Policy-first data broker for AI agents. One call plans, routes, enforces, attests, and audits.
Part of the Kraken stack: Fathom (reasoning engine) · Nautilus (policy data broker) · Stargraph (agent-graph framework).
Current version: the PyPI badge above (a number typed here goes stale on the next release). Ask an install: nautilus version, or curl -sS $NAUTILUS/healthz.
License: Apache-2.0
Language: Python 3.13+
Package Manager: uv
Maintained by: KrakenNet
Every AI agent framework gives agents direct access to data. For most tasks, that's fine.
For some tasks, unchecked access is unacceptable:
- Policy routing — "Which databases should this query hit?" can't be the agent's choice.
- Scope enforcement — "What rows is this agent allowed to see?" needs provable constraints.
- Audit — "What data did this agent touch, and why?" requires a tamper-evident trail.
- Attestation — "Can we prove this routing decision happened?" needs a signed token.
Nautilus provides deterministic, policy-first data brokering using Fathom — a CLIPS-based expert system — to route, scope, and attest every request.
uv add nautilus-rkmDatabase and object-store drivers are extras — install the ones your sources
need, or [all] for every built-in adapter:
uv add "nautilus-rkm[postgres]" # pgvector, elasticsearch, neo4j, influxdb, s3
uv add "nautilus-rkm[all]"A source whose driver is missing fails at startup naming the extra to install.
nautilus demo # a governed agent-to-agent handoff decision. No config, no database.
nautilus init # writes a nautilus.yaml that runs as it standsfrom nautilus import Broker
with Broker.from_config("nautilus.yaml") as broker:
response = broker.request(
"agent-alpha",
"Find vulnerabilities for CVE-2026-1234",
{"purpose": "threat-analysis", "session_id": "s1"},
)
print(response.outcome) # "allowed" | "denied" | "errored" | "skipped"
print(response.data) # {"main-db": [...]}
print(response.sources_queried) # ["main-db"]
print(response.denial_records) # why "classified-db" was refused, and by which rule
print(response.attestation_token) # signed JWS
print(response.duration_ms) # 47See the Getting Started guide for a full walkthrough.
Core runtime
Brokerfacade with sync/async APIs (request,arequest,from_config,afrom_config)- Fathom-based policy router for intent-aware source selection and scope enforcement
- Per-source scope constraints (WHERE-clause fragments) with injection-safe field validation
- Ed25519 JWS attestation service for signed routing decisions
- JSONL audit sink with per-request, append-only entries (fsync'd)
- Pattern-matching and LLM-based intent analysis (Anthropic, OpenAI)
- Cross-agent handoff reasoning with session-backed escalation detection
Adapters (10 built-in)
- PostgreSQL, PgVector, Elasticsearch, Neo4j, REST, ServiceNow, InfluxDB, S3, LLM
static— rows declared innautilus.yaml, for a first run with no database- Pluggable via entry points and the Adapter SDK
Transports
- FastAPI REST server (
POST /v1/request, health/readiness probes) - MCP transport (stdio and HTTP modes)
- CLI:
nautilus demo,nautilus init,nautilus serve,nautilus health,nautilus version
Rule packs
data-routing-nist— NIST clearance/classification routing rulesdata-routing-hipaa— HIPAA-compliant routing rules
| Step | What happens |
|---|---|
| Intent analysis | Classify intent into data types, entities, temporal scope, sensitivity |
| Policy routing | Fathom evaluates (clearance, purpose, source) — route, scope, or deny |
| Adapter fan-out | Routed sources execute concurrently with per-adapter error isolation |
| Attestation | Ed25519 JWS signed over routing decision, bound to request_id |
| Audit | JSONL entry appended per request — success, denial, or error |
Unlike stateless policy engines, Nautilus maintains working memory across requests within a session:
- Cumulative exposure — "This agent accessed PII from 3 sources — deny the 4th."
- Cross-agent handoffs — "Agent A is passing
secretdata to Agent B who hasunclassifiedclearance — deny." - Escalation detection — "Anomalous access pattern detected — escalate for forensic review."
Run the handoff refusal yourself with nautilus demo — no config, no adapter, no database.
As a library
from nautilus import Broker
with Broker.from_config("nautilus.yaml") as broker:
response = broker.request("agent-id", "intent", context)As a REST sidecar
nautilus serve --config nautilus.yaml --transport rest --bind 0.0.0.0:8000
curl -H "X-API-Key: $KEY" -X POST localhost:8000/v1/request \
-d '{"agent_id": "agent-alpha", "intent": "...", "context": {...}}'As an MCP server
nautilus serve --config nautilus.yaml --transport mcpAir-gapped mode
nautilus serve --config nautilus.yaml --air-gappedA nautilus.yaml declares sources, rules, analysis, audit, and attestation:
sources:
- id: main-db
type: postgres
description: "Customer orders"
classification: confidential
data_types: [users, orders]
allowed_purposes: [support]
connection: ${DATABASE_URL}
table: public.orders
agents:
support-bot:
id: support-bot
clearance: confidential
default_purpose: support
rules:
user_rules_dirs: [./rules/]
attestation:
enabled: true
audit:
path: ./audit.jsonlFull documentation is available at krakennet.github.io/nautilus.
- Fathom — Deterministic reasoning runtime that powers Nautilus routing
- Bosun — Agent governance built on Fathom (fleet analysis, compliance attestation)
git clone https://github.com/KrakenNet/nautilus.git
cd nautilus
uv sync
uv run pytest -m unit # fast suite, no containers
uv run pytest -m integration # full e2e, boots PostgreSQL via testcontainers
uv run ruff check && uv run ruff format --check && uv run pyright
uv run mkdocs serve # docs previewSee CHANGELOG.md for release notes.
We welcome contributions! Please read our Contributing Guide before submitting a pull request. All contributors are expected to follow our Code of Conduct.
To report a security vulnerability, please see our Security Policy. Do not open a public issue for security concerns.
Apache-2.0 — see LICENSE for details.