Compliance and audit export commands

Part of the NovaFabric CLI reference. Both nova and novafabric run the same binary.

Compliance evidence commands (v0.15.0, BQ-005)

These commands require pip install 'novafabric[compliance]' for full functionality.

OQ-01 status (corrected): nova subject-proof (below) remains LEGAL-HOLD DRAFT MODE — it looks up an existing redaction proof; PII stays in a legal_hold/ staging area, not sealed capsules. The DEK-based crypto-shredding strategy this note used to describe as "planned for v0.26.x" has since shipped (ADR-0069, v0.44.0) as nova pii erase below, which actually destroys the wrapping DEK for a data subject rather than only staging a proof. Corrected 2026-09-02: this sentence also named nova erasure request, which never destroyed anything — it printed a success message and did nothing, and now fails loudly.

nova export-annex-iv <capsule> --output-dir <dir> --deployment-id <id>

Export EU AI Act Annex IV technical documentation from a Run Capsule (Regulation (EU) 2024/1689 Art. 11). Produces a JSON-LD file covering all 15 mandatory Annex IV elements, with an optional PDF.

nova export-annex-iv .novafabric/runs/01HX.../ \
  --output-dir ./compliance/ \
  --deployment-id "prod-eu-classifier-v2"

nova export-annex-iv <capsule> \
  --output-dir ./compliance/ \
  --deployment-id "prod-eu-classifier-v2" \
  --pdf    # requires weasyprint

Options:

Output fields include: system description, intended purpose, training data characteristics, human oversight measures, robustness metrics, and post-market monitoring plan. Fields are marked complete, partial, or missing based on capsule content, and each element carries an evidence_source provenance marker (ADR-0197).

Exit codes: 0 (success), 1 (missing compliance extra or export error).


nova export-nis2 <capsule> --output <file> --incident-id <id>

Export a NIS2 incident report (Directive (EU) 2022/2555 Art. 23) from a Run Capsule.

nova export-nis2 .novafabric/runs/01HX.../ \
  --output incident-report.json \
  --incident-id "INC-2026-0042" \
  --phase 1    # initial report (≤24h, default)

nova export-nis2 <capsule> --output report.json --incident-id INC-001 --phase 2   # ≤72h
nova export-nis2 <capsule> --output report.json --incident-id INC-001 --phase 3   # ≤1 month

Options:

Fields requiring cross-session lineage (cap-006) are explicitly marked missing with reason requires_cap_006_cross_session_lineage.

Exit codes: 0 (success), 1 (missing compliance extra or export error).


nova export-ropa <capsule> --output <file>

Export a GDPR Art.30 Records of Processing Activities (RoPA) entry from a Run Capsule (cap-007).

nova export-ropa .novafabric/runs/01HX.../ --output ropa-entry.json

nova export-ropa .novafabric/runs/01HX.../ \
  --output ropa.json \
  --controller-name "Acme Corp" \
  --controller-contact "dpo@acme.example"

Options:

Output is a JSON-LD document with gdpr: and nova: namespaces. Fields derivable from capsule metadata are populated automatically; operator-declared fields are stubs with missing_fields markers. Use --controller-name / --controller-contact to complete the entry.

Exit codes: 0 (success), 1 (export error).


nova export-nist-rmf <capsule> --output <file>

Export a NIST AI RMF 1.0 quantitative risk assessment report from a Run Capsule (cap-009).

nova export-nist-rmf .novafabric/runs/01HX.../ --output nist-rmf.json

Options:

Derives scores for all four NIST AI RMF Core functions:

risk_level = low|medium|high|critical based on overall score and non-compliant metric count. completeness = complete|partial based on whether all expected evidence files are present.

Exit codes: 0 (success), 1 (export error).


nova subject-proof <subject-id>

Look up PII redaction proof for a data subject (GDPR Art.17). HMACs the subject ID with NOVA_PII_PEPPER, queries the RedactionSubjectIndex, and returns a redaction_proof_report.json.

Requires: NOVA_PII_PEPPER environment variable (the same pepper value used during capture). This command will exit 1 if the env var is not set.

NOVA_PII_PEPPER="<secret>" nova subject-proof "user@example.com"

NOVA_PII_PEPPER="<secret>" nova subject-proof "user@example.com" \
  --output proof.json \
  --key ~/.novafabric/keys/ed25519.pem

Options:

Exit codes: 0 (subject found), 1 (env var missing, compliance extra missing, or DB error).


Sector and transparency export commands (experimental)

Thirteen read-only renderers that project supplied references and sealed evidence into sector-specific disclosure and attestation artifacts. Shared conventions:

Command Framework / audience ADR
nova export-compliance EU AI Act / ISO 42001 / NIST GenAI + CSA exporters ADR-0107
nova export-model-risk SR 26-2 / SR 11-7 model-risk evidence ADR-0159
nova export-model-independence Model-validation independence (ADR-0058 maker-checker) ADR-0159
nova export-retention SEC 17a-4 / MiFID retention posture + RFC 3161 timestamp ADR-0159
nova export-adverse-action ECOA / Reg B specific-reasons evidence (not a notice) ADR-0159
nova export-cat CAT-style lifecycle agent-event trail (SEC Rule 613 pattern; not a CAT submission) ADR-0159
nova export-part11 21 CFR Part 11 electronic records ADR-0160
nova export-rai-scorecard Responsible-AI coverage scorecard ADR-0158
nova export-public-annex-viii EU AI Act Annex VIII public DB (DRAFT) ADR-0169
nova export-transparency-register Algorithm registers: ATRS / Amsterdam / Helsinki (DRAFT) ADR-0169
nova export-public-disclosure Public-sector disclosure record (DRAFT) ADR-0169
nova export-foia FOIA / public-records decision export (DRAFT) ADR-0169
nova export-whistleblower Source-protecting whistleblower attestation ADR-0169
nova export-citizen-explanation Subject-facing decision explanation ADR-0169
nova export-public-incident Public-interest incident summary (DRAFT) ADR-0169
nova export-election-disclosure Election / civic content-provenance disclosure ADR-0169
nova export-accessibility-claim Declared accessibility-conformance claim ADR-0169
nova export-control-attestation Governance-control attestation pack ADR-0170
nova insurance Liability chain / SLA breach / coverage trigger evidence (experimental) ADR-0170

