NIRMATA · CREATORS OF KYVERNO

Govern Your AI

Unpredictable AI agents need deterministic control. Use Kyverno policies you already trust to enforce strict boundaries on every model call and tool execution.

Securing workloads at
Customer logoCustomer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logoCustomer logoCustomer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo Customer logo

One policy engine. Multiple control points.

Write rules in Kyverno CEL and enforce them everywhere: in the pipeline, at admission, at the gateway, and at runtime. Every decision streams into a single audit log—unified governance from the team that built the engine.

One policy language — Kyverno CEL
Control point 01

Pipeline

Catch violations at the source. Block non-compliant PRs before merge.

Nirmata Scanners
Control point 01

Pipeline

Secure artifacts at build time—validated, signed, and attested before deployment.

Nirmata Scanners
Control point 02

Admission

Control what enters the cluster. Enforce rules at the API server before resources run.

Enterprise Kyverno
Control point 02

Admission

Reuse the validate, mutate, and generate rules you run today—extended to agents with no second engine.

Enterprise Kyverno
Control point 03

Gateway

Secure every model call, MCP connection, and agent interaction across the wire.

AIControls Gateway
Control point 03

Gateway

Evaluate every prompt, tool call, and model response in real time—typically single-digit millisecond overhead.

AIControls Gateway
Control point 04

Runtime

Kernel-level detection and behavioral enforcement for active workloads.

Nirmata Runtime
Control point 04

Runtime

eBPF-powered sensors monitor running workloads to enforce policies and detect shadow AI.

Nirmata Runtime
One audit report One policy set One set of skills
↑ hover or tap a card for more detail ↑

Start where your problem is.

Govern your clusters, your AI agents, or both—one engine, one syntax, one audit log, no matter where you start.

Governing your clusters

Every cluster. Every deployment.

  • Policy-as-code across every cluster and namespace
  • Standard open-source engine—no proprietary syntax
  • Start in audit mode, then switch to active blocking

Fleet-wide governance from day one—on the engine you already run.

Explore cluster governance →
Governing your agents

Every AI call. Every agent action.

  • Identity, authorization, and limits on every call
  • Centralized policy definition enforced at the gateway
  • Complete audit log for every tool an agent touches

Extends your existing Kyverno policies to the AI stack—not a new system to learn.

Explore agent governance →

Your Kyverno investment compounds in the AI era.

The skills, policy pipelines, and compliance rules your team built for Kubernetes carry directly over to AI workloads.

CNCF GraduatedProject Status
7M+Monthly Downloads
Apache 2.0Open Source, No Lock-In
Customer testimonial

"We found agents in our clusters nobody had told us about. That's the part that kept me up. Now nothing reaches a model without an identity attached and a policy decision behind it."

— Platform Lead · Large Retailer
Field performance

We now have identity-based authorization in front of every AI call — enforced with the same Kyverno policies already enforced across our clusters.

Read the solution brief →

Unify your governance from clusters to AI.

Talk to us about governing your clusters, your agents, or both—one engine, one audit log, no matter where you start.