@nodatachat/nodata
v0.1.1
Published
NoData, the Information Access Processor. One CLI to discover, protect and govern access to information, with a verifiable proof for every decision.
Maintainers
Readme
@nodatachat/nodata
NoData, the Information Access Processor. One CLI to discover, protect and govern
access to information, with a verifiable proof for every decision. The same engine
is reachable from any MCP client through @nodatachat/mcp.
Discover locally. Protect locally. Govern exposure. Prove every decision.
npm i -g @nodatachat/nodata
nodatanodata guided menu (English / עברית)
nodata scan <dir> Discover: what an AI could read here (local, no account)
nodata protect <dir> Protect: seal it, keep the key (local, free)
nodata open <file>.ndc reverse a local seal
nodata login --email [email protected] store your ndp_ org key under your email
nodata whoami / use <name> see who you are / switch user or org
nodata agent grant Govern: give an agent its own identity and access
nodata agent ask a governed decision (allow / deny / degrade) + a receipt
nodata agent revoke <name> remove access
nodata verify <proof_id> Prove: check any decision receipt
nodata fabric enroll get your Fabric address (reach across organizations)
nodata explain <concept> a short teacher for any idea here
nodata mcp connect NoData to any MCP client (Claude Code, Cursor, Codex)
nodata init | encrypt | decrypt | run -- <cmd> seal .env secrets and run with them
nodata sign <file> / verify <file> sign a file, check its signature
nodata revoke <seal_id> / doctor revoke a seal, check your setupFlags: --he (Hebrew), --explain, --json, --yes, --remove, --profile <name>.
Every command that acts as a user prints a one-line ● [email protected] banner, so you
always see who you are.
What NoData promises
- We never see your data. Access is computed content-blind: counts and paths, never the values. Locally, nothing leaves your machine.
- The key stays with you. Your device key lives in
~/.nodataand never leaves. A stolen sealed file is inert; without your key it stays sealed. - You can remove access, anytime.
nodata agent revokeshuts the gate; a burn crypto-shreds the key, so the data is gone for good (nodata explain revoke-vs-burn). - Every decision has a proof. Each governed decision emits a signed, hash-chained
receipt (Ed25519 + post-quantum ML-DSA). Check any of them with
nodata verify <id>or on the public verifier; no key required.
See it live: verify a receipt · the Fabric console · what an agent saw
Agents, identity and Fabric
An agent is any identity that is not you: an app, an AI, a service, a workflow.
- Identity.
nodata agent grantmints an agent credential (ndca-): the agent's own identity, scoped to exactly what you allow. - Connect.
nodata fabric enrollregisters your Fabric address (a 16-hex kid). It is where others reach you; the secret half of the key never leaves your machine. - Across organizations. Fabric's relay carries sealed data between orgs to that
address. You enroll, others send to your address, and you govern who may fetch with
nodata agent grant. Every fetch is a governed decision with a receipt.
The funnel
scan never ends in a finding; it ends in the next governed action. Each rung earns
the next: Discover, then Protect, then Govern, then Prove. scan and protect
are free and local (no account, nothing leaves your machine). A governed transaction
is one decision about whether another identity may access information; that is the
metered rung.
How it works
- Local:
scan,protect/openand the .env seal (init,encrypt,run,sign) run on your machine. Files are sealed with AES-256-GCM, the key sealed to your device key. Nothing is uploaded. - Governed:
agent,fabricandverifycall the NoData service (/api/v1/governance/grant,/api/v1/relay/enroll,/api/access/compute,/api/access/verify), which computes each access decision and signs its receipt.
Users are profiles under ~/.nodata (NODATA_HOME relocates it, NODATA_PROFILE
picks one per command). The canonical host is nodatacapsule.com; the org key is
ndp_, an agent grant is ndca-, and a Fabric address is a 16-hex kid.
NoData on npm
Three packages:
@nodatachat/nodata(this one): the main package, with all protection, scanning and governance capabilities.@nodatachat/sdk: integration for developers.@nodatachat/mcp: integration for AI agents and MCP clients.
Coming from an older package:
| Before | Now |
|---|---|
| @nodatachat/protect | nodata, same commands (init, encrypt, run, sign, verify <file>, revoke, doctor, ...); its nickname + PIN login is nodata login --pin |
| @nodatachat/folder-scan | nodata scan <folder> |
If npm i -g @nodatachat/nodata stops with EEXIST on nodata, an older package owns
that command. Remove it first: npm rm -g @nodatachat/protect.
License
FSL-1.1-ALv2 (Functional Source License 1.1, Apache 2.0 future license). Use it for any purpose except a competing product or service. Each release becomes available under the Apache License 2.0 two years after it is published. Copyright 2026 Capsule Ltd.