nova export-model-risk <evidence>

Assemble an SR 26-2 / SR 11-7 model-risk evidence file from per-pillar refs.

nova export-model-risk evidence.json --json

nova export-model-independence --model <id>

Experimental (ADR-0159 D2 / NF-276). Unlike the document-driven renderers above, this command reads the shipped ADR-0058 maker-checker records itself — the registry promotion_proposals rows written by nova promote propose / nova promote approve (opened read-only), plus, per --capsule-id, the NovaSeal DSSE bundles written by nova seal propose / nova seal approve, whose outcome is taken verbatim from the shipped verify_sod verifier. It renders whether the validator (checker) identity differs from the developer (maker) identity. It asserts only that independence was recorded — never that validation was sufficient, and never a rating. A single-identity approval is missing with reason single-identity approval; an open proposal, a bypass, or a record that failed SoD verification is missing with its reason. The single-sign-off nova approve table is not read (it records no developer identity).

nova export-model-independence --model credit-scorer@2.1
nova export-model-independence --model credit-scorer --capsule-id <capsule-id> --json

Exit codes: 0 (rendered, including missing fields), 2 (unreadable registry or malformed model id).


nova export-retention --bundle <zip>

Experimental (ADR-0159 D5 / NF-277). Attests the retention posture over one or more Evidence Bundles — the registry retention-policy.yaml window and deletion mode, the holds.jsonl legal-hold state, each run's WORM lock (local adapter worm.db, reported partial because it is dev/test only, or an S3 / Azure / GCS WormReceipt supplied via --worm-receipts), the RFC 3161 trusted timestamp as actually recorded in each bundle by nova export-evidence --timestamp (reported complete when the TSR is present and bound to the manifest digest; missing with the reason only when none was obtained), and the hash-chained audit-log entries for the run. It attests posture, never compliance, and makes nothing immutable. The TSR's TSA signature is not re-verified here — use openssl ts -verify as the bundle README describes.

nova export-retention --bundle evidence.zip --registry prod
nova export-retention --bundle a.zip --bundle b.zip --regime mifid --json

Exit codes: 0 (rendered, including missing rows), 2 (unreadable/corrupt bundle, policy, hold ledger, WORM DB or receipts).


nova export-adverse-action --run-id <id>

Experimental (ADR-0159 D6 / NF-278). Reads one sealed Run Capsule (by run id, resolved in $NOVAFABRIC_CAPSULE_DIR, or by path) and renders the evidence a creditor's compliance team uses to author an ECOA / Reg B adverse-action notice: the recorded model call(s) — model ref plus SHA-256 digests of the recorded request messages and response choices (the prompt and response text are never copied out); the capsule's inputs/ files, each checked against the capsule's sealed evidence_digests; the recorded facets.feature_attribution principal reasons in the order and with the rank recorded — never re-ranked, re-scored or computed; and whether the capsule carries a NovaSeal envelope (presence only — re-verify with nova verify). A capsule with no attribution facet reports principal_reasons as missing with the reason; NovaFabric does not infer reasons. Today that row is always missing on schema-valid capsules: feature_attribution is not yet in the closed run-capsule facet registry (ADR-0196 D2), and registering it is a schema change that needs its own ADR before any producer can write it. Every recorded string the pack renders — reason text, the attribution method / producer / model_call_id, and the model-call refs / status / timestamps — is length-capped (1024 chars) and scanned against the ADR-0009 secret rules; a match is suppressed (never rendered, listed in suppressed_fields) and its row marked partial. A reason's rank must be an integer and its contribution an integer or finite float; any other type (string, boolean, list) is corrupt evidence (exit 2), never rendered. It is evidence of what was recorded — not an adverse-action notice, not a credit decision, and not a legal verdict; the output carries the CFPB line that "the model decided" or a generic reason does not satisfy the specific-reasons duty. There is no notice text and no verdict field.

nova export-adverse-action --run-id 01KZ...
nova export-adverse-action --run-id 01KZ... --json
nova export-adverse-action --run-id 01KZ... --out aa-pack.json

Exit codes: 0 (rendered, including missing rows), 2 (capsule not found; a symlinked capsule.yaml / model-calls.jsonl; a file recorded in evidence_digests that is absent, a symlink, or not a regular file; a sealed digest that does not match the bytes on disk; malformed manifest, model-call line, or attribution facet; --out inside the capsule or unwritable).


nova export-cat --run-id <id>

Experimental (ADR-0159 D6 / NF-280). Reads one sealed Run Capsule (by run id, resolved in $NOVAFABRIC_CAPSULE_DIR, or by path) and renders a lifecycle-ordered, self-contained agent-event trail — lifecycle stage, recorded actor identity ref and recorded timestamps per event — as a firm-owned, self-hosted artifact modelled on the SEC Rule 613 (17 CFR 242.613) Consolidated Audit Trail event lifecycle. The stage mapping is explicit and nothing else is read:

