Compliance and audit export commands
Part of the NovaFabric CLI reference. Both nova and novafabric run the same binary.
Compliance evidence commands (v0.15.0, BQ-005)
These commands require pip install 'novafabric[compliance]' for full functionality.
OQ-01 status (corrected):
nova subject-proof(below) remains LEGAL-HOLD DRAFT MODE — it looks up an existing redaction proof; PII stays in alegal_hold/staging area, not sealed capsules. The DEK-based crypto-shredding strategy this note used to describe as "planned for v0.26.x" has since shipped (ADR-0069, v0.44.0) asnova pii erasebelow, which actually destroys the wrapping DEK for a data subject rather than only staging a proof. Corrected 2026-09-02: this sentence also namednova erasure request, which never destroyed anything — it printed a success message and did nothing, and now fails loudly.
nova export-annex-iv <capsule> --output-dir <dir> --deployment-id <id>
Export EU AI Act Annex IV technical documentation from a Run Capsule (Regulation (EU) 2024/1689 Art. 11). Produces a JSON-LD file covering all 15 mandatory Annex IV elements, with an optional PDF.
nova export-annex-iv .novafabric/runs/01HX.../ \
--output-dir ./compliance/ \
--deployment-id "prod-eu-classifier-v2"
nova export-annex-iv <capsule> \
--output-dir ./compliance/ \
--deployment-id "prod-eu-classifier-v2" \
--pdf # requires weasyprintOptions:
--output-dir, -o PATH(required) — directory to writeannex-iv-<deployment_id>.jsonld--deployment-id TEXT(required) — operator-assigned deployment identifier--pdf / --no-pdf— also render a PDF (requiresweasyprint, included innovafabric[compliance])
Output fields include: system description, intended purpose, training data characteristics, human oversight measures, robustness metrics, and post-market monitoring plan. Fields are marked complete, partial, or missing based on capsule content, and each element carries an evidence_source provenance marker (ADR-0197).
Exit codes: 0 (success), 1 (missing compliance extra or export error).
nova export-nis2 <capsule> --output <file> --incident-id <id>
Export a NIS2 incident report (Directive (EU) 2022/2555 Art. 23) from a Run Capsule.
nova export-nis2 .novafabric/runs/01HX.../ \
--output incident-report.json \
--incident-id "INC-2026-0042" \
--phase 1 # initial report (≤24h, default)
nova export-nis2 <capsule> --output report.json --incident-id INC-001 --phase 2 # ≤72h
nova export-nis2 <capsule> --output report.json --incident-id INC-001 --phase 3 # ≤1 monthOptions:
--output, -o PATH(required) — path to write the NIS2 incident report JSON--incident-id TEXT(required) — operator-assigned incident identifier--phase INT— reporting phase:1(initial, ≤24h),2(detailed, ≤72h),3(final, ≤1 month). Default:1
Fields requiring cross-session lineage (cap-006) are explicitly marked missing with reason requires_cap_006_cross_session_lineage.
Exit codes: 0 (success), 1 (missing compliance extra or export error).
nova export-ropa <capsule> --output <file>
Export a GDPR Art.30 Records of Processing Activities (RoPA) entry from a Run Capsule (cap-007).
nova export-ropa .novafabric/runs/01HX.../ --output ropa-entry.json
nova export-ropa .novafabric/runs/01HX.../ \
--output ropa.json \
--controller-name "Acme Corp" \
--controller-contact "dpo@acme.example"Options:
--output, -o PATH(required) — path to write the RoPA JSON-LD document--controller-name TEXT— GDPR Art.30(1)(a) controller name (operator-declared; marked missing if omitted)--controller-contact TEXT— controller contact / DPO email
Output is a JSON-LD document with gdpr: and nova: namespaces. Fields derivable from
capsule metadata are populated automatically; operator-declared fields are stubs with
missing_fields markers. Use --controller-name / --controller-contact to complete the entry.
Exit codes: 0 (success), 1 (export error).
nova export-nist-rmf <capsule> --output <file>
Export a NIST AI RMF 1.0 quantitative risk assessment report from a Run Capsule (cap-009).
nova export-nist-rmf .novafabric/runs/01HX.../ --output nist-rmf.jsonOptions:
--output, -o PATH(required) — path to write the NIST AI RMF JSON report
Derives scores for all four NIST AI RMF Core functions:
- GOVERN (GV-1.1 policy coverage, GV-1.2 evidence signing)
- MAP (MP-2.1 tool permission observability, MP-2.2 capture level adequacy)
- MEASURE (MS-2.5 eval performance score, MS-2.6 regression detection)
- MANAGE (MG-2.2 PII redaction rate, MG-4.1 lifecycle management score)
risk_level = low|medium|high|critical based on overall score and non-compliant metric count.
completeness = complete|partial based on whether all expected evidence files are present.
Exit codes: 0 (success), 1 (export error).
nova subject-proof <subject-id>
Look up PII redaction proof for a data subject (GDPR Art.17). HMACs the subject ID with NOVA_PII_PEPPER, queries the RedactionSubjectIndex, and returns a redaction_proof_report.json.
Requires:
NOVA_PII_PEPPERenvironment variable (the same pepper value used during capture). This command will exit 1 if the env var is not set.
NOVA_PII_PEPPER="<secret>" nova subject-proof "user@example.com"
NOVA_PII_PEPPER="<secret>" nova subject-proof "user@example.com" \
--output proof.json \
--key ~/.novafabric/keys/ed25519.pemOptions:
<subject-id>(positional, required) — data-subject identifier (email, phone, GDPR subject ID, etc.)--db PATH— path toredaction_subject_idx.db(default:$NOVAFABRIC_HOME/compliance/redaction_subject_idx.db)--key PATH— ed25519 private key for signing the proof report--output, -o PATH— path to writeredaction_proof_report.json(default: stdout)
Exit codes: 0 (subject found), 1 (env var missing, compliance extra missing, or DB error).
Sector and transparency export commands (experimental)
Thirteen read-only renderers that project supplied references and sealed evidence into sector-specific disclosure and attestation artifacts. Shared conventions:
- each command takes one positional JSON document path and supports
--jsonfor a machine-readable artifact; - exit codes are
0(artifact rendered) and2(missing or malformed input) — rendering never mutates a capsule; - outputs are evidence artifacts, not judgments: register/database entries
are explicitly
DRAFT, claims are declared claims, and the scorecard is coverage — the commands never certify, score, or judge compliance.
