FAQ
What data leaves my servers?
Section titled “What data leaves my servers?”The gate sends Noset what it needs to decide and to keep the evidence: the request an agent wants to make (method, host, path), with values that look like secrets masked before they leave the gate, the rule it matched, and the evidence records. Request bodies and command output are never sent.
On-prem, the Noset server is yours, so nothing leaves your network. In Noset Cloud, the server runs in Germany.
If you turn on agents’ reasons, the gate also sends the masked context of what the agent said before its request. The server has your organization’s own Claude integration summarize it, with your own Anthropic key, and keeps only the summary.
Does Noset see my API keys?
Section titled “Does Noset see my API keys?”No. When you start an agent with noset run --credential NAME, the key stays in the gate’s environment on your server, and the agent only sees a placeholder. The gate puts the real key into the request on its way out. The key is never sent to Noset or written into the evidence.
What happens when Noset is down?
Section titled “What happens when Noset is down?”The gate keeps working with the last rules it has:
- Deny keeps denying.
- Allow, and requests no rule matches, keep running.
- Ask: no new approvals. The agent gets “Noset cannot reach the approval service, try again later”. Approvals that arrived before still work, once each.
The gate keeps writing evidence locally and uploads it when Noset is back. After the offline limit (24 hours by default) every request through the gate is refused until Noset answers again.
Can an agent go around the gate?
Section titled “Can an agent go around the gate?”The agent runs in a small virtual machine with no network device: no network card, no route, no DNS. Its only way out is the gate, outside the virtual machine. A program that ignores the proxy simply cannot connect.
What the gate cannot see: actions another system does later because of the agent (a CI pipeline running code the agent pushed), and tools that run on the AI provider’s own servers. Put rules on those channels too, for example on git push.
Which systems does the gate run on?
Section titled “Which systems does the gate run on?”Linux x86_64 with KVM: Ubuntu 24.04 or later, or Debian 13 or later. macOS 13 or later (Apple silicon and Intel) is in testing. See Install the gate.
Can I check the evidence without trusting Noset?
Section titled “Can I check the evidence without trusting Noset?”Yes: export it and run noset verify on your own computer. See Verify the evidence.