For platform engineering
Test data as a platform service you can verify
Platform teams are asked to make test data self-service without opening the network or copying production around. DataNivra runs an outbound-only agent in your environment, ships verifiable releases and gives pipelines an API for datasets per build.
The problem
Every team that copies production into a test environment creates a system the platform team now has to secure.
- Nobody can say which environments hold copies of production, or who approved them.
- Inbound connections from a vendor into the data network are a non-starter for security review.
- Ephemeral environments need data on creation and clean-up on deletion, not a weekly manual refresh.
Live sample — synthetic, runnable now
The agent runs in your network. Before you deploy it, check what you are deploying: the release below is the one published on this site, with checksums you can verify.
- Agent release
- 0.3.0 · 2026-10-07
- Image (digest-pinned)
ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c- Platforms
- linux/amd64, linux/arm64
- Checksums
SHA256SUMSwith a Sigstore bundle — see Downloads
Run it yourself
Verify a file of agent release 0.3.0 against its published SHA-256 checksums before you deploy it.
BASE=https://www.datanivra.com/downloads/agent/0.3.0
curl -fsSLO "$BASE/SHA256SUMS"
curl -fsSLO "$BASE/datanivra-agent-0.3.0-helm-values.yaml"
sha256sum --ignore-missing -c SHA256SUMSExpected output:
datanivra-agent-0.3.0-helm-values.yaml: OKFull tested example: Customer-resident processing — verify the agent you run. Or open the synthetic playground for this pack — no account.
The outcome
- One agent per network, deployed with Helm, Docker or your cloud template, connecting out over HTTPS.
- Pipelines request a dataset per build, wait for it and clean it up — with value-free evidence kept per run.
- Approvals, policy versions and every privileged action in a hash-chained audit trail.
- Tenant isolation on every request, and signed job authorizations the agent checks before it runs anything.
Security: production data stays home
Runs in your environment Row-level work happens only in your environment.
- Outbound-only: the agent connects to DataNivra Cloud; nothing connects into your network.
- Every field that crosses the boundary is classified; messages carrying anything else are rejected on both sides.
- Source credentials and masking keys stay in your secret store and are referenced, never transmitted.
Customer-resident architecture · Verify it yourself · Security model
Your first action
- Verify the latest agent release with the snippet above and read the release notes.
- Read the customer-resident architecture and the trust page, then check it with your own proxy.
- Start free, enrol one agent in a non-production network and wire one pipeline.
Other teams: Developer · QA automation · Data engineer · Healthcare · Finance · Insurance · Manufacturing · All teams