| Command | Framework / audience | ADR |
|---|---|---|
nova export-compliance |
EU AI Act / ISO 42001 / NIST GenAI + CSA exporters | ADR-0107 |
nova export-model-risk |
SR 26-2 / SR 11-7 model-risk evidence | ADR-0159 |
nova export-model-independence |
Model-validation independence (ADR-0058 maker-checker) | ADR-0159 |
nova export-retention |
SEC 17a-4 / MiFID retention posture + RFC 3161 timestamp | ADR-0159 |
nova export-adverse-action |
ECOA / Reg B specific-reasons evidence (not a notice) | ADR-0159 |
nova export-cat |
CAT-style lifecycle agent-event trail (SEC Rule 613 pattern; not a CAT submission) | ADR-0159 |
nova export-part11 |
21 CFR Part 11 electronic records | ADR-0160 |
nova export-rai-scorecard |
Responsible-AI coverage scorecard | ADR-0158 |
nova export-public-annex-viii |
EU AI Act Annex VIII public DB (DRAFT) | ADR-0169 |
nova export-transparency-register |
Algorithm registers: ATRS / Amsterdam / Helsinki (DRAFT) | ADR-0169 |
nova export-public-disclosure |
Public-sector disclosure record (DRAFT) | ADR-0169 |
nova export-foia |
FOIA / public-records decision export (DRAFT) | ADR-0169 |
nova export-whistleblower |
Source-protecting whistleblower attestation | ADR-0169 |
nova export-citizen-explanation |
Subject-facing decision explanation | ADR-0169 |
nova export-public-incident |
Public-interest incident summary (DRAFT) | ADR-0169 |
nova export-election-disclosure |
Election / civic content-provenance disclosure | ADR-0169 |
nova export-accessibility-claim |
Declared accessibility-conformance claim | ADR-0169 |
nova export-control-attestation |
Governance-control attestation pack | ADR-0170 |
nova insurance |
Liability chain / SLA breach / coverage trigger evidence (experimental) | ADR-0170 |
nova export-model-risk <evidence>
Assemble an SR 26-2 / SR 11-7 model-risk evidence file from per-pillar refs.
nova export-model-risk evidence.json --json<evidence>— JSON:{model_id, development[], independent_validation[], ongoing_monitoring[], model_inventory[], partial[]}
nova export-model-independence --model <id>
Experimental (ADR-0159 D2 / NF-276). Unlike the document-driven renderers
above, this command reads the shipped ADR-0058 maker-checker records itself —
the registry promotion_proposals rows written by nova promote propose /
nova promote approve (opened read-only), plus, per --capsule-id, the NovaSeal
DSSE bundles written by nova seal propose / nova seal approve, whose outcome is
taken verbatim from the shipped verify_sod verifier. It renders whether the
validator (checker) identity differs from the developer (maker) identity.
It asserts only that independence was recorded — never that validation was
sufficient, and never a rating. A single-identity approval is missing with
reason single-identity approval; an open proposal, a bypass, or a record that
failed SoD verification is missing with its reason. The single-sign-off
nova approve table is not read (it records no developer identity).
nova export-model-independence --model credit-scorer@2.1
nova export-model-independence --model credit-scorer --capsule-id <capsule-id> --json--model— asset id,nameorname@version(required)--capsule-id— also read the NovaSeal maker-checker bundle for this capsule (repeatable)--db— registry database (default$NOVAFABRIC_DB_PATHor$NOVAFABRIC_HOME/registry.db)--data-dir,--policy-db— NovaSeal bundle directory and policy DB (defaults asnova seal)--json— machine-readable artifact
Exit codes: 0 (rendered, including missing fields), 2 (unreadable registry or malformed model id).
nova export-retention --bundle <zip>
Experimental (ADR-0159 D5 / NF-277). Attests the retention posture over one
or more Evidence Bundles — the registry retention-policy.yaml window and deletion
mode, the holds.jsonl legal-hold state, each run's WORM lock (local adapter
worm.db, reported partial because it is dev/test only, or an S3 / Azure / GCS
WormReceipt supplied via --worm-receipts), the RFC 3161 trusted timestamp as
actually recorded in each bundle by nova export-evidence --timestamp (reported
complete when the TSR is present and bound to the manifest digest; missing
with the reason only when none was obtained), and the hash-chained audit-log
entries for the run. It attests posture, never compliance, and makes nothing
immutable. The TSR's TSA signature is not re-verified here — use
openssl ts -verify as the bundle README describes.
nova export-retention --bundle evidence.zip --registry prod
nova export-retention --bundle a.zip --bundle b.zip --regime mifid --json--bundle— Evidence Bundle ZIP (repeatable, required)--regime—17a-4(default;17 CFR 240.17a-4 (2022 amendment)) ormifid— a version-pinned tag, not a determination--registry— read.novafabric/registries/<name>/{retention-policy.yaml,holds.jsonl,worm.db}--worm-db,--worm-receipts,--audit-log— override the WORM DB, supply cloud WORM receipts, override the audit log
Exit codes: 0 (rendered, including missing rows), 2 (unreadable/corrupt bundle, policy, hold ledger, WORM DB or receipts).
nova export-adverse-action --run-id <id>
Experimental (ADR-0159 D6 / NF-278). Reads one sealed Run Capsule (by run id,
resolved in $NOVAFABRIC_CAPSULE_DIR, or by path) and renders the evidence a
creditor's compliance team uses to author an ECOA / Reg B adverse-action notice:
the recorded model call(s) — model ref plus SHA-256 digests of the recorded
request messages and response choices (the prompt and response text are never
copied out); the capsule's inputs/ files, each checked against the capsule's
sealed evidence_digests; the recorded facets.feature_attribution principal
reasons in the order and with the rank recorded — never re-ranked, re-scored or
computed; and whether the capsule carries a NovaSeal envelope (presence only —
re-verify with nova verify). A capsule with no attribution facet reports
principal_reasons as missing with the reason; NovaFabric does not infer
reasons. Today that row is always missing on schema-valid capsules:
feature_attribution is not yet in the closed run-capsule facet registry
(ADR-0196 D2), and registering it is a schema change that needs its own ADR
before any producer can write it. Every recorded string the pack renders — reason
text, the attribution method / producer / model_call_id, and the model-call
refs / status / timestamps — is length-capped (1024 chars) and scanned against the
ADR-0009 secret rules; a match is suppressed (never rendered, listed in
suppressed_fields) and its row marked partial. A reason's rank must be an
integer and its contribution an integer or finite float; any other type (string,
boolean, list) is corrupt evidence (exit 2), never rendered. It is evidence of what was recorded — not an
adverse-action notice, not a credit decision, and not a legal verdict; the
output carries the CFPB line that "the model decided" or a generic reason does not
satisfy the specific-reasons duty. There is no notice text and no verdict field.
nova export-adverse-action --run-id 01KZ...
nova export-adverse-action --run-id 01KZ... --json
nova export-adverse-action --run-id 01KZ... --out aa-pack.json--run-id— run id or capsule directory path (required)--capsule-dir— capsule store to resolve the run id in--json— machine-readable pack on stdout--out— also write the pack JSON to a file (refused inside the capsule)
Exit codes: 0 (rendered, including missing rows), 2 (capsule not found; a
symlinked capsule.yaml / model-calls.jsonl; a file recorded in evidence_digests
that is absent, a symlink, or not a regular file; a sealed digest that does not match
the bytes on disk; malformed manifest, model-call line, or attribution facet; --out
inside the capsule or unwritable).
