Skip to main content
New in 0.3: guardrails, routers, MCP agents, multimodal, connectors, training

Private AI
that shows its work.

Build assistants, agents and workflows on your own models. Every answer cites its sources, every consequential action waits for a different person to approve it, and every step lands in an audit chain you can verify offline.

$python3 -m nuvora.server --demono GPU · no pip install · no hosted model
nuvora.example.com
Nuvora playground with an answer and the evidence passages behind it
3 sources citedevery passage with a content digest
Approval requiredauthor is never approver
Audit chain verifiedhash-chained, exportable

How it works

From a question to an approved, recorded action.

01

Ground

Hybrid retrieval finds the passages behind the answer, filtered by who may see them.

02

Act

Agents and workflows call your APIs and MCP tools within a bounded budget.

03

Approve

Anything that writes, sends or spends pauses until a second person signs off.

04

Prove

Runs, guardrail decisions and approvals land in a hash-chained audit log.

Capabilities

Everything an AI platform needs.
Nothing that leaves your network.

Your models, your endpoints

Connect any model you run, on an exact host allow-list. Cascade routers start small and escalate when a judge flags a weak answer, with cached tokens priced in.

vLLMOllamaOpenAI-compatibleAWSCascade routingPrompt caching

Author is never approver

Consequential steps wait for a different person, who sees the exact action and its fingerprint.

Guardrails as policy

Word and regex filters, PII with checksum validation, contextual grounding and an optional classifier model.

Knowledge with access rules

Web, S3 and Confluence connectors sync incrementally. Group rules from SSO decide who retrieves what.

Agents with real tools

Import OpenAPI actions, attach MCP servers, keep long-term memory, and trace every step in a waterfall.

OpenAPIMCPMemoryOTLP

Documents, images, audio

OCR, transcription and vision in chat. Extraction blueprints turn documents into fields, with low-confidence review.

Evaluate and experiment

Grounded and LLM-judge evaluations, plus prompt experiments that compare variants on the same suite.

Fine-tune and distill

Validated datasets go to your own trainer for LoRA, QLoRA or distillation, and the result registers as a model.

Image generation

An images API and playground mode, with budgets, guardrails and expiring artifacts.

Evidence and cost

A usage ledger with budgets per workspace beside an audit chain you can export and verify offline.

The console

A real product, not a mockup.

Ask, ground and verify: every answer next to its sources.

Ask, ground and verify: every answer next to its sources. See all views →

Drop-in API

Point your existing clients at Nuvora.

Chat, streaming and image endpoints speak the OpenAI wire format, so SDKs and tools work unchanged. Behind them, every request passes guardrails, routing, budgets and the audit chain.

  • Scoped service tokens per workspace
  • Token budgets and concurrency caps
  • Every call metered and recorded
client.py
import os
from openai import OpenAI

client = OpenAI(
base_url="https://nuvora.example.com/v1",
api_key=os.environ["NUVORA_TOKEN"], # a scoped service token
)

reply = client.chat.completions.create(
model="auto", # or a model id, or "router:<id>"
messages=[{"role": "user", "content": "Summarize our refund policy"}],
)
print(reply.choices[0].message.content)

Why Nuvora

Built for the questions risk teams ask.

You can’t send prompts or documents to a hosted AI vendor

Your own endpoints only, on an exact host allow-list

Answers sound right, but nobody can say where they came from

Cited passages with content digests on every grounded answer

An agent wants to send, write or spend

The step pauses until a different person approves the exact action

Audit asks what happened six weeks ago

A hash-chained audit log you can export and verify offline

Teams share a platform but not their data

Tenant-scoped storage, four roles, SSO groups and document access rules

Finance asks what AI costs

A usage ledger per workspace, with budgets and cache savings

Run it on your laptop in a minute.
Run it on your cluster in one command.

./scripts/deploy-remote.sh HOST USER

Builds on the host, imports into k3s and serves HTTPS with a generated admin password. SQLite on one node, PostgreSQL across replicas.

Zyvor Production License v1.0: free for evaluation, development and other non-production use; production needs a commercial license. The capability matrix in the repository says exactly what is and isn’t built.