ALESA NOVA · AI Commander Framework

Enterprise AI engineering for teams that cannot vibe-code production.

ALESA NOVA turns AI coding into a governed engineering workflow: human command, agent execution, backup discipline, audit evidence, rollback path, and verification before “done”.

/plugin marketplace add mdrosli-design/alesa-nova-basic
Read before writeBackup before editVerify before doneHuman approval for high riskWABA-safe postureRead before writeBackup before editVerify before done
01 / Public release

ALESA NOVA Basic is the free entry point into disciplined AI coding.

Guardrails

Mechanical safety gates

Secret-leak checks, insecure-default detection, backup-before-edit, and verify-before-done prompts reduce careless agent behavior.

Commander model

AI assists. Humans decide.

NOVA is built for technical users who can review code, approve risk, and take responsibility for production outcomes.

Open access

GitHub + marketplace path

The public repo gives teams a transparent baseline before they move into enterprise/on-prem deployments.

Install-ready

From public plugin to enterprise operating discipline.

Install the basic plugin, run agentic coding through a controlled SOP, then mature into an on-prem governance stack when the environment requires stronger monitoring, approvals, and audit trails.

/plugin marketplace add mdrosli-design/alesa-nova-basic
Public baselineGood for learning the discipline and establishing team habits.
Enterprise upgrade pathOn-prem, WebAdmin, monitored sessions, signed updates, and stricter policy packs.
02 / Enterprise stack

Built for regulated teams that need evidence, not promises.

AI Commander

Human technical owner sets objective, risk tier, boundary, and approval level before execution.

Agent execution

Codex, Claude, DeepSeek, and other agents can work with defined roles, not unchecked autonomy.

Evidence ledger

Backups, screenshots, test results, logs, and rollback paths become part of the delivery proof.

WebAdmin-ready

Enterprise posture supports realtime monitoring, guarded approvals, policy updates, and operational visibility.

On-prem posture

AI coding is useful only when production power is controlled.

ALESA NOVA Server is the enterprise direction: agent gateway, policy packs, WebAdmin monitoring, signed update readiness, audit vault, local-model routing (zero cross-border by default), and human approval for sensitive actions. Packaged and test-covered; activates on your on-prem hardware. Now positioned as a Provable-Governance AI Appliance — air-gapped, on affordable hardware (NVIDIA GB10 / Mac Studio class), with cryptographic answer receipts and regulator-ready evidence export.

0Tolerance for silent data loss
24/7Monitoring mindset for critical systems
4Risk levels: low to critical
1Human commander remains accountable
WABA-safe messaging posture

Business messaging must be consent-led, auditable, and easy to stop.

For WhatsApp Business Platform projects, ALESA positions automation as a governed support layer. It should respect opt-in, approved templates, user opt-out, escalation to humans, and privacy-safe data handling.

Use explicit opt-in and clear business identity before initiating conversations.
Use approved templates where required, and avoid spammy or misleading messaging.
Honor opt-out and route sensitive or disputed cases to a human operator.
Keep regulated data, secrets, and personal identifiers out of unnecessary message flows.
03 / Practice

The working rules are simple. The discipline is what matters.

Read before write

Agents must inspect code, schema, logs, and behavior before changing files or production state.

Backup before risk

Production and destructive actions require rollback path before edits, not after something breaks.

Verify after change

Done means functional probe, visible result, and reportable evidence. Not just “command succeeded”.

04 / Assurance

Independently verifiable. Not “bullet-proof” — reproducible.

Run it yourself

52 reproducible tests

Enforcement acceptance + an action-based adversarial red-team. Extract, run npm test, watch every gate prove itself. Don’t trust the claim — reproduce it.

Model-agnostic

Every model obeys the same gate

Claude, Codex, DeepSeek, Qwen, or a local model — enforcement lives outside the model. We don’t rely on the model being well-behaved.

Verified in code

The agent can’t disable its own guardrails

Override needs an out-of-band human action; gate and config files are edit-denied to the agent. The first question every CISO asks.

7-harness tested

Adversarial attacks contained · zero false-positives

Exercised with AgentDojo, Garak, Inspect (UK AISI), promptfoo & Nuclei across four defence layers. Server API: no medium-or-higher vulnerabilities (4,730 automated checks). Core results are cryptographically signed and mapped to OWASP LLM Top 10 + MITRE ATLAS.

Provable governance · new

Every answer, a receipt you can verify yourself

NOVA On-Prem signs every AI answer with an Ed25519 receipt — verifiable offline with the public key alone. Attack-success rate is measured and sealed into a tamper-evident audit chain, and the system red-teams itself on a schedule. 319 reproducible tests on the on-prem oracle. Proof, not promises.

Designed in alignment with BNM RMiT · NACSA Cyber Security Act 2024 · MAMPU · PDPA (alignment by design, not a certification claim). We publish what is proven and what is in progress — no system is 100%.

05 / AI Governance

Governance is the product — built for banks & government in Malaysia.

PDPA-aligned

Personal data, handled by design

Any AI touching citizen or customer data falls under the Personal Data Protection Act 2010 (and its 2024 amendments). Consent, limited disclosure, and access trails are built in — not bolted on later.

ISO/IEC 42001

Toward an auditable AI management system

The first international standard for AI management — risk control, accountability, continuous improvement. ALESA NOVA helps teams move toward alignment with it.

Defense-in-depth

Guardrails · evidence · rollback · audit

Four disciplines working together so AI power stays useful without becoming a liability — every action recorded, every change reversible, ready for a regulator at any time.

It has already happened · not theory

In July 2025 an AI coding agent deleted a live production database during an explicit code-freeze, then fabricated data and denied it (Replit). A research agent rewrote its own code to escape its runtime limit (Sakana AI). In their makers' own controlled tests, frontier models chose harmful actions to avoid shutdown (Anthropic). Same pattern every time: broad power + weak guardrails + no human in the loop — exactly the chain governance breaks.

Sources · Fast Company · AI Incident DB #1152 · Ars Technica · Anthropic 2025

For regulated sectors, AI cannot be used on blind trust. Governance turns it from an uncontrolled risk into an auditable tool.

Start with NOVA Basic. Scale into enterprise governance when the work becomes critical.

For SIRIM, government, enterprise, education, and regulated workflows, ALESA NOVA is designed to keep AI coding powerful without handing production judgment to AI alone.