Stage Capsule source Actor identity ref
origination capsule.yaml created_at none recorded at run level
decision model-calls.jsonl response (else request) model ref
authorization (optional) tool-permission-events.jsonl, human_approvals.jsonl authorising_identity (+ approval_principal) / approver_id
action tool-calls.jsonl tool_name (+ agent_call_id link)
disposition capsule.yaml finished_at + status none recorded at run level

Events are ordered by UTC-normalised recorded timestamp, ties broken by stage, stream and line; an event without a timestamp is kept (never given a guessed time), placed last, and its stage marked partial. A missing required stage makes the trail partial; authorization is reported but optional (a run whose policy needed no decision records none). No event is ever synthesised; prompt/response text, tool arguments/results and approval rationales never reach the trail. Every rendered recorded string is capped (1024 chars) and scanned against the ADR-0009 secret rules — a match is suppressed and the stage marked partial. It is not a CAT submission: no CAT technical-specification format, reporter id or event-type code; it never connects to the CAT central repository or a plan processor and transmits nothing.

nova export-cat --run-id 01KZ...
nova export-cat --run-id 01KZ... --json
nova export-cat --run-id 01KZ... --out cat-events.json

Exit codes: 0 (rendered, including missing / partial stages), 2 (capsule not found; a symlinked capsule file; a stream recorded in evidence_digests that is absent or not a regular file; a sealed digest that does not match the bytes on disk; a malformed manifest or event line; an over-long field; an unparseable or offset-less timestamp; --out inside the capsule or unwritable).


nova export-part11 <document>

Render a 21 CFR Part 11 electronic-records evidence artifact — the records/signatures elements a run recorded (signer identity, §11.50 signing intent, DSSE signature binding, record integrity, trusted timestamp, audit trail), each complete / partial / missing. Facts, never a Part 11 call.

nova export-part11 part11.json --json

nova export-rai-scorecard <document>

Render a Responsible-AI coverage scorecard — presence of evidence per dimension (supported / partial / unsupported / not_applicable), never a score: no threshold, no fair/unfair or pass/fail label.

nova export-rai-scorecard rai.json --json

nova export-public-annex-viii <document>

Render a DRAFT EU AI Act Annex VIII / Art. 71 public-database entry from sealed evidence + operator declarations. Each field is either capsule_evidence (a digest/ref into the sealed capsule — never the raw value) or operator_declared (the operator's public declaration).

nova export-public-annex-viii entry.json --json

nova export-transparency-register <document>

Render a DRAFT algorithm-register record from sealed evidence + operator declarations, crosswalked to a public register shape.

nova export-transparency-register reg.json --standard atrs
nova export-transparency-register reg.json --standard amsterdam --json

nova export-public-disclosure <document>

Render a DRAFT public-sector disclosure record from supplied references.

nova export-public-disclosure disclosure.json --json

nova export-foia <document>

Render a DRAFT FOIA/public-records decision export from a decision's ordered record index + redaction claims (each redaction a salted digest plus the claimed statutory exemption_ref).

nova export-foia foia.json --json

nova export-whistleblower <document>

Render a source-protecting whistleblower attestation over a sealed bundle.

nova export-whistleblower wb.json --json

nova export-citizen-explanation <document>

Render a plain-language, subject-facing decision explanation.

nova export-citizen-explanation cit.json --json

nova export-public-incident <document>

Render a DRAFT public-interest incident summary from a sealed incident.

nova export-public-incident incident.json --json

nova export-election-disclosure <document>

Render an election/democratic-process content-provenance disclosure — records, never judges. Binds a provenance receipt (e.g. NF-094 / C2PA / SynthID) by digest.

nova export-election-disclosure elec.json --json

nova export-accessibility-claim <document>

Render a declared accessibility-conformance claim — a declared claim, never a guarantee.

nova export-accessibility-claim a11y.json
nova export-accessibility-claim a11y.json --standard en_301_549_v4_1_1 --json

nova export-control-attestation <document>

Render a governance-control attestation pack — presents evidence, never certifies.

nova export-control-attestation ctrl.json --json

nova insurance

Risk-transfer evidence over facets.risk_transfer (ADR-0170 P2). experimental. Records evidence — it never assigns fault, decides coverage, adjudicates a claim, or pays out. Every output (rich or --json) carries the in-mission-boundary line: evidence supports, never determines, an insurance or legal outcome. Read-only unless --write is passed, which merges the recorded object into capsule.yaml after validating the whole facet (atomic replace; a symlinked capsule.yaml or capsule directory is refused). A NovaSeal-sealed capsule (.seal/ present) is refused with exit 2 unless --force-unseal is also passed, which writes anyway and warns that the existing seal no longer verifies and must be re-issued. The other sub-commands ADR-0170 names (features, loss bind, subrogation, insurability) are planned — not yet implemented.

nova insurance liability show --capsule <capsule>

NF-383 liability-attribution chain: ordered {role, party_ref, acted_as_ref, basis_ref, contribution_marker} — records who was attributed, never who is at fault. role ∈ principal | deployer | operator | vendor | model_provider | integrator | agent | third_party; contribution_marker ∈ recorded | disputed | none (recorded/disputed must name a basis_ref). References are sha256: digests; acted_as_ref must name another chain member (no dangling, self or cyclic edges); fault/verdict/payout-shaped keys are rejected.

