---
title: "Nirmata"
url: https://docs.nirmata.io/
---

<header class="bannerfront cust-header-section bg-primary row homepage-section">
<div class="containerfront sectionfront">
<div class="row">
<div class="col-lg-8 mx-auto text-center">
<h1 class="text-white h1heading mb-3">Nirmata Documentation</h1>
<p class="text-white mb-1" style="font-size: 1.35rem; font-weight: 600; font-family: 'Ubuntu', sans-serif; letter-spacing: 0.01em;">AI and Infrastructure Governance Platform</p>
<p class="text-white mb-4" style="font-size: 1.1rem; opacity: 0.8; line-height: 1.7;">Identity-aware policy enforcement, AI agent governance, and runtime authorization across every control point — built on Kyverno.</p>
<div class="btn-hero-group">
<a class="btn btn-lg btn-primary" href="/docs/ai">Get Started with AI Agents</a>
<a class="btn btn-lg btn-secondary" href="/docs/control-hub">Explore Control Hub</a>
</div>
</div>
</div>
</div>
</header>
<section class="py-3 homepage-section" style="background-color: #F3F6FB; border-bottom: 1px solid #D4DCE5;">
<div class="container-fluid px-4">
<p class="mb-0 text-center" style="font-size: 1rem; color: #1E345D;"><strong>From the team that created Kyverno</strong> — the CNCF Graduated project with 7K+ GitHub stars, trusted by thousands of organizations worldwide</p>
</div>
</section>
<section class="py-5 homepage-section" style="background-color: #fff;">
<div class="container">
<h2 class="text-center mb-2" style="color: #1E345D; font-family: 'Ubuntu', sans-serif;">Our Products</h2>
<p class="text-center text-muted mb-5">Platform tools for policy governance, CLI operations, and enterprise Kubernetes</p>
<div class="row justify-content-center">
<div class="col-lg-10 mb-4">
<div class="doc-card doc-card--featured">
<div class="card-body d-flex flex-wrap align-items-center">
<div style="flex: 1; min-width: 240px;">
<h5 class="card-title" style="color: #1E345D;"><strong>Nirmata Control Hub</strong></h5>
<p class="card-text text-muted mb-0">Unified control plane for managing policy governance across Kubernetes clusters, IaC, CI/CD pipelines, and cloud resources. Provides identity context, policy management, guardrails, context graph, observability, and exception handling.</p>
</div>
<div class="ml-4 mt-3 mt-md-0">
<a href="/docs/control-hub" class="btn btn-primary">View docs</a>
</div>
</div>
</div>
</div>
<div class="col-lg-10 mb-4">
<div class="doc-card doc-card--featured">
<div class="card-body d-flex flex-wrap align-items-center">
<div style="flex: 1; min-width: 240px;">
<h5 class="card-title" style="color: #1E345D;"><strong>Nirmata CLI (nctl)</strong></h5>
<p class="card-text text-muted mb-0">Command-line tool for managing policies, clusters, AI agents, and governance workflows. The primary interface for the Nirmata Assistant and all platform automation.</p>
</div>
<div class="ml-4 mt-3 mt-md-0">
<a href="/docs/nctl" class="btn btn-primary">View docs</a>
</div>
</div>
</div>
</div>
<div class="col-lg-10 mb-4">
<div class="doc-card doc-card--featured">
<div class="card-body d-flex flex-wrap align-items-center">
<div style="flex: 1; min-width: 240px;">
<h5 class="card-title" style="color: #1E345D;"><strong>Nirmata Enterprise for Kyverno</strong></h5>
<p class="card-text text-muted mb-0">Enterprise Kyverno distribution with LTS support, SLAs, and FIPS compliance. Enforce policies at admission time across all Kubernetes clusters with extended support and enterprise features.</p>
</div>
<div class="ml-4 mt-3 mt-md-0">
<a href="/docs/controllers/n4k" class="btn btn-primary">View docs</a>
</div>
</div>
</div>
</div>
</div>
</div>
</section>
<section class="py-5 homepage-section" style="background-color: #F3F6FB; border-top: 1px solid #D4DCE5;">
<div class="container">
<h2 class="text-center mb-2" style="color: #1E345D; font-family: 'Ubuntu', sans-serif;">AI Agents</h2>
<p class="text-center text-muted mb-5">Autonomous governance agents — remediate, optimize, audit, and recommend across your platform</p>
<div class="row justify-content-center">
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card doc-card--featured h-100">
<div class="card-body">
