The customer-owned boundary does not silently convert missing authority into permission. Unverified or incomplete paths remain explicitly partial.

If access must be removed

Customer-held credentials and local services remain under customer control. Project credentials can be revoked without transferring raw provider credentials to Nora.

Current reference boundary

The design-partner acceptance path uses an isolated sandbox and deterministic target. The optional GitHub integration is read-only preflight only: it cannot dispatch, merge, or produce live-write acceptance evidence.

Responsible disclosure

Found a security issue?

Contact the Witnora founder at ziwei@witnora.com with the affected version and a non-sensitive summary. Ask for a private follow-up channel before sharing sensitive reproduction details. Do not include credentials, customer evidence, private endpoints, or exploit details in a public issue.

Contact privately