nova insurance liability show --capsule 01HX...                          # read the recorded chain
nova insurance liability show --capsule 01HX... --chain chain.json --write

Options: --chain PATH (declared chain JSON — a list or {liability_chain: [...]}), --write (requires --chain), --json.

nova insurance sla verify --capsule <capsule> --sla <terms.json> --observed <decimal>

NF-384 SLA/warranty breach: compares the observed value to the declared commitment {metric, operator (lt|lte|gt|gte|eq), threshold, window, unit?} and records breach (the commitment did not hold) with both figures as exact decimals. sla_ref is the sha256 of the terms file. Numeric condition only — no remedy, service credit or damages; distinct from ADR-0146 cost showback.

nova insurance sla verify --capsule 01HX... --sla sla.json --observed 99.2 --evidence-ref sha256:<hex>

Options: --evidence-ref (repeatable sha256: digest), --write, --json.

nova insurance coverage check --capsule <capsule> --exclusions <set.json> --facts <facts.json> --event-kind <kind>

NF-386 exclusion-aware coverage trigger: records covered_event_kind, trigger_facts (digests), exclusion_set_ref (sha256 of the declared set, e.g. ISO CG 40 47), matched_exclusions (declared exclusions whose declared fact markers are present among the observed facts — possibly empty), and optional parametric_conditions (observed value vs declared parametric threshold; unobserved terms are recorded as not observed). It never decides whether the policy responds.

nova insurance coverage check --capsule 01HX... --exclusions cg4047.json --facts facts.json \
    --event-kind erroneous_output --json

--exclusions: {exclusions: [{exclusion_id, fact_markers[]}], parametric_triggers?: [{metric, operator, threshold, unit?}]}. --facts: {trigger_facts: [{fact_ref, marker}], observations?: {metric: value}}.

Exit codes (all three): 0 recorded — a breach or a matched exclusion is a recorded fact, not a failure; 2 input error — unknown capsule, unreadable/oversize (1 MiB cap)/malformed input, a non-finite figure (NaN/inf), a non-digest reference, or a determination-shaped field. JSON numbers in the input files are parsed as exact decimals.


Compliance commands — full reference

This section consolidates all compliance-related CLI surfaces. Commands are labeled per the docs honesty rule: works today, planned (implementation in progress or scheduled for v0.26.x), or future (ADR accepted, implementation not yet scheduled).

Already implemented — works today

Command Regulation Version
nova seal sign --intent <intent> FDA 21 CFR Part 11 §11.50 v0.12.15+
nova export-annex-iv <capsule_id> EU AI Act Annex IV (Reg. 2024/1689 Art. 11) v0.15.0
nova export-nis2 <capsule_id> NIS2 Directive Art. 23 (Phase 1/2/3) v0.15.0
nova subject-proof <subject_id> GDPR Art.17 HMAC subject lookup v0.15.0
nova audit coverage Multi-profile control coverage scoring v0.16.0
nova audit bundle ZIP export of full audit report v0.16.0
nova audit verify AuditReport schema validation v0.16.0
nova classify run EU AI Act / NIST RMF / OMB M-24-10 risk tier v0.16.0
nova verify <capsule> DSSE + RFC 3161 TSR + Merkle log verification v0.10.0+
nova export-ropa <capsule_id> GDPR Art.30 Records of Processing Activities (cap-007) v0.25.1
nova export-aibom <capsule_dir> CycloneDX 1.7 AI-SBOM / ML-BOM (cap-008); default output aibom.json v0.25.1
nova aibom status CRA SBOM compliance status: deadline 2026-09-11, format, per-capsule coverage v0.35.0
nova aibom generate [--all] [--force] Per-deployment automation: generate/refresh aibom.json for one or all capsules v0.45.0
nova export-nist-rmf <capsule_id> NIST AI RMF 1.0 quantitative risk report (cap-009) v0.25.1
nova assure <capsule_id> OWASP LLM Top 10 (2025) evidence checks — exit 1 on failure (E-10) v0.25.1
nova mcp scan <manifest> OWASP LLM supply-chain risk scanner for MCP manifests (E-9) v0.25.1

nova seal sign --intent <intent>

Sign a capsule with a declared signing intent per FDA 21 CFR Part 11 §11.50.

nova seal propose <capsule-id> \
  --key signer.pem \
  --cert signer_cert.pem \
  --justification "FDA §11.50 review approved — all eval gates green"

Signing intents are expressed via the SigningIntent enum (src/novafabric/trust/novaseal/envelope.py):

Intent Meaning (FDA §11.50 mapping)
approved Approval signature (§11.50(a)(1))
reviewed Review signature (§11.50(a)(2))
authored Authorship signature (§11.50(a)(3))
witnessed Witnessed signature
verified Verification / QA signature

The intent value is embedded in the DSSE predicate and verified by nova seal verify. The five-check SoD verifier (exit codes 3–7) enforces the separation-of-duties required by FDA §11.50(b).

nova seal sign --backend sigstore

works today — Keyless Sigstore signing (ADR-0071, v0.44.0). Produces a Sigstore Bundle v0.3 using an ephemeral OIDC-bound certificate and Rekor v2 transparency log inclusion. Requires pip install novafabric[sigstore].

nova seal sign --backend sigstore --capsule-id 01HX...
nova seal sign --backend sigstore --capsule-id 01HX... --home /data/nova

Options:

Bundles stored at $NOVAFABRIC_HOME/sigstore/<capsule_id>.bundle.json. Verify with nova verify --backend sigstore --capsule-id <id>.

