For platform engineering

Test data as a platform service you can verify

Platform teams are asked to make test data self-service without opening the network or copying production around. DataNivra runs an outbound-only agent in your environment, ships verifiable releases and gives pipelines an API for datasets per build.

The problem

Every team that copies production into a test environment creates a system the platform team now has to secure.

  • Nobody can say which environments hold copies of production, or who approved them.
  • Inbound connections from a vendor into the data network are a non-starter for security review.
  • Ephemeral environments need data on creation and clean-up on deletion, not a weekly manual refresh.

Live sample — synthetic, runnable now

The agent runs in your network. Before you deploy it, check what you are deploying: the release below is the one published on this site, with checksums you can verify.

Agent release
0.3.0 · 2026-10-07
Image (digest-pinned)
ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c
Platforms
linux/amd64, linux/arm64
Checksums
SHA256SUMS with a Sigstore bundle — see Downloads

Run it yourself

Verify a file of agent release 0.3.0 against its published SHA-256 checksums before you deploy it.

BASE=https://www.datanivra.com/downloads/agent/0.3.0
curl -fsSLO "$BASE/SHA256SUMS"
curl -fsSLO "$BASE/datanivra-agent-0.3.0-helm-values.yaml"
sha256sum --ignore-missing -c SHA256SUMS

Expected output:

datanivra-agent-0.3.0-helm-values.yaml: OK

Full tested example: Customer-resident processing — verify the agent you run. Or open the synthetic playground for this pack — no account.

The outcome

  • One agent per network, deployed with Helm, Docker or your cloud template, connecting out over HTTPS.
  • Pipelines request a dataset per build, wait for it and clean it up — with value-free evidence kept per run.
  • Approvals, policy versions and every privileged action in a hash-chained audit trail.
  • Tenant isolation on every request, and signed job authorizations the agent checks before it runs anything.

Security: production data stays home

Runs in your environment Row-level work happens only in your environment.

  • Outbound-only: the agent connects to DataNivra Cloud; nothing connects into your network.
  • Every field that crosses the boundary is classified; messages carrying anything else are rejected on both sides.
  • Source credentials and masking keys stay in your secret store and are referenced, never transmitted.

Customer-resident architecture · Verify it yourself · Security model

Your first action

  1. Verify the latest agent release with the snippet above and read the release notes.
  2. Read the customer-resident architecture and the trust page, then check it with your own proxy.
  3. Start free, enrol one agent in a non-production network and wire one pipeline.

Other teams: Developer · QA automation · Data engineer · Healthcare · Finance · Insurance · Manufacturing · All teams