Probity by NOFire AI

Accelerate agent adoption, safely.

AI agent governance for security. Isolated coding-agent execution for developers.

Explore Probity
Probity Sandboxes · Brig

Launching supported agent CLI...

Preparing isolated agent environment...

Booting lightweight Linux VM

Network: shared

Isolation: one lightweight VM

Starting isolated agent session

Probity Sandboxes

Run supported coding agents inside dedicated microVMs with Brig.

Explore Sandboxes

Probity AI Governance

Independent observation, security findings, signed evidence, and SIEM delivery.

Explore AI governance

Brig

Free, Apache-2.0 microVM sandbox for AI coding agents on Mac and Linux.

Get Brig

Two products. One foundation.

Familiar workflows for developers. Independent evidence for security.

Probity Sandboxes uses Brig to run coding agents inside microVMs. Probity AI Governance observes supported AI-agent workloads outside the agent boundary and delivers the record into the existing SOC.

Sandbox view

Your coding agent. One lightweight VM.

Launching supported agent CLI

Agent environment ready

VM booted

$ brig info claude

Governance record

Your SOC. One signed record.

ObserveBoundary + host activity
DetectRisky action linked to intent
SignEvidence integrity valid
DeliverFinding sent to SIEM

A common systems foundation

The runtime and evidence layer under every agent.

Isolated coding-agent execution for developers. Independent observation and signed evidence for security.

01

One agent session. One VM.

Each supported coding-agent CLI launches inside its own lightweight VM boundary.

$ brig run claude

agent session isolated

isolation lightweight-vm

02

Evidence outside the agent

Boundary and host observations remain independent from agent-authored session context.

Boundary activityObserved
Host activityObserved
Signed recordVerified

03

Nothing to rip and replace

Keep existing OCI images, agent tools, runners, and security workflows.

OCI image
Agent tool
Existing SIEM

04

Open foundations

Apache-2.0 foundations aligned with OCI and cloud-native standards.

License

Apache 2.0

Packaging

OCI

Sandbox CLI

Brig

Model

Open standards

One evidence model

Connect supported workloads. Keep the record independent.

Probity correlates agent intent, tool use, boundary activity, and host observation without treating the agent-authored session as the source of truth.

Supported workload evidence

Independent record
Coding agent sessionBoundary + hostObserved
CI/CD runnerHost activityObserved
Internal automationSigned recordVerified
Customer-facing agentFinding deliverySIEM

Useful autonomy. Clear accountability.

Move faster without losing the record.

Developers

Keep the workflow familiar.

Launch supported coding-agent CLIs while isolation stays part of the execution model.

run · ps · logs · stop · rm

Platform teams

Connect the workloads you already operate.

Add independent observation to supported developer machines, runners, and agent environments without replacing the surrounding stack.

workloads → evidence model

Security teams

Investigate from a signed record.

Receive security findings with integrity status and declared coverage in the existing SOC workflow.

finding → signed evidence → SIEM

Built by open-source systems creators

The team behind production-grade cloud-native isolation.

Probity is powered by NOFire AI and built by the creators of urunc, an Apache-2.0 cloud-native runtime that is now a CNCF Sandbox project.

Open-source lineage

Project
urunc
Purpose
Open cloud-native runtime
Foundation
CNCF Sandbox
License
Apache 2.0

The Probity product family

Isolation for agent sessions. Evidence for security.

Choose the product that fits the boundary you need to secure, or use both as part of the same open systems foundation.

See it in action

Get started with Probity.

Explore the right combination of isolated coding-agent execution and independent AI-agent governance for your team.

  • One lightweight VM for every supported coding-agent session
  • Independent observation outside supported AI-agent boundaries
  • Security findings delivered into your existing SIEM
  • Signed records with integrity status and declared coverage

We will use your details only to respond to this request.