The agent reality layer · start here
See it. Prove it. Run a real agent through it.
One primitive under everything: compute(who, what, intent) → authorized view + proof. Data stays sealed at rest, keys release per request, and non-access is provable. The agent never receives too much in the first place — no block, no "Access Denied," just a reality computed for it. Below: the demos to watch, the proofs to check yourself, the mechanism, and the one command to point a real agent at it.
Classify→Protect→Route→Retrieve→Prove
New here? Watch one thing move, check it’s real, then point your own agent at it — in that order.
01See itdemos you can play in 30 seconds
Agent Console
Same question. Different answer. Proven.
Switch the agent's identity — CISO, Exec, Comms, Legal — and it works perfectly on a reality computed for it. It never receives too much in the first place: no block, no "Access Denied." Partial key, live proof.
Open /agent-identity-console.html →
Steal the Crown Jewels
Attack it. You can't.
We sealed our own secrets and hand you the keyboard. Three identities, three answers, and every jailbreak returns zero — because the key was never released.
Open /steal-the-crown-jewels.html →
CISO Simulator
One request, the whole stack
Throw one request at an entire security stack and watch each layer respond as it does today — then see NoData govern the one thing none of them own: the decision on the information.
Open /ciso-simulator.html →
02Prove itverify without trusting us
Verify a receipt
Recompute the proof
Every decision emits a signed, hash-chained receipt. Paste one and re-verify it against the same chain, holding no secret of ours.
Open /verify-pack →
Proofs
The evidence ledger
Content-free receipts for what was decided and what was never released — names, counts and hashes, never a value.
Open /proofs →
Prove non-access
What the AI never saw
The one thing only this architecture can produce: a signed certificate that the model was provably not shown these fields.
Verify a receipt /verify-pack →
03Understand itthe full mechanism
How it works
The one primitive
Classify, Protect, Route, Retrieve, Prove — five continuous ops on one self-governing unit of information, exposed through few endpoints.
Open /how-it-works-v2 →
Fabric
The reach
Capsules that carry their own security and classification, computed at request time — the network effect when they connect.
Open /fabric →
For CISOs
Why it's a moat
Ciphertext at rest, no keys held, provable non-access, recompute-never-cache — architectural, not a feature.
Open /for-ciso →
04Run a real agent through itone command
Point any MCP client (Claude, Cursor, an agent runtime) at NoData
# the agent holds a grant, not a key — it physically cannot exceed its claims
claude mcp add nodata -- npx @nodatachat/mcp --grant-token ndca-YOUR_GRANT