n

nono

Developed by always-further

nono is a capability-based, policy-governed runtime for AI agents. Fitting perfectly between giving agents full host access and sealing them in VMs, it grants agents narrowly scoped access to necessary host resources. These composable policies are strictly enforced via OS-kernel primitives like Landlock and Seatbelt. Its key features include secure proxy credential injection without exposing API keys, allowlist-based network filtering, content-addressable filesystem snapshots for secure rollbacks, and comprehensive audit logs.

  • OS-level kernel sandboxing (Landlock/Seatbelt)
  • Secure proxy credential injection
  • Allowlist-based network filtering
  • Filesystem snapshots and rollbacks
  • Comprehensive audit logs and attestation
desktop