Explore the source
Start with the repository, follow development, and see how the platform is taking shape.
View on GitHub →Service accounts, API keys, workload identities and AI agents power your business. We’re building Nomyr to map what each one can reach, resolve who is accountable for it, and never quietly report a blind spot as good news.
git clone https://github.com/nomyr-security/nomyr.gitSPIFFE and SPIRE issue workload identities. cert-manager renews certificates. OpenBao and Vault hold secrets. All of them do their job well, and none of them can tell you who is accountable for the service account that has been reaching production for 214 days. Nomyr's core is the open layer that answers that — designed for self-hosting and transparent, evidence-driven decisions.
git clone https://github.com/nomyr-security/nomyr.gitcd nomyrmake web-installmake test-fastmake build./bin/nomyr demoSelf-hosted means identity metadata, access paths and evidence stay inside your perimeter by construction — not because a vendor architecture promises it. Nomyr is designed around local control of evidence and explicitly authorized connections.
Explore the source, follow the decisions behind the product, and contribute improvements. Open development gives your team a direct way to understand the platform and shape what comes next.
Nomyr is free to explore, self-host, and contribute to. Build with the community, inspect the source, and help shape non-human identity security around the needs of your team.
Every scanner can enumerate service accounts. The work starts at the three questions a flat list can't answer — and each one shapes the platform we’re building.
Candidate owners are ranked from authoritative evidence — service-catalog fields, CODEOWNERS, creation events — with the evidence shown beside the confidence. When nothing authoritative exists, the identity stays unresolved rather than taking the nearest plausible name.
Blast radius is scored on its own axis, beside severity — so a mid-severity finding on a widely-reachable identity stops hiding behind its rating.
Configured, observed and evaluated access are three different claims. Nomyr walks the real path, and when one policy condition can't be read it reports an unproven path — not an assumed allow, not an assumed deny.
When a source loses log access, most tools quietly show an improvement. Nomyr separates what it can see from what it can prove — revoked log access marks usage coverage unknown, and never marks an identity inactive.
An illustrative comparison for a 214-day-old key: a flat scanner record beside the evidence-rich view Nomyr is designed to provide.
Findings nobody can act on are just a longer list. Lifecycle runs, agent governance and a grounded assistant carry each one to a decision someone signed.
Provisioning, ownership, vaulting, rotation and retirement run as one auditable track. An identity parked at a stage shows which stage and why — here, no accountable owner means rotation policy has nobody to attach to.
Allow, flag or block what an agent may do, evaluated before the action executes and scoped by agent, team and resource. Agents with no declared manifest are flagged by default — visible immediately, never blocked blind.
The assistant works from the same evidence the screens show, cites the finding it is acting on, and writes the remediation step by step. It will not execute a production change without a human approving the plan — that boundary is a product decision, not a setting.
Every decision is timestamped with its actor, and an evidence package replays to the same findings it was built from.
Four operating modes in the Nomyr design. Explicit scope, human accountability, no silent escalation.
Discovers and evidences everything. Takes no automated action at all. Where every deployment starts.
Proposes fixes and drafts the change for a human to approve. Nothing moves without a signature.
Executes the low-risk, high-confidence actions you have defined. Everything else still routes to a person.
Blocks non-compliant access at request time, where a supported enforcement point exists.
Explore the code, run Nomyr in your own environment, and help shape what comes next. An open project for teams who want control of their machine identity security.
Start with the repository, follow development, and see how the platform is taking shape.
View on GitHub →Build from source and try the local demo in your own environment with the getting-started guide.
Get started →Bring your use cases, ideas, documentation, and code. Help make machine identity security better for everyone.
Contribute to Nomyr →Explore the open-source project, help shape machine identity security, or talk with us about your environment. Start with the source and see where Nomyr can fit into your identity stack.