Docs/Security and Compliance

Security and Compliance

Tenant isolation, sandboxing, audit trails, and compliance readiness.

Tenant and org isolation

Tenant and org boundaries are resolved through the canonical bootstrap and policy layers. Marketplace visibility, access objects, and release channels do not bypass tenant controls.

WorkOS provides the identity and org signals. NOME enforces the isolation boundaries at every service layer: platform, gateway, spine, and client.

Tool sandboxing and risk classification

NOME uses AST-based shell command parsing for risk classification — structurally evaluating commands before execution instead of relying on string matching.

Tools are classified into risk tiers (read/write/danger). Dangerous operations trigger approval workflows. The tool policy matrix defines governance per tool.

File permission gateways

The file permission system operates on cascading configuration with strict precedence. The most restrictive protection level wins when multiple rules match.

noAccess blocks all operations on sensitive files (.env, keys, credentials). readOnly permits inspection but blocks modifications. Hardcoded rules ensure the system fails safe.

Audit trails vs telemetry separation

NOME explicitly separates audit/compliance trails from product telemetry. Evidence, approvals, and run receipts serve compliance review. Telemetry and eval traces serve product improvement.

This separation is a structural rule, not a policy preference. Merging these streams would compromise both compliance integrity and experimentation freedom.

Encrypted persistence and key management

Connector OAuth tokens and sensitive platform state use encrypted token persistence through the platform's secret records infrastructure.

SCIM bearer tokens are stored only as hashes. Key rotation is available through the control plane without backend surgery.

Compliance and evidence generation

Every NOME run produces receipts, tool call logs, approval records, and artifact references. These constitute the evidence chain for compliance review.

The evidence pass and run receipt system is designed for SOC2, HIPAA, and dedicated VPC deployment security reviews.

Ready to try it?

Open NOME

Futures, foreign currency, and options trading contains substantial risk and is not for every investor. An investor could potentially lose all or more than the initial investment. Risk capital is money that can be lost without jeopardizing one’s financial security or lifestyle. Only risk capital should be used for trading and only those with sufficient risk capital should consider trading. Past performance is not necessarily indicative of future results.

Hypothetical or simulated performance results have certain limitations. Unlike an actual performance record, simulated results do not represent actual trading. Also, since the trades have not been executed, the results may have under- or over-compensated for the impact, if any, of certain market factors, such as lack of liquidity. Simulated trading programs in general are also subject to the fact that they are designed with the benefit of hindsight. No representation is being made that any account will or is likely to achieve profits or losses similar to those shown.

NinjaTrader® is a registered trademark of NinjaTrader Group, LLC. No NinjaTrader company has any affiliation with the owner, developer, or provider of the products or services described herein, or any interest, ownership or otherwise, in any such product or service, or endorses, recommends or approves any such product or service.

Nomad Maraud may receive compensation when users register through partner links. This does not constitute a recommendation to trade futures or open a brokerage account.

NOME