<h5 class="card-title" style="color: #1E345D;"><strong>Nirmata Assistant</strong></h5>
<p class="card-text text-muted">Security-first AI assistant for platform engineers. 15+ specialized skills via CLI — generate policies, write tests, and get instant governance help from your terminal.</p>
<a href="/docs/ai/nctl-ai" style="color: #71CFEB; font-weight: 600; position: relative; z-index: 1;">View docs →</a>
</div>
</div>
</div>
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card doc-card--featured h-100">
<div class="card-body">
<h5 class="card-title" style="color: #1E345D;"><strong>Cloud Agents</strong></h5>
<p class="card-text text-muted">On-demand, scheduled AI agents that run in the cloud. Perform automated audits, compliance scans, and governance tasks on a schedule without in-cluster installation.</p>
<a href="/docs/control-hub/agent-hub/cloud-agents" style="color: #71CFEB; font-weight: 600; position: relative; z-index: 1;">View docs →</a>
</div>
</div>
</div>
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card doc-card--featured h-100">
<div class="card-body">
<h5 class="card-title" style="color: #1E345D;"><strong>Service Agents</strong></h5>
<p class="card-text text-muted">Autonomous in-cluster agents for 24/7 monitoring and remediation. Deploy once and let them continuously enforce governance, detect drift, and open GitOps PRs with AI-generated fixes.</p>
<a href="/docs/ai/service-agents" style="color: #71CFEB; font-weight: 600; position: relative; z-index: 1;">View docs →</a>
</div>
</div>
</div>
</div>
</div>
</section>
<section class="py-5 homepage-section" style="background-color: #F3F6FB; border-top: 1px solid #D4DCE5;">
<div class="container">
<h2 class="text-center mb-2" style="color: #1E345D; font-family: 'Ubuntu', sans-serif;">Policy Control Points</h2>
<p class="text-center text-muted mb-5">Identity-aware policy enforcement, runtime authorization, reporting, and exceptions — built on Kyverno + Kyverno AuthZ</p>
<div class="row justify-content-center">
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card h-100">
<div class="card-body">
<h6 class="card-title" style="color: #1E345D;"><strong>Kubernetes Control Point</strong></h6>
<p class="card-text text-muted small">Enforce policies at admission time across all Kubernetes clusters with Kyverno. Includes Nirmata Enterprise for Kyverno — the enterprise Kyverno distribution with LTS and SLAs.</p>
<a href="/docs/controllers/n4k" style="color: #71CFEB; font-weight: 600; font-size: 0.9rem; position: relative; z-index: 1;">Nirmata Enterprise for Kyverno docs →</a>
</div>
</div>
</div>
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card h-100">
<div class="card-body">
<h6 class="card-title" style="color: #1E345D;"><strong>Pipeline Control Point</strong></h6>
<p class="card-text text-muted small">Shift-left policy checks in GitHub Actions, GitLab CI, Jenkins, and Bitbucket pipelines using nctl. Catch policy violations before they reach production.</p>
<a href="/docs/nctl" style="color: #71CFEB; font-weight: 600; font-size: 0.9rem; position: relative; z-index: 1;">nctl docs →</a>
</div>
</div>
</div>
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card h-100">
<div class="card-body">
<h6 class="card-title" style="color: #1E345D;"><strong>Terraform Control Point</strong></h6>
<p class="card-text text-muted small">Policy enforcement for Terraform Cloud workspaces via the Nirmata Terraform Controller. Block or warn on non-compliant infrastructure.</p>
<a href="/docs/controllers/ntc" style="color: #71CFEB; font-weight: 600; font-size: 0.9rem; position: relative; z-index: 1;">Nirmata Terraform Controller docs →</a>
</div>
</div>
</div>
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card h-100">
<div class="card-body">
<h6 class="card-title" style="color: #1E345D;"><strong>AI Control Point</strong> <span class="badge" style="background: #71CFEB; color: #1E345D; font-size: 0.7rem; border-radius: 4px; padding: 2px 6px; vertical-align: middle;">In Private Preview</span></h6>
<p class="card-text text-muted small">Identity-aware governance for LLM access. Enforce who can call which model, enforce session budgets pre-call, and maintain a full audit trail — powered by Kyverno CEL.</p>