Note: The sigstore SDK performs OIDC browser-based or ambient identity (GitHub Actions, GCP, AWS) credential lookup at sign time. Not suitable for air-gapped HPC environments (use --backend local with RFC 3161 instead).


nova pii erase <subject_id>

works today — GDPR Art.17 crypto-shredding erasure (ADR-0069, v0.44.0). Destroys the AES-256-GCM DEK for a data subject, rendering all PII encrypted under that DEK permanently unreadable. Writes an ErasureReceipt (immediate) or ErasureDeferredReceipt (Art.17(3)(b) retention window still active).

nova pii erase "user@example.com"
nova pii erase "user@example.com" --output receipt.json
nova pii erase "user@example.com" --retention-months 6

Options:

Exit codes: 0 (receipt written), 1 (subject not found or error).

Scope: single data subject. Requires DEK store at $NOVAFABRIC_HOME/dek.db.

nova pii status <capsule_id>

works today — Show PII encryption status for a capsule — which fields are encrypted, which subjects have active DEKs, and which have been erased (crypto-shredded, ADR-0069). Read-only and local-first: correlates the capsule's redaction_manifest.json against the DEK store at $NOVAFABRIC_HOME/dek.db without creating or modifying either. Subjects appear only as HMACs — no key material or plaintext PII is ever shown.

nova pii status 01HXAMPLECAPSULEID                  # resolve by capsule ID
nova pii status .novafabric/runs/01HX.../           # or by capsule directory path
nova pii status 01HXAMPLECAPSULEID --json           # machine-readable PIIStatusReport
NOVA_PII_PEPPER=secret nova pii status 01HX...      # pepper enables DEK correlation

Options:

Per-subject dek_state:

Exit codes: 0 (report produced — including capsules with no redaction manifest), 1 (capsule not found or manifest unreadable).

Scope: single capsule. Works without a DEK store and without NOVA_PII_PEPPER (degrades honestly as above).

nova export-rocrate <capsule_dir>

Export a Run Capsule as a FAIR-compliant RO-Crate v1.1 research object (ZIP archive).

works today — implemented in v0.32.0.

nova export-rocrate .novafabric/runs/01HX.../
nova export-rocrate .novafabric/runs/01HX.../ --output ./out.rocrate.zip

Options:

nova export-rocrate-science --capsule <capsule>

Export a science capsule as a FAIR Workflow-Run-RO-Crate science profile (ADR-0164 NF-324).

experimental — ADR-0164 P2. Composes over the nova export-rocrate carrier (NF-040): the carrier's RO-Crate 1.1 file set is kept, and the Workflow Run Crate 0.5 entities are added — a W3C-PROV-aligned CreateAction, the reproducibility-receipt digests and seeds as PropertyValues, the hypothesis→claim DAG (with isBasedOn parent edges), and the sealed science root as an identifier. Byte-deterministic when the capsule carries a timestamp.

nova export-rocrate-science --capsule .novafabric/runs/01HX.../ --out ./crates
nova export-rocrate-science --capsule 01HX... --orcid 0000-0002-1825-0097 --ror 03yrm5c26 --json

Writes <run_id>.science.rocrate.zip and <run_id>.fair-binding.json (the NF-324 fair_binding record: profile URIs, rocrate_digest, prov_alignment: "w3c-prov", sealed_root, receipt_root, persistent identifiers, unbound, verdict: null).

Options:

Exit codes: 0 exported; 1 refused — no science_provenance facet, a tampered receipt, a workflow profile with no declared workflow, or a malformed DAG; 2 usage error. Every output carries the in-mission-boundary line: NovaFabric records and exports provenance; it never runs experiments or adjudicates scientific validity.

nova science receipt build|verify --capsule <capsule>

Computational-reproducibility receipt (ADR-0164 NF-323). experimental — ADR-0164 P2.

build binds the environment digest, seed(s), input-data digest, code digest and optional workflow digest — plus the declared determinism_class and, when the science facet records one, the sealed capsule root — under one bound_root. Components not supplied are named in receipt_incomplete, never fabricated. verify recomputes the root offline and checks the declared incompleteness. Record-only: nothing is re-executed and reproducible_in_fact is always null.

nova science receipt build --capsule 01HX... --env sha256:<hex> --data sha256:<hex> \
    --code sha256:<hex> --seed 1337 --seed 42 --determinism statistical --write
nova science receipt verify --capsule 01HX... [--strict] [--json]

build options: --env, --data, --code, --workflow (each sha256:<64 hex>), --seed INT (repeatable, ordered), --determinism bitwise|statistical|nondeterministic|undeclared, --write (persist into capsule.yaml under facets.science_provenance.reproducibility_receipt; atomic replace, symlinked capsule.yaml refused), --force-unseal (with --write: rewrite a NovaSeal-sealed capsule — refused with exit 2 otherwise — and warn that its seal no longer verifies and must be re-issued), --json.

