Customer-resident architecture

Metadata crosses the boundary. Rows never do.

A hosted control plane for coordination. A data plane that lives where your data lives.

Four data classes may cross the boundary; raw data never doesInside your network, control metadata, aggregate metrics, evidence metadata and secret references are the only classes sent to the DataNivra Cloud control plane. Raw rows, cell values, credentials and keys stop at the boundary.Your networkdata planeControl metadataAggregate metricsEvidence metadataSecret referencesRaw rows and valuesnever leavesDataNivra Cloudjobs and schedulespolicies, approvalsaudit trailevidence references
Control plane and customer-resident data planeTwo zones. The top zone is DataNivra Cloud: public website and console, control-plane API, a metadata and audit store, and the policy registry. The bottom zone is your environment: the DataNivra agent, the TDM engine, your source systems accessed read-only, and your test environments. The agent opens outbound-only HTTPS connections to the cloud and sends only control metadata, aggregate metrics, evidence references and secret references. Raw rows and secret values never cross the boundary.DataNivra CloudWebsite & consoleControl-plane APIMetadata & auditstorePolicy registry &approvalsYour environmentDataNivra agentTDM engineSource systems(read-only)DEV / QA / SIT / UAT/ PERF targetsOutbound-only HTTPS, started by the agentMetadata, aggregates, evidence references only. No rawrows, no secrets.
Control plane and customer-resident data plane. Two zones. The top zone is DataNivra Cloud: public website and console, control-plane API, a metadata and audit store, and the policy registry. The bottom zone is your environment: the DataNivra agent, the TDM engine, your source systems accessed read-only, and your test environments. The agent opens outbound-only HTTPS connections to the cloud and sends only control metadata, aggregate metrics, evidence references and secret references. Raw rows and secret values never cross the boundary.
Text description
  1. DataNivra Cloud: Website & console → Control-plane API → Metadata & audit store → Policy registry & approvals

    Connection: Outbound-only HTTPS, started by the agent — Metadata, aggregates, evidence references only. No raw rows, no secrets.

  2. Your environment: DataNivra agent → TDM engine → Source systems (read-only) → DEV / QA / SIT / UAT / PERF targets

What runs where

Responsibilities of each plane
DataNivra Cloud (control plane)Your environment (data plane)
Tenants, users, roles and OIDC single sign-onThe DataNivra agent (container) and its local secret providers
Policy registry, versions and approvalsRead-only connectors to databases, lakes and files
Dataset requests, job state and schedulesDiscovery, profiling, classification, subsetting, masking, synthesis
Aggregate metrics and evidence referencesValidation, certification, evidence files and provisioning to targets
Audit trail of every privileged actionLocal job workspaces, cleaned up by policy

What crosses the boundary

Data classes and whether they may reach the cloud
ClassExamplesReaches DataNivra Cloud?
Control metadataJob ids and states, table and column names, policy versions, timestampsYes
Aggregate metricsRow counts, null ratios, durations, rule-hit countsYes
Evidence metadataChecksums, customer-side artifact URIs, gate outcomesYes
Secret referencesA vault path or key-vault secret name — never the valueYes
Raw dataCell values, rows, samples, query results, credentials, keysNever

Why “zero raw-production-data egress” and not “zero copy”

The agent does create copies — subsets, masked datasets, synthetic datasets — inside your environment, because that is what test data is. What it never does is send raw production data out. That is the precise promise, and it is enforced in code: message contracts reject unclassified or prohibited fields, the agent’s egress guard inspects every outbound message, and the control plane validates again on arrival.

Outbound lease modelThe control plane queues a declarative command and grants a time-bound lease when the agent asks for work. The agent validates the command and the policy checksum, executes locally and reports metadata. The control plane never opens a connection into your network.DataNivra CloudQueue declarativecommandGrant time-bound leaseRecord status & auditYour environmentAgent polls for workVerify command &policy checksumExecute locallyReport metadataAgent-initiated HTTPS only; no inbound ports
Outbound lease model. The control plane queues a declarative command and grants a time-bound lease when the agent asks for work. The agent validates the command and the policy checksum, executes locally and reports metadata. The control plane never opens a connection into your network.
Text description
  1. DataNivra Cloud: Queue declarative command → Grant time-bound lease → Record status & audit

    Connection: Agent-initiated HTTPS only; no inbound ports

  2. Your environment: Agent polls for work → Verify command & policy checksum → Execute locally → Report metadata

The standard deployment is the hosted control plane with your agents. For isolated networks, a self-hosted control plane is available on request as a Docker Compose scaffold with offline-verified license files. Read customer-resident data processing for a guided explanation.