nova export-cat --run-id <id>
Experimental (ADR-0159 D6 / NF-280). Reads one sealed Run Capsule (by run id,
resolved in $NOVAFABRIC_CAPSULE_DIR, or by path) and renders a lifecycle-ordered,
self-contained agent-event trail — lifecycle stage, recorded actor identity ref and
recorded timestamps per event — as a firm-owned, self-hosted artifact modelled on
the SEC Rule 613 (17 CFR 242.613) Consolidated Audit Trail event lifecycle. The stage
mapping is explicit and nothing else is read:
| Stage | Capsule source | Actor identity ref |
|---|---|---|
origination |
capsule.yaml created_at |
none recorded at run level |
decision |
model-calls.jsonl |
response (else request) model ref |
authorization (optional) |
tool-permission-events.jsonl, human_approvals.jsonl |
authorising_identity (+ approval_principal) / approver_id |
action |
tool-calls.jsonl |
tool_name (+ agent_call_id link) |
disposition |
capsule.yaml finished_at + status |
none recorded at run level |
Events are ordered by UTC-normalised recorded timestamp, ties broken by stage, stream
and line; an event without a timestamp is kept (never given a guessed time), placed
last, and its stage marked partial. A missing required stage makes the trail
partial; authorization is reported but optional (a run whose policy needed no
decision records none). No event is ever synthesised; prompt/response text, tool
arguments/results and approval rationales never reach the trail. Every rendered
recorded string is capped (1024 chars) and scanned against the ADR-0009 secret
rules — a match is suppressed and the stage marked partial. It is not a CAT
submission: no CAT technical-specification format, reporter id or event-type code;
it never connects to the CAT central repository or a plan processor and transmits
nothing.
nova export-cat --run-id 01KZ...
nova export-cat --run-id 01KZ... --json
nova export-cat --run-id 01KZ... --out cat-events.json--run-id— run id or capsule directory path (required)--capsule-dir— capsule store to resolve the run id in--json— machine-readable trail on stdout--out— also write the trail JSON to a file (refused inside the capsule)
Exit codes: 0 (rendered, including missing / partial stages), 2 (capsule not
found; a symlinked capsule file; a stream recorded in evidence_digests that is
absent or not a regular file; a sealed digest that does not match the bytes on
disk; a malformed manifest or event line; an over-long field; an unparseable or
offset-less timestamp; --out inside the capsule or unwritable).
nova export-part11 <document>
Render a 21 CFR Part 11 electronic-records evidence artifact — the
records/signatures elements a run recorded (signer identity, §11.50 signing
intent, DSSE signature binding, record integrity, trusted timestamp, audit
trail), each complete / partial / missing. Facts, never a Part 11
call.
nova export-part11 part11.json --json<document>— JSON:{capsule_root, elements: {name: ref}, partial: {name: reason}}
nova export-rai-scorecard <document>
Render a Responsible-AI coverage scorecard — presence of evidence per
dimension (supported / partial / unsupported / not_applicable),
never a score: no threshold, no fair/unfair or pass/fail label.
nova export-rai-scorecard rai.json --json<document>— JSON:{evidence: {dimension: ...}, not_applicable[], partial[]}
nova export-public-annex-viii <document>
Render a DRAFT EU AI Act Annex VIII / Art. 71 public-database entry from
sealed evidence + operator declarations. Each field is either
capsule_evidence (a digest/ref into the sealed capsule — never the raw
value) or operator_declared (the operator's public declaration).
nova export-public-annex-viii entry.json --json<document>— JSON:{capsule_root, capsule_evidence{}, operator_declared{}}
nova export-transparency-register <document>
Render a DRAFT algorithm-register record from sealed evidence + operator declarations, crosswalked to a public register shape.
nova export-transparency-register reg.json --standard atrs
nova export-transparency-register reg.json --standard amsterdam --json<document>— JSON:{capsule_root, capsule_evidence{}, operator_declared{}}--standard TEXT— register shape:atrs|amsterdam|helsinki(default:atrs)
nova export-public-disclosure <document>
Render a DRAFT public-sector disclosure record from supplied references.
nova export-public-disclosure disclosure.json --json<document>— JSON:{authority_ref, agent_ref, decision_scope, human_oversight_ref, capsule_refs[], system_card_ref?}
nova export-foia <document>
Render a DRAFT FOIA/public-records decision export from a decision's ordered
record index + redaction claims (each redaction a salted digest plus the
claimed statutory exemption_ref).
nova export-foia foia.json --json<document>— JSON:{decision_ref, record_index[], redactions[{digest, exemption_ref}]}
nova export-whistleblower <document>
Render a source-protecting whistleblower attestation over a sealed bundle.
nova export-whistleblower wb.json --json<document>— JSON:{content_digest, authenticity_attestation, anonymity_set_ref?}
nova export-citizen-explanation <document>
Render a plain-language, subject-facing decision explanation.
nova export-citizen-explanation cit.json --json<document>— JSON:{decision_ref, factors[], human_involvement, contest_channel_ref?, logic_summary_ref?}
nova export-public-incident <document>
Render a DRAFT public-interest incident summary from a sealed incident.
nova export-public-incident incident.json --json<document>— JSON:{incident_ref, public_summary?, affected_scope?, remediation_ref?}
nova export-election-disclosure <document>
Render an election/democratic-process content-provenance disclosure — records, never judges. Binds a provenance receipt (e.g. NF-094 / C2PA / SynthID) by digest.
nova export-election-disclosure elec.json --json<document>— JSON:{content_ref, provenance_receipt_ref, disclosure_label, capsule_refs[]}
nova export-accessibility-claim <document>
Render a declared accessibility-conformance claim — a declared claim, never a guarantee.
nova export-accessibility-claim a11y.json
nova export-accessibility-claim a11y.json --standard en_301_549_v4_1_1 --json<document>— JSON:{declared_standard?, audit_digest?, export_format_check?}--standard TEXT— declared standard (wcag_2_2_aa|en_301_549_v4_1_1); overrides the document
nova export-control-attestation <document>
Render a governance-control attestation pack — presents evidence, never certifies.
nova export-control-attestation ctrl.json --json<document>— JSON:{capsule_root, catalog: [{control_id, evidence_kind?}], present_evidence{}, declared[]}
nova insurance
Risk-transfer evidence over facets.risk_transfer (ADR-0170 P2). experimental. Records
evidence — it never assigns fault, decides coverage, adjudicates a claim, or pays out. Every
output (rich or --json) carries the in-mission-boundary line: evidence supports, never
determines, an insurance or legal outcome. Read-only unless --write is passed, which merges the
recorded object into capsule.yaml after validating the whole facet (atomic replace; a
symlinked capsule.yaml or capsule directory is refused). A NovaSeal-sealed capsule (.seal/
present) is refused with exit 2 unless --force-unseal is also passed, which writes anyway
and warns that the existing seal no longer verifies and must be re-issued. The other sub-commands
ADR-0170 names (features, loss bind, subrogation, insurability) are planned — not yet
implemented.
nova insurance liability show --capsule <capsule>
NF-383 liability-attribution chain: ordered {role, party_ref, acted_as_ref, basis_ref, contribution_marker} — records who was attributed, never who is at fault. role ∈ principal |
deployer | operator | vendor | model_provider | integrator | agent | third_party;
contribution_marker ∈ recorded | disputed | none (recorded/disputed must name a
basis_ref). References are sha256: digests; acted_as_ref must name another chain member (no
dangling, self or cyclic edges); fault/verdict/payout-shaped keys are rejected.
