Skip to main content
Product

Choose where the working environment lives.

Nova needs a real engineering environment with the repository, toolchain, tests and browser. Use one in your infrastructure or one managed by NovaCore.

Where it runs

A real workbench, not a simulated tool call.

A customer-owned environment runs inside your cloud or network. It holds the repository, build toolchain, caches and browser setup needed to do the work.

Access and networking are configured for the project and reviewed with your security team. Nova reports progress and selected results without turning implementation details into a user concern.

A managed environment provides the same project capabilities while NovaCore handles its operation. Capacity can be on demand or reserved where faster startup matters.

What your security team will ask
  • Where is the working copy?

    In the customer-owned or NovaCore-managed environment selected for that project.

  • What reaches an AI provider?

    Only the context Nova needs for the current task, including relevant excerpts and tool results.

  • Where do external credentials live?

    Credentials remain outside AI prompts and are scoped to approved connected services.

  • Do we open a firewall port?

    The exact network pattern depends on the chosen deployment and is documented during security review.

  • Can we choose the boundary?

    Yes. Use an environment in your infrastructure or one managed by NovaCore.

Nova · checkout team working
  1. 09:00 Picked up PAY-2841 Duplicate confirmation emails started
  2. 09:18 Reproduced the issue Regression test added working
  3. 10:42 Fix verified 214 tests passed · browser journey passed verified
Needs your approval one action

Publish the verified fix as a pull request.

Approve Reject
tests 214 ✓ browser passed evidence attached
Why it matters beyond security

It has the environment required to prove the work.

Your builds actually run

Real machine, real toolchain. It compiles, runs your test suite, spins up the containers your tests need, and installs from your internal package feeds.

Your test data is reachable

The development database that only resolves inside your network is exactly where it needs to be. Nothing has to be copied out to make it usable.

It can verify the browser

Application lifecycle and browser checks run with the changed code, producing structured results and screenshots for review.

Most AI coding tools fail here rather than on intelligence. If it cannot build and test your code, it cannot know whether its own work is correct, and you are back to reviewing guesses.

The boundary

The work environment is capable, but access remains scoped.

The environment can build, test and browse. Actions in Jira, GitHub and other connected services still follow the rules and approvals your team configured.

AI output does not grant itself permission. Nova checks the requested action against those rules and pauses for a person whenever approval is required.

Edit the local workspace yes
Run your tests and builds yes
Run browser verification yes
Place service credentials in AI prompts no
Bypass an approval decision no
Exceed the project usage limit no
Access another customer's data no
Turn AI output into authority no

Relevant source excerpts and tool results may be sent to the AI provider you configure. That boundary is documented and reviewable; we do not disguise AI processing behind the false claim that no code ever leaves the environment.

Put your security team on the call.

We would rather answer the hard questions in the first week than the ninth. Most of them have a one-sentence answer, and the ones that do not, we will say so.