Back to the registry
Agent passport

NanoOrch

Cambridge Technology · Software Development

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownCloudFormation template
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

NanoOrch is a self-hostable, multi-tenant AI orchestration platform that lets teams build, deploy, and monitor intelligent agent workflows without handing control to a third-party cloud. From a single UI, you can run autonomous agents, chain them into pipelines, trigger them from webhooks or cron schedules, and supervise every action they take.

Multi-tenant workspaces keep teams, projects, or customers fully isolated. A global admin governs the platform , capping resource limits per workspace, restricting which AI providers are permitted, and managing users through a 3-tier RBAC model (global admin, workspace admin, member). SSO is supported via OIDC or SAML 2.0, with automatic user provisioning on first login.

Show the rest of the publisher’s description (10 more lines)

Orchestrators and agents are the core building blocks. Each workspace can run multiple orchestrators , each with its own AI provider, model, and system prompt , and each orchestrator can host multiple agents with individual instructions, memory, temperature settings, and tool access. NanoOrch supports five AI providers out of the box: OpenAI, Anthropic, Gemini, Ollama, and vLLM. Orchestrators also support model failover: if the primary model fails, a backup kicks in automatically, with exponential backoff retry logic.

Tasks can be submitted through the UI, a webhook endpoint, an API key channel, or a scheduled cron job. Real-time log streaming via SSE keeps you informed as tasks execute. For high-impact write operations, approval gates pause execution mid-task and surface a pending approval in the sidebar , or push interactive Approve/Reject cards directly into a Slack thread or Microsoft Teams conversation so reviewers never need to leave their messaging app.

Pipeline and DAG chaining lets you build sequential multi-step workflows where each step's output feeds as context into the next agent. Pipelines support cron scheduling, manual triggers, and per-run step history.

Event-driven triggers connect NanoOrch to your development workflow. Webhook listeners fire agent tasks on GitHub push/PR events, GitLab push/merge events, or Jira issue updates, all HMAC-SHA256 verified with full event history. Git Agents take this further: connect a repo, drop a .nanoorch.yml file in the root, and NanoOrch automatically dispatches tasks on push or PR events and posts AI-generated feedback comments back to the PR.

Two-way messaging turns NanoOrch into a conversational AI layer inside Slack, Microsoft Teams, or Google Chat. Enable a workspace as a comms workspace, and users can mention the bot or DM it , the message gets routed to an agent, and the reply lands in the same thread. Features include a DM allowlist, bypass phrases for approval gates, conversation history across the last 50 exchanges per thread, and built-in commands like /status, /reset, and /help.

Integrations span cloud platforms (AWS, GCP, Azure), DevTools (GitHub, GitLab, Jira), ITSM (ServiceNow), databases (PostgreSQL with a built-in read/write approval gate), and RAGFlow for knowledge base querying or auto-injected context. Messaging platforms: Slack, Teams, Google Chat can also be used as agent tools, not just inbound channels.

Observability covers token usage and cost across all providers, with daily charts, per-agent breakdowns, and configurable threshold alerts dispatched to any outbound channel when rolling usage crosses a set limit.

Code execution runs Python and JavaScript directly from chat inside a gVisor sandbox: fully network-isolated, read-only filesystem, memory and CPU capped. Action tasks run in ephemeral Docker containers for the same isolation guarantees.

The MCP Server exposes NanoOrch's core capabilities: running tasks, checking status, approving requests, triggering pipelines: to Claude Desktop or any MCP-compatible client via a standard HTTP/SSE interface.

All credentials (AI provider keys, cloud credentials, database connection strings) are stored AES-256-GCM encrypted. NanoOrch is designed to run entirely on your infrastructure, giving your team full data residency and control.

Highlights

Highlighted by the publisher on AWS Marketplace.

Intelligent Agent Workflows Run multiple orchestrators and agents per workspace, each with its own AI provider, model, system prompt, memory, and toolset. Chain agents into sequential pipelines where each step's output feeds the next. Built-in model failover with exponential backoff ensures reliability , if the primary model fails, a backup takes over automatically. Submit tasks via UI, webhook, API key, or cron schedule with real-time log streaming throughout.

Human-in-the-Loop Approvals & Two-Way Messaging Approval gates pause agent execution before high-impact operations, surfacing interactive Approve/Reject cards directly inside Slack threads or Microsoft Teams conversations : no context switching required. Enable any workspace as a comms workspace so users can DM or mention the bot in Slack, Teams, or Google Chat, with replies landing in the same thread and conversation history retained across 50 exchanges

Secure, Observable, and Fully Self-Hosted All credentials are stored AES-256-GCM encrypted. Code execution runs inside gVisor sandboxes; action tasks run in ephemeral Docker containers. A built-in observability dashboard tracks token usage and costs across all five AI providers : OpenAI, Anthropic, Gemini, Ollama, and vLLM , with per-agent breakdowns and configurable threshold alerts. NanoOrch runs entirely on your infrastructure for full data residency and control

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

1 listed
t3.medium
  • Hrs
$0.00

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
CloudFormation template
cloc@ctepl.com
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.