One rulebook, enforced everywhere
Pick rules from curated packs, roll them out in monitor mode, then enforce them on every laptop, gateway and agent. High-stakes actions wait for the right person, and incidents end in fixes.
- Rule packs for MCP, agents, secrets, models and LLM traffic, monitor mode first
- Approvals rendered from the real call, never the agent’s summary
- Incidents investigated for you, and fixes opened as pull requests
Can I run AI safely at company scale, and show that I do?

Rules live in a dozen consoles
Each AI product has its own settings page, and none of them agree on what “not allowed” means.
Approvals turn into rubber stamps
A hijacked agent can word its own approval request. A tired approver clicks yes on a summary, not on the call.
Incidents stall between teams
Security finds it, engineering owns it, and nobody closes it until the same thing happens again.
Govern in practice.
Each part below is shown the way it looks and works in the product.
Start from templates, not a blank page
Pick from 113 rule templates grouped by what they protect, or apply a whole pack. Every one starts in monitor mode so you can tune it before it blocks.
- Stricter in production, looser in a sandbox
- A repository can tighten the rules, never loosen them
- Every version kept, and flagged if it loosened a rule
Mapped to what you already report on
Every rule, finding and control maps to the frameworks your auditors and customers ask about, with controls marked covered, attested, at risk or not assessed.
- OWASP LLM and Agentic Top 10, MITRE ATLAS, NIST AI RMF
- ISO/IEC 42001, the EU AI Act, NIST CSF 2.0 and GDPR
- Not assessed is shown as not assessed, never as covered
When someone leaves, their agents don’t
NoFly shows every agent, key, MCP server and grant a departed person left running, and what revoking each one will and won’t stop.
- Departed people who still hold access, flagged
- An offboarding plan with every step
- Ticket and owner for each item
When this happens, do that.
Every automation is one sentence: a trigger, optional conditions, and one or more actions. Start in notify-only, read what it would have done, then let it contain.
Call blocked
Rule 1If the agent is in production and the rule is critical
- 01Post to #security-alertsSlack
- 02Declare an incidentNoFly
MCP server changed after approval
Rule 2If its tools or permissions widened
- 01Quarantine the serverNoFly
- 02Open a ticket for the ownerJira
Agent over budget
Rule 3If spend is 3 times its weekly average
- 01Clamp the budgetNoFly
- 02Page the on-call engineerPagerDuty
Nothing happened for 7 days
Rule 4If an enrolled machine or connector went quiet
- 01Tell the platform teamTeams
- 02Call your webhookWebhook
Illustrative
Things that start one
- Finding raised or back
- Call blocked
- Approval asked or decided
- Attack got through
- MCP server drifted
- Budget exceeded
- Connector went blind
- Nothing happened
“Nothing happened” is a real trigger: an agent that stopped reporting or a connector that went quiet looks exactly like a peaceful week, so NoFly fires on the silence.
When it becomes an incident
- Open
- Investigating
- Contained
- Resolved
- Closed
Incidents collect the runs, findings and agents involved, and playbooks hold the steps agreed before the bad afternoon.
Things it can do
- Tell someoneSlack, Teams, email or a ticket
- Put a person in the wayRequire an approval, answered in Slack, Teams or the console
- Contain itSuspend an agent · Revoke a grant · Narrow its authority · Quarantine a server · Clamp a budget
- Do the workPropose a fix · Run an attack simulation · Run a playbook · Re-prove the critical findings
- Hand it onDeclare an incident · Call a webhook
What most tools do, and what NoFly does.
Everything in Govern.
One rulebook for every agent, approvals that hold up, and incidents that end in fixes.
G1Packs, not blank pages
Curated packs and rule templates for packages, licences, containers, CI, MCP, agents, models, secrets and LLM traffic.
G2Rules by environment and team
Stricter in production, looser in a sandbox. A repository’s own policy file can tighten the rules, never loosen them.
G3The frameworks you report on
OWASP LLM and Agentic Top 10, MITRE ATLAS, NIST AI RMF, NIST CSF 2.0, ISO/IEC 42001, the EU AI Act, GDPR and more.
G4Tamper-evident history
A hash-chained audit log, every policy version kept, and a signed receipt for each firewall decision.
G5Exceptions with an expiry
Bypasses are time-boxed and logged. Accepted risks carry an owner, a reason and a date to look again.
G6Incidents, investigated for you
An AI investigator pulls the runs, calls and people involved into one case and proposes the fix, for a person to approve.
G7Automations and playbooks
When a call is blocked, a server drifts or a simulation breaches: page someone, open a ticket, revoke a key, quarantine a server.
G8Ask NoFly
Ask about your estate in plain words and get answers with links to the evidence.
G9People who leave
See the agents, keys and grants a leaver left running, and what revoking them will and won ’t stop.
G10Enterprise administration
SAML SSO, SCIM, custom roles, two-factor sign-in and data-subject export and erasure.
Questions about Govern.
Security team ›Can we start without blocking anything?
Security team ›How do approvals avoid rubber-stamping?
Security team ›Which frameworks are mapped?
Find out what your AI is allowed to do today.
Book a call and we will map your agents, MCP servers and keys with you, or start on one laptop with the free scan.