nova insurance liability show --capsule 01HX... # read the recorded chain
nova insurance liability show --capsule 01HX... --chain chain.json --writeOptions: --chain PATH (declared chain JSON — a list or {liability_chain: [...]}), --write
(requires --chain), --json.
nova insurance sla verify --capsule <capsule> --sla <terms.json> --observed <decimal>
NF-384 SLA/warranty breach: compares the observed value to the declared commitment
{metric, operator (lt|lte|gt|gte|eq), threshold, window, unit?} and records breach (the
commitment did not hold) with both figures as exact decimals. sla_ref is the sha256 of the terms
file. Numeric condition only — no remedy, service credit or damages; distinct from ADR-0146 cost
showback.
nova insurance sla verify --capsule 01HX... --sla sla.json --observed 99.2 --evidence-ref sha256:<hex>Options: --evidence-ref (repeatable sha256: digest), --write, --json.
nova insurance coverage check --capsule <capsule> --exclusions <set.json> --facts <facts.json> --event-kind <kind>
NF-386 exclusion-aware coverage trigger: records covered_event_kind, trigger_facts (digests),
exclusion_set_ref (sha256 of the declared set, e.g. ISO CG 40 47), matched_exclusions (declared
exclusions whose declared fact markers are present among the observed facts — possibly empty), and
optional parametric_conditions (observed value vs declared parametric threshold; unobserved terms
are recorded as not observed). It never decides whether the policy responds.
nova insurance coverage check --capsule 01HX... --exclusions cg4047.json --facts facts.json \
--event-kind erroneous_output --json--exclusions: {exclusions: [{exclusion_id, fact_markers[]}], parametric_triggers?: [{metric, operator, threshold, unit?}]}. --facts: {trigger_facts: [{fact_ref, marker}], observations?: {metric: value}}.
Exit codes (all three): 0 recorded — a breach or a matched exclusion is a recorded fact, not a
failure; 2 input error — unknown capsule, unreadable/oversize (1 MiB cap)/malformed input, a non-finite
figure (NaN/inf), a non-digest reference, or a determination-shaped
field. JSON numbers in the input files are parsed as exact decimals.
Compliance commands — full reference
This section consolidates all compliance-related CLI surfaces. Commands are labeled per the docs honesty rule: works today, planned (implementation in progress or scheduled for v0.26.x), or future (ADR accepted, implementation not yet scheduled).
Already implemented — works today
| Command | Regulation | Version |
|---|---|---|
nova seal sign --intent <intent> |
FDA 21 CFR Part 11 §11.50 | v0.12.15+ |
nova export-annex-iv <capsule_id> |
EU AI Act Annex IV (Reg. 2024/1689 Art. 11) | v0.15.0 |
nova export-nis2 <capsule_id> |
NIS2 Directive Art. 23 (Phase 1/2/3) | v0.15.0 |
nova subject-proof <subject_id> |
GDPR Art.17 HMAC subject lookup | v0.15.0 |
nova audit coverage |
Multi-profile control coverage scoring | v0.16.0 |
nova audit bundle |
ZIP export of full audit report | v0.16.0 |
nova audit verify |
AuditReport schema validation | v0.16.0 |
nova classify run |
EU AI Act / NIST RMF / OMB M-24-10 risk tier | v0.16.0 |
nova verify <capsule> |
DSSE + RFC 3161 TSR + Merkle log verification | v0.10.0+ |
nova export-ropa <capsule_id> |
GDPR Art.30 Records of Processing Activities (cap-007) | v0.25.1 |
nova export-aibom <capsule_dir> |
CycloneDX 1.7 AI-SBOM / ML-BOM (cap-008); default output aibom.json |
v0.25.1 |
nova aibom status |
CRA SBOM compliance status: deadline 2026-09-11, format, per-capsule coverage | v0.35.0 |
nova aibom generate [--all] [--force] |
Per-deployment automation: generate/refresh aibom.json for one or all capsules |
v0.45.0 |
nova export-nist-rmf <capsule_id> |
NIST AI RMF 1.0 quantitative risk report (cap-009) | v0.25.1 |
nova assure <capsule_id> |
OWASP LLM Top 10 (2025) evidence checks — exit 1 on failure (E-10) | v0.25.1 |
nova mcp scan <manifest> |
OWASP LLM supply-chain risk scanner for MCP manifests (E-9) | v0.25.1 |
nova seal sign --intent <intent>
Sign a capsule with a declared signing intent per FDA 21 CFR Part 11 §11.50.
nova seal propose <capsule-id> \
--key signer.pem \
--cert signer_cert.pem \
--justification "FDA §11.50 review approved — all eval gates green"Signing intents are expressed via the SigningIntent enum (src/novafabric/trust/novaseal/envelope.py):
| Intent | Meaning (FDA §11.50 mapping) |
|---|---|
approved |
Approval signature (§11.50(a)(1)) |
reviewed |
Review signature (§11.50(a)(2)) |
authored |
Authorship signature (§11.50(a)(3)) |
witnessed |
Witnessed signature |
verified |
Verification / QA signature |
The intent value is embedded in the DSSE predicate and verified by nova seal verify.
The five-check SoD verifier (exit codes 3–7) enforces the separation-of-duties
required by FDA §11.50(b).
nova seal sign --backend sigstore
works today — Keyless Sigstore signing (ADR-0071, v0.44.0). Produces a Sigstore
Bundle v0.3 using an ephemeral OIDC-bound certificate and Rekor v2 transparency log
inclusion. Requires pip install novafabric[sigstore].
nova seal sign --backend sigstore --capsule-id 01HX...
nova seal sign --backend sigstore --capsule-id 01HX... --home /data/novaOptions:
--backend [local|sigstore]— signing backend (default:local;sigstorerequiresnovafabric[sigstore])--capsule-id TEXT— capsule ID to sign (required)--home PATH—NOVAFABRIC_HOMEoverride for bundle storage path
Bundles stored at $NOVAFABRIC_HOME/sigstore/<capsule_id>.bundle.json.
Verify with nova verify --backend sigstore --capsule-id <id>.
Note: The sigstore SDK performs OIDC browser-based or ambient identity
(GitHub Actions, GCP, AWS) credential lookup at sign time. Not suitable for
air-gapped HPC environments (use --backend local with RFC 3161 instead).
nova pii erase <subject_id>
works today — GDPR Art.17 crypto-shredding erasure (ADR-0069, v0.44.0). Destroys
the AES-256-GCM DEK for a data subject, rendering all PII encrypted under that DEK
permanently unreadable. Writes an ErasureReceipt (immediate) or
ErasureDeferredReceipt (Art.17(3)(b) retention window still active).
nova pii erase "user@example.com"
nova pii erase "user@example.com" --output receipt.json
nova pii erase "user@example.com" --retention-months 6Options:
--output, -o PATH— path to write theErasureReceiptJSON (default: stdout)--capsule-dir PATH— search for redaction manifests here (default:$NOVAFABRIC_HOME/capsules/)--retention-months INT— Art.17(3)(b) retention floor in months (default:6; provider mode:120)
Exit codes: 0 (receipt written), 1 (subject not found or error).
