Your network stays closed. nara works anyway.
The Edge Connector executes approved tools on devices, servers, and in private networks. The connection runs outbound only, with no open ports and no changes to your firewall.

Outbound only. No exceptions.
The Edge Connector opens an outbound WebSocket connection to nara. That is the only path data travels. No inbound port, no VPN tunnel, no new firewall rule. Your network team has nothing to open and nothing to monitor that was not there before. From your perimeter's point of view, the Edge Connector behaves like a browser: it calls out, nobody calls in.
No open shell. Ever.
The Edge Connector does not run arbitrary commands. It only knows tools you have explicitly approved.
Approval per agent
Every tool is approved per agent. An agent can only execute what it has been explicitly allowed to run, nothing else.
Typed parameters
Every tool has typed parameters and a result schema. What goes in and what comes out is defined, not free text.
A complete record
Every call is logged: who, what, when, with which result. Audit questions are answered with one look at the log.
Your own tools in TypeScript
You write your own tools in TypeScript. Same typing, same approval, same logging as everything else.
How a tool gets into your network.
Package
Tool code is packaged as a versioned bundle.
Every version is unique, nothing changes unnoticed.
Pin or update
You pin a version or let reviewed updates install automatically.
If an update fails, the Edge Connector rolls back automatically.
Approve
You approve the tool per agent.
Only then can it be called at all.
Execute and log
The agent calls the tool, the Edge Connector executes it and writes the complete call to the log.
Runs where your systems run.
Desktop mode
For tools that run on individual workstations.
Server mode
For tools on servers and for systems that are only reachable internally.
Windows, macOS, Linux
The Edge Connector runs on all three platforms. Your device fleet decides, not us.
Versioned bundles
Every tool bundle is versioned and pinnable. Updates are reviewed, rollbacks are automatic.
Old school remote access vs. the Edge Connector
Classic remote access
Edge Connector
Inbound ports or VPN access that must be maintained and monitored
Outbound WebSocket connection only, no firewall changes
Shell access with arbitrary commands
Only approved tools with typed parameters and a result schema
Traceability depends on who takes notes
Every call logged automatically: who, what, when, result
Let us show it in your network.
In a demo, you see how the Edge Connector executes tools without your perimeter changing. Your security team is welcome to join.
