Customer-resident architecture
Metadata crosses the boundary. Rows never do.
A hosted control plane for coordination. A data plane that lives where your data lives.
Text description
- DataNivra Cloud: Website & console → Control-plane API → Metadata & audit store → Policy registry & approvals
Connection: Outbound-only HTTPS, started by the agent — Metadata, aggregates, evidence references only. No raw rows, no secrets.
- Your environment: DataNivra agent → TDM engine → Source systems (read-only) → DEV / QA / SIT / UAT / PERF targets
What runs where
| DataNivra Cloud (control plane) | Your environment (data plane) |
|---|---|
| Tenants, users, roles and OIDC single sign-on | The DataNivra agent (container) and its local secret providers |
| Policy registry, versions and approvals | Read-only connectors to databases, lakes and files |
| Dataset requests, job state and schedules | Discovery, profiling, classification, subsetting, masking, synthesis |
| Aggregate metrics and evidence references | Validation, certification, evidence files and provisioning to targets |
| Audit trail of every privileged action | Local job workspaces, cleaned up by policy |
What crosses the boundary
| Class | Examples | Reaches DataNivra Cloud? |
|---|---|---|
| Control metadata | Job ids and states, table and column names, policy versions, timestamps | Yes |
| Aggregate metrics | Row counts, null ratios, durations, rule-hit counts | Yes |
| Evidence metadata | Checksums, customer-side artifact URIs, gate outcomes | Yes |
| Secret references | A vault path or key-vault secret name — never the value | Yes |
| Raw data | Cell values, rows, samples, query results, credentials, keys | Never |
Why “zero raw-production-data egress” and not “zero copy”
The agent does create copies — subsets, masked datasets, synthetic datasets — inside your environment, because that is what test data is. What it never does is send raw production data out. That is the precise promise, and it is enforced in code: message contracts reject unclassified or prohibited fields, the agent’s egress guard inspects every outbound message, and the control plane validates again on arrival.

Text description
- DataNivra Cloud: Queue declarative command → Grant time-bound lease → Record status & audit
Connection: Agent-initiated HTTPS only; no inbound ports
- Your environment: Agent polls for work → Verify command & policy checksum → Execute locally → Report metadata
The standard deployment is the hosted control plane with your agents. For isolated networks, a self-hosted control plane is available on request as a Docker Compose scaffold with offline-verified license files. Read customer-resident data processing for a guided explanation.