Single sign-on (OIDC)
Nuvora signs people in through any OpenID Connect provider: Keycloak (including Haven), Microsoft Entra ID, Okta, Auth0 or Google Workspace. Password sign-in keeps working for the bootstrap administrator and any local accounts.
PostgreSQL and replicas
SQLite stays the default: no extra service, one file, one process. Set NUVORADATABASEURL to run on PostgreSQL 13 or later and scale to several replicas. This needs the postgres extra (psycopg), which the container image includes.
Zyvor platform integrations
Each integration is configured by the operator through the environment. Its host must also be on NUVORAPROVIDERHOSTS, it must use HTTPS for anything but loopback, and redirects are refused. Govern → Settings → Integrations shows what is configured and has a Test button for each system.
Documents, retrieval and evaluations
Upload documents
Guardrails
A guardrail policy is a workspace resource, edited in Govern → Guardrails or with POST /api/policies. Nuvora checks the input before a model sees it and the output before a person does. Streamed answers are released sentence by sentence after the check, or held until the end when the policy needs the whole answer (a classifier model or a grounding threshold).
Routers and caching
Cascade routers
Agents, tools and prompts
Tools
Connectors and document access
Connectors keep a knowledge base in step with a source. They are administrator resources, managed in Workspace → Connectors.
Images, audio and extraction
Vision in chat
Fine-tuning and distillation
Nuvora prepares and governs customization; your own trainer does the GPU work.
Image generation
Create a model with the image capability and an imageprice (cost per image). An OpenAI-compatible image endpoint that returns b64json works. For a dry run without a GPU, the offline demo seeds Offline demo images, which returns a synthetic placeholder.