Exit codes: 0 ok; 1 (verify) root mismatch, misreported incompleteness, malformed or absent receipt — or --strict with an incomplete receipt; 2 usage error (unknown capsule, malformed digest or seed).

nova science lab show|verify --capsule <capsule>

Declared lab-experiment provenance (ADR-0164 NF-322). experimental — ADR-0164 P3.

nova science lab show prints facets.science_provenance.lab_experiment — lab_kind (self_driving | cloud_lab | manual | simulation), protocol_ref, instrument_refs, run_id, sim_to_real (sim | real | hybrid), outcome_digest, optional started_at / node_ref — and how many instrument records the capsule carries. nova science lab verify checks offline, and fails closed, that: every instrument_ref resolves to an instrument record; no referenced instrument was calibrated after the experiment (experiment time is started_at, else the capsule's created_at; unknown fails); the experiment and instrument digests re-derive; a simulation is not declared real; and an optional node_ref names an experiment_design / experiment_run node of the NF-321 lineage. Declarations only — NovaFabric never dispatches to or controls a lab and never reads instrument telemetry (controls_lab: false, reads_telemetry: false, verdict: null).

nova science lab show --capsule 01HX... [--json]
nova science lab verify --capsule 01HX... [--json]

The blocks are written by the library API (novafabric.science.lab.build_lab_experiment, build_instrument_record, attach_lab); there is no build subcommand.

Exit codes: 0 ok; 1 (verify) a failed check or an absent block — and for every subcommand a malformed block (unknown lab_kind, malformed digest, a telemetry / raw-data / credential-shaped field); 2 usage error (unknown capsule).

nova science instrument show --capsule <capsule>

Declared instrument / calibration provenance (ADR-0164 NF-329). experimental — ADR-0164 P3.

Prints each facets.science_provenance.instrument_provenance[] record — instrument_id, instrument_class, firmware_digest, calibration_ref (digest of the calibration record, never the record), calibration_timestamp, manufacturer_ref, and the record_digest a lab experiment's instrument_refs point at. Add --json for machine output. Exit 0 shown (or none recorded); 1 malformed block; 2 unknown capsule.

nova lineage export-prov <capsule_dir>

Export a W3C PROV provenance graph from a capsule's lineage.jsonl, as PROV-JSON (default) or PROV-N text — both serializations of the same graph.

works today — PROV-JSON since v0.32.0; PROV-N added (ADR-0176).

nova lineage export-prov .novafabric/runs/01HX.../
nova lineage export-prov .novafabric/runs/01HX.../ --output prov.json
nova lineage export-prov .novafabric/runs/01HX.../ --format prov-n -o prov.provn

Options:

nova export-hipaa-proof <capsule_dir>

works today — Export a HIPAA Safe Harbor (§164.514(b)) de-identification proof artifact for a capsule, documenting which of the 18 identifier categories were absent, redacted, or not assessable from available capsule evidence files.

DISCLAIMER: This is a technical evidence artifact only. It is NOT legal advice, NOT a compliance certification, and does NOT guarantee Safe Harbor legal sufficiency.

nova export-hipaa-proof .novafabric/runs/01HX.../                           # writes hipaa-proof.json in capsule dir
nova export-hipaa-proof .novafabric/runs/01HX.../ --output hipaa-proof.json

Options:

nova export-aibom <capsule_dir>

Export an AI Bill of Materials (AIBOM) using CycloneDX ML-BOM 1.7 (ECMA-424 2nd Edition). Required for EU Cyber Resilience Act (CRA) compliance. Deadline: 2026-09-11 (ADR-0073).

works today — implemented in v0.25.1; --output default + nova aibom status added v0.35.0; nova aibom generate (per-deployment automation) added 2026-06-04.

nova export-aibom .novafabric/runs/01HX.../            # writes aibom.json in the capsule dir
nova export-aibom .novafabric/runs/01HX.../ --output /tmp/aibom.cdx.json
nova aibom status                                       # show deadline + per-capsule coverage
nova aibom status --capsules-dir ~/novafabric-data/capsules
nova aibom generate .novafabric/runs/01HX.../          # generate one (skips if present)
nova aibom generate --all                              # batch: every capsule missing an aibom.json
nova aibom generate --all --force                      # batch: refresh all (overwrite)
# NF-056 CycloneDX 1.7 extensions (opt-in; default output unchanged):
nova aibom generate <cap> --citations --force          # bind components to capsule/evidence digests
nova aibom generate <cap> --tlp TLP:AMBER --force      # distribution marker in metadata.properties
nova aibom generate <cap> --model-card auto --force    # model-card externalReference per model
nova aibom generate <cap> --no-include-datasets --force # suppress type:data components
nova aibom validate <cap>/aibom.json                   # structural + binding check (exit 1 on error)

Options (nova export-aibom):

Options (nova aibom status):

Options (nova aibom generate) — per-deployment automation (CRA):

Options (nova aibom validate <bom.json>) — NF-056: structural CycloneDX 1.7 + NovaFabric-binding check (specVersion/bomFormat/serialNumber, TLP marker validity, per-component name/bom-ref/hash-alg/citation digest). Exit 0 valid, 1 on validation errors, 2 on a missing/malformed file. --json emits {valid, errors}.

nova dataset provenance-card <asset> (experimental)

Experimental — NF-058, ADR-0105. Emit (and optionally sign) a dataset provenance card recording a dataset's source, version, content hash, and transform history. Feeds the AI-BOM (NF-056) and the SLSA-for-ML attestation (NF-057). Op digests only — never raw values, prompts, or cell contents.

nova dataset provenance-card dataset:gaia@2026-05 \
    --source oci://reg/gaia:2026-05 --version 2026-05 --hash b17a... \
    --license CC-BY-4.0 --tlp TLP:CLEAR --registry-digest b17a... --sign
# pull the transform history from a capsule's lineage derivation edges:
nova dataset provenance-card dataset:x@1 --source oci://x --version 1 --hash <sha256> \
    --from-capsule ./my-capsule --sign --out card.json

nova export-c2pa <capsule_dir>

Export a C2PA v2.3-compatible provenance manifest for AI-generated content (ADR-0074). Required by EU AI Act Art.50. Deadline: 2026-08-02.