<a href="/docs/controllers/mcp-ai-gateways" style="color: #71CFEB; font-weight: 600; font-size: 0.9rem; position: relative; z-index: 1;">Learn more →</a>
</div>
</div>
</div>
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card h-100">
<div class="card-body">
<h6 class="card-title" style="color: #1E345D;"><strong>Authz Control Point</strong> <span class="badge" style="background: #71CFEB; color: #1E345D; font-size: 0.7rem; border-radius: 4px; padding: 2px 6px; vertical-align: middle;">In Private Preview</span></h6>
<p class="card-text text-muted small">Runtime authorization for Kubernetes and cloud services using Kyverno AuthZ. Identity-aware, policy-driven authorization decisions with full audit trails.</p>
<a href="/docs/controllers/authorization-service" style="color: #71CFEB; font-weight: 600; font-size: 0.9rem; position: relative; z-index: 1;">Learn more →</a>
</div>
</div>
</div>
<div class="col-lg-4 col-md-6 mb-4">
<div class="doc-card h-100">
<div class="card-body">
<h6 class="card-title" style="color: #1E345D;"><strong>Cloud Control Point</strong></h6>
<p class="card-text text-muted small">Continuous posture management and admission control for AWS, GCP, and Azure with Nirmata Control Hub.</p>
<a href="/docs/controllers/nch-cloud" style="color: #71CFEB; font-weight: 600; font-size: 0.9rem; position: relative; z-index: 1;">Nirmata Control Hub docs →</a>
</div>
</div>
</div>
</div>
</div>
</section>
<section class="py-4 homepage-section" style="background-color: #1E345D;">
<div class="container">
<div class="row align-items-center">
<div class="col-md-8 mb-3 mb-md-0">
<h5 class="text-white mb-1" style="font-family: 'Ubuntu', sans-serif;">Release Notes</h5>
<p class="mb-0" style="color: rgba(255,255,255,0.75); font-size: 0.95rem;">Latest updates across Nirmata Control Hub, Nirmata Enterprise for Kyverno, and nctl.</p>
</div>
<div class="col-md-4 text-md-right">
<a href="/docs/release-notes/control-hub" class="btn btn-sm btn-secondary mr-2 mb-2">Control Hub</a>
<a href="/docs/release-notes/n4k" class="btn btn-sm btn-secondary mr-2 mb-2">Enterprise for Kyverno</a>
<a href="/docs/release-notes/nctl" class="btn btn-sm btn-secondary mb-2">nctl</a>
</div>
</div>
</div>
</section>
<section class="py-5 homepage-section" style="background-color: #fff;">
<div class="container">
<div class="row align-items-center">
<div class="col-lg-7 mb-4 mb-lg-0">
<h2 class="mb-2" style="color: #1E345D; font-family: 'Ubuntu', sans-serif;">Nirmata Policy Library</h2>
<p class="text-muted mb-3">An extensive, open-source collection of 500+ Kyverno policies for security, compliance, and best practices — maintained by Nirmata, trusted by the Kubernetes community.</p>
<ul class="text-muted mb-4" style="padding-left: 1.25rem;">
<li>Pod Security Standards (Baseline &amp; Restricted)</li>
<li>RBAC hardening and least-privilege enforcement</li>
<li>Image signing, provenance, and supply chain security</li>
<li>CIS Kubernetes Benchmark controls</li>
<li>NSA/CISA Kubernetes Hardening Guidance</li>
</ul>
<a class="btn btn-primary mr-3" href="https://github.com/nirmata/kyverno-policies" target="_blank" rel="noopener">View on GitHub</a>
<a class="btn btn-outline-brand" href="/docs/policy-sets">Browse Curated Policies</a>
</div>
<div class="col-lg-5 text-center">
<div style="background: #F3F6FB; border-radius: 0.75rem; padding: 2rem; border: 1px solid #D4DCE5;">
<div style="font-size: 2.5rem; font-weight: 700; color: #71CFEB; font-family: 'Ubuntu', sans-serif;">500+</div>
<div style="color: #1E345D; font-weight: 600;">open-source policies</div>
<hr style="border-color: #D4DCE5; margin: 1rem 0;">
<div style="font-size: 1.5rem; font-weight: 700; color: #71CFEB; font-family: 'Ubuntu', sans-serif;">7K+</div>
<div style="color: #1E345D; font-weight: 600;">Kyverno GitHub stars</div>
<hr style="border-color: #D4DCE5; margin: 1rem 0;">
<div style="font-size: 1.1rem; font-weight: 600; color: #1E345D;">CNCF Graduated Project</div>
</div>
</div>
</div>
</div>
</section>


---

## Nirmata Documentation



---

## Search