Scope: single data subject. Requires DEK store at $NOVAFABRIC_HOME/dek.db.
nova pii status <capsule_id>
works today — Show PII encryption status for a capsule — which fields are encrypted,
which subjects have active DEKs, and which have been erased (crypto-shredded, ADR-0069).
Read-only and local-first: correlates the capsule's redaction_manifest.json against
the DEK store at $NOVAFABRIC_HOME/dek.db without creating or modifying either.
Subjects appear only as HMACs — no key material or plaintext PII is ever shown.
nova pii status 01HXAMPLECAPSULEID # resolve by capsule ID
nova pii status .novafabric/runs/01HX.../ # or by capsule directory path
nova pii status 01HXAMPLECAPSULEID --json # machine-readable PIIStatusReport
NOVA_PII_PEPPER=secret nova pii status 01HX... # pepper enables DEK correlationOptions:
--capsule-dir PATH— directory scanned for the capsule'sredaction_manifest.jsonwhen a bare capsule ID is given (default:$NOVAFABRIC_HOME/capsules/)--json— emit the status report as JSON instead of human-readable text
Per-subject dek_state:
active— a live DEK exists; ciphertext is still recoverable by the key holdererased— no DEK exists (crypto-shredded vianova pii erase, ordek.dbabsent)unknown—dek.dbis present butNOVA_PII_PEPPERis not set, so manifest HMACs cannot be correlated
Exit codes: 0 (report produced — including capsules with no redaction manifest), 1 (capsule not found or manifest unreadable).
Scope: single capsule. Works without a DEK store and without NOVA_PII_PEPPER (degrades honestly as above).
nova export-rocrate <capsule_dir>
Export a Run Capsule as a FAIR-compliant RO-Crate v1.1 research object (ZIP archive).
works today — implemented in v0.32.0.
nova export-rocrate .novafabric/runs/01HX.../
nova export-rocrate .novafabric/runs/01HX.../ --output ./out.rocrate.zipOptions:
--output, -o PATH— output ZIP file path (default:<capsule_dir>.rocrate.zipnext to the capsule dir)
nova export-rocrate-science --capsule <capsule>
Export a science capsule as a FAIR Workflow-Run-RO-Crate science profile (ADR-0164 NF-324).
experimental — ADR-0164 P2. Composes over the nova export-rocrate carrier (NF-040): the
carrier's RO-Crate 1.1 file set is kept, and the Workflow Run Crate 0.5 entities are added — a
W3C-PROV-aligned CreateAction, the reproducibility-receipt digests and seeds as
PropertyValues, the hypothesis→claim DAG (with isBasedOn parent edges), and the sealed
science root as an identifier. Byte-deterministic when the capsule carries a timestamp.
nova export-rocrate-science --capsule .novafabric/runs/01HX.../ --out ./crates
nova export-rocrate-science --capsule 01HX... --orcid 0000-0002-1825-0097 --ror 03yrm5c26 --jsonWrites <run_id>.science.rocrate.zip and <run_id>.fair-binding.json (the NF-324
fair_binding record: profile URIs, rocrate_digest, prov_alignment: "w3c-prov",
sealed_root, receipt_root, persistent identifiers, unbound, verdict: null).
Options:
--capsule TEXT— capsule directory or run id (required)--out PATH— output directory (default: the capsule's parent directory)--profile process-run-crate|workflow-run-crate— default:workflow-run-cratewhen the receipt declares aworkflow_digest, elseprocess-run-crate.provenance-run-crateis planned.--doi TEXT,--orcid TEXT(repeatable),--ror TEXT(repeatable) — persistent-identifier references (ORCIDs becomecontributor, neverauthor)--json— print thefair_bindingrecord
Exit codes: 0 exported; 1 refused — no science_provenance facet, a tampered receipt, a
workflow profile with no declared workflow, or a malformed DAG; 2 usage error.
Every output carries the in-mission-boundary line: NovaFabric records and exports provenance;
it never runs experiments or adjudicates scientific validity.
nova science receipt build|verify --capsule <capsule>
Computational-reproducibility receipt (ADR-0164 NF-323). experimental — ADR-0164 P2.
build binds the environment digest, seed(s), input-data digest, code digest and optional
workflow digest — plus the declared determinism_class and, when the science facet records
one, the sealed capsule root — under one bound_root. Components not supplied are named in
receipt_incomplete, never fabricated. verify recomputes the root offline and checks the
declared incompleteness. Record-only: nothing is re-executed and reproducible_in_fact is
always null.
nova science receipt build --capsule 01HX... --env sha256:<hex> --data sha256:<hex> \
--code sha256:<hex> --seed 1337 --seed 42 --determinism statistical --write
nova science receipt verify --capsule 01HX... [--strict] [--json]build options: --env, --data, --code, --workflow (each sha256:<64 hex>), --seed INT
(repeatable, ordered), --determinism bitwise|statistical|nondeterministic|undeclared,
--write (persist into capsule.yaml under facets.science_provenance.reproducibility_receipt;
atomic replace, symlinked capsule.yaml refused), --force-unseal (with --write: rewrite a
NovaSeal-sealed capsule — refused with exit 2 otherwise — and warn that its seal no longer
verifies and must be re-issued), --json.
Exit codes: 0 ok; 1 (verify) root mismatch, misreported incompleteness, malformed or
absent receipt — or --strict with an incomplete receipt; 2 usage error (unknown capsule,
malformed digest or seed).
nova science lab show|verify --capsule <capsule>
Declared lab-experiment provenance (ADR-0164 NF-322). experimental — ADR-0164 P3.
nova science lab show prints facets.science_provenance.lab_experiment — lab_kind
(self_driving | cloud_lab | manual | simulation), protocol_ref, instrument_refs, run_id,
sim_to_real (sim | real | hybrid), outcome_digest, optional started_at / node_ref — and
how many instrument records the capsule carries. nova science lab verify checks offline, and
fails closed, that: every instrument_ref resolves to an instrument record; no referenced
instrument was calibrated after the experiment (experiment time is started_at, else the
capsule's created_at; unknown fails); the experiment and instrument digests re-derive; a
simulation is not declared real; and an optional node_ref names an experiment_design /
experiment_run node of the NF-321 lineage. Declarations only — NovaFabric never dispatches to
or controls a lab and never reads instrument telemetry (controls_lab: false,
reads_telemetry: false, verdict: null).
nova science lab show --capsule 01HX... [--json]
nova science lab verify --capsule 01HX... [--json]The blocks are written by the library API (novafabric.science.lab.build_lab_experiment,
build_instrument_record, attach_lab); there is no build subcommand.
Exit codes: 0 ok; 1 (verify) a failed check or an absent block — and for every
subcommand a malformed block (unknown lab_kind, malformed digest, a telemetry / raw-data /
credential-shaped field); 2 usage error (unknown capsule).
nova science instrument show --capsule <capsule>
Declared instrument / calibration provenance (ADR-0164 NF-329). experimental — ADR-0164 P3.