works today — implemented in v0.33.0.

nova export-c2pa .novafabric/runs/01HX.../
nova export-c2pa .novafabric/runs/01HX.../ --output manifest.json
nova export-c2pa .novafabric/runs/01HX.../ --training-mining   # adds notAllowed assertion

Options:

Note: the manifest is structurally valid for TSP signing. Hard-binding C2PA verification requires operator enrollment with a C2PA-certified Trust Service Provider (TSP signing path deferred to a future release).

nova export-compliance <subcommand>

Export EU AI Act / ISO / NIST compliance evidence from the ADR-0107 exporters. Each subcommand reads a capsule or a JSON input and writes a report as JSON (to --out, else stdout). The CLI only parses and serialises — the exporter logic lives in novafabric.compliance.export.

works today — implemented in v0.89.0 (experimental).

# NIST GenAI + CSA Agentic profile, built from a capsule's NIST-RMF report (NF-097)
nova export-compliance genai-profile .novafabric/runs/01HX.../ --evidence tool_permissions,eval_gate --out profile.json

# ISO/IEC 42001 control-evidence mapping from a declared catalog (NF-095)
nova export-compliance iso42001 --catalog controls.json --evidence eval_gate --capsule-id run-123 --out iso.json

# First sealed revision of a GPAI Art. 53 documentation form (NF-093)
nova export-compliance gpai53 --model my-gpai --fields art53.json --out form.json

# Art. 72 post-market-monitoring report; serious findings refer Art. 73 incidents (NF-091)
nova export-compliance pmm --system triage --findings findings.json --occurred-at 2026-07-01 --out pmm.json

Subcommands and key options:

Note: NF-090 (Art. 12) is served by nova euaiact; NF-092 (Annex IV) by the AIBOM/Annex-IV exporters; NF-094 (Art. 50 dual-layer receipt) composes with nova export-c2pa.

nova export-system-card <capsule_dir>

Generate and seal an auto-generated system/audit card (ADR-0085). The card is assembled from capsule + eval + lineage facts (capsule.yaml, eval_result.json, lineage.jsonl) and sealed by reusing the existing DSSE/Ed25519 signing path — no new crypto. It is generated, never hand-written, so it cannot drift from the capsule it describes. The sealed output is a DSSE envelope (predicate type https://novafabric.io/system-card/v0) that verifies with the same verifier used for Evidence Bundles.

works today — implemented in v0.48.0.

nova export-system-card .novafabric/runs/01HX.../
nova export-system-card .novafabric/runs/01HX.../ -o card.intoto.json --key ed25519.pem

Options:

Related: eval results now also pin the asset version and an optional dataset version (nova eval-driven run_evals, ADR-0085) so a stored eval result can be tied back to exactly what was measured.

nova export-blob --dest <uri>

Export a batch of capsules to blob storage with one signed, verifiable completeness manifest (ADR-0141, spec batch-blob-export-v0). Members are selected explicitly (--capsule, repeatable) or by scanning the capsule directory with an optional created_at time range (--since/--until, inclusive); the selection is frozen at export start (a batch is a snapshot). Each member is packed deterministically and written content-addressed under objects/<sha256> at the destination — already-present blobs are skipped, so re-runs are idempotent and an interrupted export resumes. The Ed25519/DSSE-signed export-manifest.json (validates against schemas/export-manifest.schema.json) is written last as the atomic completion marker: it lists every member's capsule_id, content_hash, and size, plus a batch_digest over the sorted member list, so a recipient can verify integrity and completeness offline. Source capsules are never modified.

experimental — implemented; API may change.

# Local directory (always works, fully offline)
nova export-blob --dest ./exports/audit-q3 -c 01HX... -c 01HY...

# Time-range scan of the capsule store
nova export-blob --dest ./exports/w27 --since 2026-06-29 --until 2026-07-05

# Query filter (ADR-0129 DSL) — composes with the time window
nova export-blob --dest ./exports/gpt4o --query "model = 'gpt-4o'"
nova export-blob --dest ./exports/failures \
  --query "status = 'error'" --since 2026-07-01

# Any S3-compatible endpoint (existing optional boto3 adapter; private endpoints OK)
NOVA_S3_ENDPOINT_URL=https://s3.internal nova export-blob \
  --dest s3://audit-bucket/exports/2026-07/ --worm --worm-retention-days 2555

Options:

Verify offline (no NovaFabric service; extends nova verify):

nova verify export-manifest.json --public-key export.pub.pem
nova verify manifest.json --public-key pub.pem --dest s3://audit-bucket/exports/2026-07/

Verdicts: VALID (signature + batch digest + every member's bytes at the destination check out), INCOMPLETE (a member missing, or size/hash mismatch — e.g. a deleted or tampered blob), INVALID (bad signature, count, or batch digest — e.g. a member quietly dropped from the manifest). Exit 0 only on VALID.

nova import <source>

Import a batch export (nova export-blob) into the local capsule store — the verified inverse of the export (ADR-0207, spec batch-import-v0). <source> is either a directory containing export-manifest.json + objects/, or a single .tar/.tar.gz archive of that layout (the air-gap courier format).