Prints each facets.science_provenance.instrument_provenance[] record — instrument_id,
instrument_class, firmware_digest, calibration_ref (digest of the calibration record,
never the record), calibration_timestamp, manufacturer_ref, and the record_digest a lab
experiment's instrument_refs point at. Add --json for machine output. Exit 0 shown (or
none recorded); 1 malformed block; 2 unknown capsule.
nova lineage export-prov <capsule_dir>
Export a W3C PROV provenance graph from a capsule's lineage.jsonl, as PROV-JSON
(default) or PROV-N text — both serializations of the same graph.
works today — PROV-JSON since v0.32.0; PROV-N added (ADR-0176).
nova lineage export-prov .novafabric/runs/01HX.../
nova lineage export-prov .novafabric/runs/01HX.../ --output prov.json
nova lineage export-prov .novafabric/runs/01HX.../ --format prov-n -o prov.provnOptions:
--format, -f {prov-json,prov-n}— serialization (defaultprov-json)--output, -o PATH— output path (default:<capsule_dir>/prov.jsonorprov.provn)
nova export-hipaa-proof <capsule_dir>
works today — Export a HIPAA Safe Harbor (§164.514(b)) de-identification proof artifact for a capsule, documenting which of the 18 identifier categories were absent, redacted, or not assessable from available capsule evidence files.
DISCLAIMER: This is a technical evidence artifact only. It is NOT legal advice, NOT a compliance certification, and does NOT guarantee Safe Harbor legal sufficiency.
nova export-hipaa-proof .novafabric/runs/01HX.../ # writes hipaa-proof.json in capsule dir
nova export-hipaa-proof .novafabric/runs/01HX.../ --output hipaa-proof.jsonOptions:
--output, -o PATH— path to write the proof JSON (default:<capsule_dir>/hipaa-proof.json)
nova export-aibom <capsule_dir>
Export an AI Bill of Materials (AIBOM) using CycloneDX ML-BOM 1.7 (ECMA-424 2nd Edition). Required for EU Cyber Resilience Act (CRA) compliance. Deadline: 2026-09-11 (ADR-0073).
works today — implemented in v0.25.1; --output default + nova aibom status added v0.35.0; nova aibom generate (per-deployment automation) added 2026-06-04.
nova export-aibom .novafabric/runs/01HX.../ # writes aibom.json in the capsule dir
nova export-aibom .novafabric/runs/01HX.../ --output /tmp/aibom.cdx.json
nova aibom status # show deadline + per-capsule coverage
nova aibom status --capsules-dir ~/novafabric-data/capsules
nova aibom generate .novafabric/runs/01HX.../ # generate one (skips if present)
nova aibom generate --all # batch: every capsule missing an aibom.json
nova aibom generate --all --force # batch: refresh all (overwrite)
# NF-056 CycloneDX 1.7 extensions (opt-in; default output unchanged):
nova aibom generate <cap> --citations --force # bind components to capsule/evidence digests
nova aibom generate <cap> --tlp TLP:AMBER --force # distribution marker in metadata.properties
nova aibom generate <cap> --model-card auto --force # model-card externalReference per model
nova aibom generate <cap> --no-include-datasets --force # suppress type:data components
nova aibom validate <cap>/aibom.json # structural + binding check (exit 1 on error)Options (nova export-aibom):
--output, -o PATH— path to write the AIBOM JSON (default:<capsule_dir>/aibom.json)
Options (nova aibom status):
--capsules-dir PATH— root directory to scan for capsules (default:$NOVAFABRIC_CAPSULE_DIRor$NOVAFABRIC_HOME/capsules)
Options (nova aibom generate) — per-deployment automation (CRA):
<capsule_dir>— optional positional: generate for a single capsule--all— batch-generate across--capsules-dir, skipping capsules that already have anaibom.json--capsules-dir PATH— capsule store for--all(default:$NOVAFABRIC_CAPSULE_DIRor$NOVAFABRIC_HOME/capsules)--force— regenerate even when anaibom.jsonalready exists--citations— (NF-056, ADR-0105) bind each model/dataset component to its source capsule/evidence digest (+ ADR-0097 inclusion proof when the manifest records one). Default off (byte-stable output).--tlp TLP:CLEAR|GREEN|AMBER|AMBER+STRICT|RED— TLP 2.0 distribution marker inmetadata.properties(novafabric:tlp). Default: none.--model-card auto|<path>— add amodel-cardexternalReference to each model component (autoderives aregistry://URI). Default: none.--include-datasets / --no-include-datasets— emittype:datadataset components from lineage (default on).
Options (nova aibom validate <bom.json>) — NF-056: structural CycloneDX 1.7 + NovaFabric-binding check (specVersion/bomFormat/serialNumber, TLP marker validity, per-component name/bom-ref/hash-alg/citation digest). Exit 0 valid, 1 on validation errors, 2 on a missing/malformed file. --json emits {valid, errors}.
nova dataset provenance-card <asset> (experimental)
Experimental — NF-058, ADR-0105. Emit (and optionally sign) a dataset provenance card recording a dataset's source, version, content hash, and transform history. Feeds the AI-BOM (NF-056) and the SLSA-for-ML attestation (NF-057). Op digests only — never raw values, prompts, or cell contents.
nova dataset provenance-card dataset:gaia@2026-05 \
--source oci://reg/gaia:2026-05 --version 2026-05 --hash b17a... \
--license CC-BY-4.0 --tlp TLP:CLEAR --registry-digest b17a... --sign
# pull the transform history from a capsule's lineage derivation edges:
nova dataset provenance-card dataset:x@1 --source oci://x --version 1 --hash <sha256> \
--from-capsule ./my-capsule --sign --out card.json--source,--version,--hash(required) — the dataset's source URI, version label, and content sha256.--from-capsule <dir>— derivetransformHistory[]from the capsule'slineage.jsonlderivation edges (eachsignedOpDigestis the content hash of the recorded edge).--license,--tlp,--registry-digest,--retrieved-at— optional card fields.--sign [--identity <id>]— Ed25519-sign the card with the keyring key (reuses the NovaSeal/Evidence-Bundle path). The signature is taken over the canonical-JSON body excluding the signature block. An unsigned card is schema-invalid — a signed card is evidence.--out, -o <path>— write the card JSON (default: stdout).
nova export-c2pa <capsule_dir>
Export a C2PA v2.3-compatible provenance manifest for AI-generated content (ADR-0074). Required by EU AI Act Art.50. Deadline: 2026-08-02.
works today — implemented in v0.33.0.
nova export-c2pa .novafabric/runs/01HX.../
nova export-c2pa .novafabric/runs/01HX.../ --output manifest.json
nova export-c2pa .novafabric/runs/01HX.../ --training-mining # adds notAllowed assertionOptions:
--output, -o PATH— output JSON file (default:<capsule_dir>/c2pa-manifest.json)--training-mining— includec2pa.training-mining: notAllowedassertion (opt-in)
Note: the manifest is structurally valid for TSP signing. Hard-binding C2PA verification requires operator enrollment with a C2PA-certified Trust Service Provider (TSP signing path deferred to a future release).
nova export-compliance <subcommand>
Export EU AI Act / ISO / NIST compliance evidence from the ADR-0107 exporters. Each
subcommand reads a capsule or a JSON input and writes a report as JSON (to --out, else
stdout). The CLI only parses and serialises — the exporter logic lives in
novafabric.compliance.export.
works today — implemented in v0.89.0 (experimental).
# NIST GenAI + CSA Agentic profile, built from a capsule's NIST-RMF report (NF-097)
nova export-compliance genai-profile .novafabric/runs/01HX.../ --evidence tool_permissions,eval_gate --out profile.json
# ISO/IEC 42001 control-evidence mapping from a declared catalog (NF-095)
nova export-compliance iso42001 --catalog controls.json --evidence eval_gate --capsule-id run-123 --out iso.json
# First sealed revision of a GPAI Art. 53 documentation form (NF-093)
nova export-compliance gpai53 --model my-gpai --fields art53.json --out form.json
# Art. 72 post-market-monitoring report; serious findings refer Art. 73 incidents (NF-091)
nova export-compliance pmm --system triage --findings findings.json --occurred-at 2026-07-01 --out pmm.jsonSubcommands and key options:
genai-profile <capsule>—--evidence a,b(governance-evidence kinds present),--out.iso42001 --catalog c.json—--evidence a,b,--capsule-id ID(supplies the re-performable reference evidenced controls require; without it, evidenced controls honestly degrade tonot_evidenced),--out.gpai53 --model NAME --fields f.json—--out.fields.jsonis a{field: value}object.pmm --system NAME --findings f.json --occurred-at ISO—--period-start,--period-end,--out. A serious finding (severitycritical/high) must carry anincident_classification, or the command fails closed.
Note: NF-090 (Art. 12) is served by nova euaiact; NF-092 (Annex IV) by the AIBOM/Annex-IV
exporters; NF-094 (Art. 50 dual-layer receipt) composes with nova export-c2pa.
nova export-system-card <capsule_dir>
Generate and seal an auto-generated system/audit card (ADR-0085). The card is
assembled from capsule + eval + lineage facts (capsule.yaml, eval_result.json,
lineage.jsonl) and sealed by reusing the existing DSSE/Ed25519 signing path — no
new crypto. It is generated, never hand-written, so it cannot drift from the
capsule it describes. The sealed output is a DSSE envelope (predicate type
https://novafabric.io/system-card/v0) that verifies with the same verifier used
for Evidence Bundles.
works today — implemented in v0.48.0.
nova export-system-card .novafabric/runs/01HX.../
nova export-system-card .novafabric/runs/01HX.../ -o card.intoto.json --key ed25519.pemOptions:
--output, -o PATH— output DSSE JSON (default:<capsule_dir>/system-card.intoto.json)--key PATH— PEM-encoded ed25519 private key to seal with. If omitted, a local key under$NOVAFABRIC_HOME/keys/is created/loaded.
Related: eval results now also pin the asset version and an optional
dataset version (nova eval-driven run_evals, ADR-0085) so a stored eval
result can be tied back to exactly what was measured.
nova export-blob --dest <uri>
Export a batch of capsules to blob storage with one signed, verifiable
completeness manifest (ADR-0141,
spec batch-blob-export-v0). Members are
selected explicitly (--capsule, repeatable) or by scanning the capsule directory
with an optional created_at time range (--since/--until, inclusive); the
selection is frozen at export start (a batch is a snapshot). Each member is packed
deterministically and written content-addressed under objects/<sha256> at the
destination — already-present blobs are skipped, so re-runs are idempotent and an
interrupted export resumes. The Ed25519/DSSE-signed export-manifest.json
(validates against schemas/export-manifest.schema.json) is written last as the
atomic completion marker: it lists every member's capsule_id, content_hash, and
size, plus a batch_digest over the sorted member list, so a recipient can verify
integrity and completeness offline. Source capsules are never modified.
experimental — implemented; API may change.
# Local directory (always works, fully offline)
nova export-blob --dest ./exports/audit-q3 -c 01HX... -c 01HY...
# Time-range scan of the capsule store
nova export-blob --dest ./exports/w27 --since 2026-06-29 --until 2026-07-05
# Query filter (ADR-0129 DSL) — composes with the time window
nova export-blob --dest ./exports/gpt4o --query "model = 'gpt-4o'"
nova export-blob --dest ./exports/failures \
--query "status = 'error'" --since 2026-07-01
# Any S3-compatible endpoint (existing optional boto3 adapter; private endpoints OK)
NOVA_S3_ENDPOINT_URL=https://s3.internal nova export-blob \
--dest s3://audit-bucket/exports/2026-07/ --worm --worm-retention-days 2555Options:
--dest URI— local directory ors3://bucket[/prefix](any S3-compatible endpoint viaNOVA_S3_ENDPOINT_URL).azure:///gcs://are planned (ADR-0141 P2) and report a clear error.--capsule, -c ID|PATH— explicit member (repeatable); recordsquery: null.--capsule-dir PATH— scan root (default$NOVAFABRIC_HOME/capsules).--since / --until RFC3339— inclusivecreated_atwindow for the scan; recorded as the manifestqueryfor reproducibility.--query EXPR— select members with an ADR-0129wherefilter, e.g."model = 'gpt-4o'"or"status = 'error'". Composes with--since/--until(both must hold), and is mutually exclusive with--capsule. The parsed, canonical predicates are recorded in the manifestqueryfield alongside the time window — so a manifest reader sees what was asked, not free text they must re-parse. Filters on the query'swhereclause only:run_idis not a DSL dimension, and grouping by it would invite the high-cardinality blow-up the DSL's cardinality cap exists to prevent.--key PATH— PEM ed25519 signing key (default: the NovaFabric keyring key, created if absent).--worm/--worm-retention-days N— write members and manifest under WORM retention (S3 Object Lock COMPLIANCE via the existing ADR-0031 adapter; local dirs get best-effort read-only files); intent recorded in the manifest.--out PATH— also save a local copy of the manifest.--public-key-out PATH— save the signer's public key PEM for recipients.
Verify offline (no NovaFabric service; extends nova verify):
nova verify export-manifest.json --public-key export.pub.pem
nova verify manifest.json --public-key pub.pem --dest s3://audit-bucket/exports/2026-07/Verdicts: VALID (signature + batch digest + every member's bytes at the
destination check out), INCOMPLETE (a member missing, or size/hash mismatch —
e.g. a deleted or tampered blob), INVALID (bad signature, count, or batch
digest — e.g. a member quietly dropped from the manifest). Exit 0 only on VALID.
nova import <source>
Import a batch export (nova export-blob)
into the local capsule store — the verified inverse of the export
(ADR-0207, spec
batch-import-v0). <source> is either a
directory containing export-manifest.json + objects/, or a single
.tar/.tar.gz archive of that layout (the air-gap courier format).
Verification-first, fail-closed: before any byte enters the store the
manifest must verify (VALID — DSSE signature via the supplied public key,
count/batch_digest consistency, and every member's bytes re-hashed).