Verification-first, fail-closed: before any byte enters the store the manifest must verify (VALID — DSSE signature via the supplied public key, count/batch_digest consistency, and every member's bytes re-hashed). INVALID or INCOMPLETE refuses the whole import. Unpacking is hardened against hostile archives (absolute paths, .., links, devices — refused) and staged: members extract to a scratch directory and are atomically renamed into place, so a crash never leaves a half-written capsule. After unpack, lineage (lineage.jsonl → lineage store) and the dashboard runs_cache are reindexed (the offline query index self-scans and needs no rebuild). Every run — including refusals and dry runs — writes an import receipt JSON under $NOVAFABRIC_HOME/import-receipts/<import_id>.json and one hash-chained audit entry (capsule.import).

Idempotent by content address: a member whose run_id already exists locally with byte-identical content (same deterministic re-pack hash) is skipped, so re-running an import is a no-op and an interrupted import resumes. Collisions are never overwritten: same run_id with different local content is reported per-member with both hashes (exit 5); delete the local capsule with existing retention tooling and re-import to replace it — there is deliberately no --force.

experimental — implemented (ADR-0207 P1); API may change.

# Verified import (the normal path; key from `nova export-blob --public-key-out`)
nova import ./exports/audit-q3 --public-key export.pub.pem

# DR drill: verify + classify with zero writes, same exit codes
nova import ./exports/audit-q3 --public-key export.pub.pem --dry-run

# Air-gap courier archive
nova import batch.tar.gz --public-key export.pub.pem

# Machine-readable report
nova import ./exports/audit-q3 --public-key export.pub.pem --json

Options:

Exit codes: 0 success (imported / already present), 2 usage error, 3 verification INVALID (structure, signature, digest), 4 verification INCOMPLETE (member missing / hash or size mismatch), 5 collision(s), 6 member(s) failed during unpack. Nothing is imported on 3/4; non-colliding members still import on 5.

nova euaiact export

Export structured EU AI Act Art.12 log events for authority access requests (Art.74). Binding for high-risk AI systems: 2026-08-02 (ADR-0076).

works today — implemented in v0.33.0.

nova euaiact export --from 2026-01-01 --to 2026-06-30 --output euaiact-report.json
NOVA_EUAIACT_HIGH_RISK=true nova euaiact export --from 2026-01-01
nova euaiact export --pretty    # Rich table output to terminal
nova euaiact status             # show active configuration

Options:

Environment:


Governance commands (v0.16)

nova classify run

Classify an AI system's risk tier against EU AI Act Annex III, NIST AI RMF, and OMB M-24-10.

nova classify run --system system.yaml
nova classify run --system system.yaml --vocabulary nist-ai-rmf/1.0.0
nova classify run --system system.yaml --format json

Options:

Exit codes: 0 = classified; 1 = prohibited tier detected.

AISystemRecord fields: name, description, use_cases (list of strings), deployment_context, data_subjects (list), automated_decision_making (bool), biometric_processing (bool), critical_infrastructure (bool).

nova classify list-vocabularies

List all available classification vocabularies.

nova classify list-vocabularies

nova classify from-capsule

Infer an AI system record from a captured run capsule and classify it.

nova classify from-capsule .novafabric/runs/01HXAY7M/

Reference: src/novafabric/governance/, src/novafabric/cli/classify.py, ADR-0056.


Compliance audit commands (v0.16)

nova audit map

List all evidence checkers for a compliance profile.

nova audit map --profile nist-ai-rmf
nova audit map --profile eu-ai-act-high-risk
nova audit map --profile gdpr

Available profiles: nist-ai-rmf, eu-ai-act-high-risk, gdpr, soc2-type2, iso42001, scientific-reproducibility.

nova audit report

Run a compliance audit against a capsule and print the result.

nova audit report --capsule .novafabric/runs/01HXAY7M/ --profile nist-ai-rmf
nova audit report --capsule .novafabric/runs/01HXAY7M/ --profile gdpr --format json

Options:

nova audit verify

Assert that a capsule meets a minimum compliance coverage threshold. Exits 1 if the coverage is below the threshold.

nova audit verify --capsule .novafabric/runs/01HXAY7M/ --profile nist-ai-rmf --min-coverage 0.8

Options:

nova audit bundle

Export a signed audit bundle (ZIP) containing the compliance report and evidence artifacts.

nova audit bundle --capsule .novafabric/runs/01HXAY7M/ --profile eu-ai-act-high-risk --output audit.zip

nova audit coverage

Print a numeric coverage summary for all profiles against a capsule.

nova audit coverage --capsule .novafabric/runs/01HXAY7M/

Reference: src/novafabric/compliance/audit/, src/novafabric/cli/audit.py.


Examiner exporter commands (v0.16)

nova export-examiner bagit

Export a capsule as a RFC 8493 BagIt archive with SHA-256 checksums.

nova export-examiner bagit .novafabric/runs/01HXAY7M/ --output run.bagit.zip

Output: BagIt ZIP containing bagit.txt, bag-info.txt, manifest-sha256.txt, and the full capsule payload under data/.

nova export-examiner pccp

Export a capsule as an FDA 21 CFR Part 11 PCCP (Predetermined Change Control Plan) package.

nova export-examiner pccp .novafabric/runs/01HXAY7M/ --output pccp.zip
nova export-examiner pccp .novafabric/runs/01HXAY7M/ --output pccp.zip --format json

Output: ZIP containing protocol document, change manifest, training documentation, and validation records.

nova export-examiner iso42001

Export a capsule as an ISO/IEC 42001 AI Management System package.

nova export-examiner iso42001 .novafabric/runs/01HXAY7M/ --output iso42001.zip

Output: ZIP containing system profile, risk register, monitoring plan, and improvement log.

Reference: src/novafabric/compliance/export/examiner.py, src/novafabric/cli/export_examiner.py.