INVALID or INCOMPLETE refuses the whole import. Unpacking is hardened
against hostile archives (absolute paths, .., links, devices — refused) and
staged: members extract to a scratch directory and are atomically renamed into
place, so a crash never leaves a half-written capsule. After unpack, lineage
(lineage.jsonl → lineage store) and the dashboard runs_cache are reindexed
(the offline query index self-scans and needs no rebuild). Every run —
including refusals and dry runs — writes an import receipt JSON under
$NOVAFABRIC_HOME/import-receipts/<import_id>.json and one hash-chained audit
entry (capsule.import).
Idempotent by content address: a member whose run_id already exists
locally with byte-identical content (same deterministic re-pack hash) is
skipped, so re-running an import is a no-op and an interrupted import resumes.
Collisions are never overwritten: same run_id with different local
content is reported per-member with both hashes (exit 5); delete the local
capsule with existing retention tooling and re-import to replace it — there is
deliberately no --force.
experimental — implemented (ADR-0207 P1); API may change.
# Verified import (the normal path; key from `nova export-blob --public-key-out`)
nova import ./exports/audit-q3 --public-key export.pub.pem
# DR drill: verify + classify with zero writes, same exit codes
nova import ./exports/audit-q3 --public-key export.pub.pem --dry-run
# Air-gap courier archive
nova import batch.tar.gz --public-key export.pub.pem
# Machine-readable report
nova import ./exports/audit-q3 --public-key export.pub.pem --jsonOptions:
--public-key PATH— PEM ed25519 public key of the export signer. Required unless--allow-unsigned.--allow-unsigned— skip the DSSE signature check only (loud warning; recorded permanently asverification.mode: "unsigned"in the receipt and audit log). All content-hash/size/consistency checks still run — tamper still refuses.--capsule-dir PATH— target store root (default$NOVAFABRIC_HOME/capsules).--dry-run— verify + classify (would-import / would-skip / collision), write nothing to the store or indexes; the receipt is still written.--no-reindex— unpack only; skip lineage + runs-cache updates.--json— print the import receipt JSON to stdout.
Exit codes: 0 success (imported / already present), 2 usage error, 3
verification INVALID (structure, signature, digest), 4 verification
INCOMPLETE (member missing / hash or size mismatch), 5 collision(s), 6
member(s) failed during unpack. Nothing is imported on 3/4; non-colliding
members still import on 5.
nova euaiact export
Export structured EU AI Act Art.12 log events for authority access requests (Art.74). Binding for high-risk AI systems: 2026-08-02 (ADR-0076).
works today — implemented in v0.33.0.
nova euaiact export --from 2026-01-01 --to 2026-06-30 --output euaiact-report.json
NOVA_EUAIACT_HIGH_RISK=true nova euaiact export --from 2026-01-01
nova euaiact export --pretty # Rich table output to terminal
nova euaiact status # show active configurationOptions:
--from DATE— start date ISO 8601 (default: no lower bound)--to DATE— end date ISO 8601 (default: now)--capsules-dir PATH— capsule root (default:$NOVAFABRIC_CAPSULE_DIRor$NOVAFABRIC_HOME/capsules)--output, -o PATH— output file (default: stdout as JSON)--pretty— Rich table output instead of JSON
Environment:
NOVA_EUAIACT_HIGH_RISK=true— declares this is a high-risk AI system under EU AI Act Annex IIINOVA_EUAIACT_PROVIDER=true— enables provider mode (120-month / Art.18 retention floor instead of 6-month deployer floor)
Governance commands (v0.16)
nova classify run
Classify an AI system's risk tier against EU AI Act Annex III, NIST AI RMF, and OMB M-24-10.
nova classify run --system system.yaml
nova classify run --system system.yaml --vocabulary nist-ai-rmf/1.0.0
nova classify run --system system.yaml --format jsonOptions:
--system PATH— YAML file describing the AI system (AISystemRecordschema)--vocabulary TEXT— vocabulary ID (default:eu-ai-act/2024.1.0). List withnova classify list-vocabularies.--format [text|json]— output format (default:text)
Exit codes: 0 = classified; 1 = prohibited tier detected.
AISystemRecord fields: name, description, use_cases (list of strings), deployment_context, data_subjects (list), automated_decision_making (bool), biometric_processing (bool), critical_infrastructure (bool).
nova classify list-vocabularies
List all available classification vocabularies.
nova classify list-vocabulariesnova classify from-capsule
Infer an AI system record from a captured run capsule and classify it.
nova classify from-capsule .novafabric/runs/01HXAY7M/Reference: src/novafabric/governance/, src/novafabric/cli/classify.py, ADR-0056.
Compliance audit commands (v0.16)
nova audit map
List all evidence checkers for a compliance profile.
nova audit map --profile nist-ai-rmf
nova audit map --profile eu-ai-act-high-risk
nova audit map --profile gdprAvailable profiles: nist-ai-rmf, eu-ai-act-high-risk, gdpr, soc2-type2, iso42001, scientific-reproducibility.
nova audit report
Run a compliance audit against a capsule and print the result.
nova audit report --capsule .novafabric/runs/01HXAY7M/ --profile nist-ai-rmf
nova audit report --capsule .novafabric/runs/01HXAY7M/ --profile gdpr --format jsonOptions:
--capsule PATH— path to a captured run capsule--profile TEXT— compliance profile (seenova audit map)--format [text|json]— output format (default:text)
nova audit verify
Assert that a capsule meets a minimum compliance coverage threshold. Exits 1 if the coverage is below the threshold.
nova audit verify --capsule .novafabric/runs/01HXAY7M/ --profile nist-ai-rmf --min-coverage 0.8Options:
--min-coverage FLOAT— minimum required coverage score [0.0, 1.0] (default:0.7)
nova audit bundle
Export a signed audit bundle (ZIP) containing the compliance report and evidence artifacts.
nova audit bundle --capsule .novafabric/runs/01HXAY7M/ --profile eu-ai-act-high-risk --output audit.zipnova audit coverage
Print a numeric coverage summary for all profiles against a capsule.
nova audit coverage --capsule .novafabric/runs/01HXAY7M/Reference: src/novafabric/compliance/audit/, src/novafabric/cli/audit.py.
Examiner exporter commands (v0.16)
nova export-examiner bagit
Export a capsule as a RFC 8493 BagIt archive with SHA-256 checksums.
nova export-examiner bagit .novafabric/runs/01HXAY7M/ --output run.bagit.zipOutput: BagIt ZIP containing bagit.txt, bag-info.txt, manifest-sha256.txt, and the full capsule payload under data/.
nova export-examiner pccp
Export a capsule as an FDA 21 CFR Part 11 PCCP (Predetermined Change Control Plan) package.
nova export-examiner pccp .novafabric/runs/01HXAY7M/ --output pccp.zip
nova export-examiner pccp .novafabric/runs/01HXAY7M/ --output pccp.zip --format jsonOutput: ZIP containing protocol document, change manifest, training documentation, and validation records.
nova export-examiner iso42001
Export a capsule as an ISO/IEC 42001 AI Management System package.
nova export-examiner iso42001 .novafabric/runs/01HXAY7M/ --output iso42001.zipOutput: ZIP containing system profile, risk register, monitoring plan, and improvement log.
Reference: src/novafabric/compliance/export/examiner.py, src/novafabric/cli/export_examiner.py.