Nexus is an open-source framework for building secure, governed AI applications, retrieval systems, and operational workflows on your own data. Seven independently deployable layers take you from raw enterprise data to a grounded, policy-checked answer — without locking you into a model provider, a vector database, or a runtime. It is the same foundation behind every Veloxs product, and it is yours under Apache-2.0.
Every AI prototype reinvents the same infrastructure from scratch — ingestion, retrieval, guardrails, audit logging, and security controls. Nexus packages all of it so your team focuses on the intelligence, not the plumbing.
spent rebuilding ingestion pipelines, retrieval layers, guardrails, and audit logging for every new use case.
ever reach production — the non-model engineering is harder than the model, and most teams underestimate it.
Nexus is the same foundation Veloxs uses to build Contexion and every product in our portfolio — battle-hardened from day one.
Each capability is independently composable, model-agnostic, and production-ready. Integration happens through data contracts (JSONL), config references, CLI subprocess contracts, and HTTP — never through Python imports. Any layer can be swapped for a production adapter without touching the others.
Unify data from SaaS apps, databases, file stores, and event streams into a governed, AI-ready foundation — REST APIs, batch drops, PostgreSQL logical replication, Apache Kafka, signed webhooks and Slack, all delivered at least once.
More than 30 formats — PDF, Office, e-mail, images, audio, video, code, API specs and databases — parsed into context-rich chunks, with PII masked at ingestion and a five-stage trace of every document.
Local semantic embeddings (FastEmbed, 384 dimensions), hybrid search that blends meaning, keywords and entities, and cross-encoder re-ranking — with reference schemas for pgvector, MySQL and MongoDB Atlas.
The control plane every prompt flows through — Unicode normalization, PII detection, prompt-injection defense on questions and retrieved text, policy enforcement, and grounded answers with citations, confidence and an optional relevance gate.
The single front door for users, apps, and AI agents — one in-process client, plus API-key auth, identity binding, owned sessions and a normalized response via REST or CLI.
Tenant-bound Fernet encryption with HKDF-SHA256 key derivation, RBAC with tenant scopes, SSRF-safe outbound calls, and JSONL audit logging — consulted by all six other layers.
Metrics, structured logs, distributed traces, AI interaction events and alert rules — written as JSONL locally, with exporter settings for OpenTelemetry, Prometheus, Grafana, Datadog, Splunk and CloudWatch validated locally (nothing is pushed by default).
eval / exec / pickle / os.system anywhere. Fail-closed security defaults. Subprocess hardening on every CLI path. This is what makes Nexus production-safe — not an afterthought, the architecture itself.
Tested building blocks for the most common enterprise AI patterns — so your team focuses on the differentiating logic, not the scaffolding.
Retrieval-augmented answers with chunking, hybrid search, citations, confidence scoring and a relevance gate that refuses what your documents cannot answer.
Rules as data, scorecards, contact rules, human approvals and a fair holdout — every action explained with reason codes and sent exactly once.
PostgreSQL change streaming, Apache Kafka, CDC normalization, signed webhooks and Slack — acknowledged only after your write, so nothing is ever skipped.
Explainable anomaly scores from sensor readings, likely failure modes with recommended checks, and work orders in ServiceNow, Maximo or Teams.
PDF, Office files, e-mail, images, audio, video, code and databases turned into retrieval-ready chunks — with OCR and transcription when you install the extras.
Per-tenant encryption keys, role and data-scope access checks, audit events, and outbound calls checked against SSRF on every provider request.
Every Nexus layer ships a working local implementation suitable for dev and CI, plus a documented extension contract for production. Wire in your own LLM, vector DB, KMS, SIEM, or policy engine — without touching any other layer.
| Extension point | Layer | Ships today | Production swap |
|---|---|---|---|
| Embedding provider | Retrieval | FastEmbed BGE (local ONNX) | OpenAI (built in) · any FastEmbed model · your own embedder |
| Vector DB | Retrieval | In-memory or file-backed | pgvector (schema included) · MongoDB Atlas · Pinecone · Weaviate · Qdrant |
| Graph DB | Retrieval | File-backed JSON | Neo4j · AWS Neptune |
| Model gateway | Guardrails | Answer composition only | OpenAI · Anthropic · Bedrock · Azure · Vertex |
| PII engine | Guardrails | Regex + Luhn validation | Microsoft Presidio · AWS Comprehend |
| Policy engine | Guardrails | Substring policies | OPA · Cedar · custom DSL |
| Auth provider | Engagement | API keys (constant-time) | OIDC · JWT · SSO |
| Session store | Engagement | In-memory dict | Redis · PostgreSQL |
| Key material | Security | Env var → HKDF | AWS KMS · HashiCorp Vault · Azure Key Vault |
| Audit storage | Security | JSONL append | SIEM · data lake · WORM storage |
| Telemetry export | Observability | Config validated (no push) | OTLP · Prometheus · Datadog · Splunk · CloudWatch |
| Object store | Pipeline | Local filesystem | Amazon S3 · Azure Blob · MinIO |
Every external dependency is behind a documented extension contract. Choose the integration pattern that fits your team's architecture today — and change it later without a rewrite.
Import NexusClient — processing, retrieval and guardrails in one process, with no subprocess or network hop.
Wire your own policy engine via the Authorizer Protocol — bring your existing access-control logic.
Start the engagement layer as a FastAPI service. Front with your ingress and terminate TLS there.
The root nexus CLI invokes each layer via subprocess — never imports child-layer code directly.
Deploy each layer as its own container. Cross-layer integration via config, JSONL, and HTTP — no shared runtime.
Authenticated encryption, Luhn-validated PII detection, SSRF-safe outbound calls, prompt-injection screening of questions and retrieved text, constant-time auth, and fail-closed key handling are the baseline. This is rare in AI frameworks, and it's the first thing security teams check.
The root package and every layer ship their own pytest suite. No random seeds, no cloud credentials, no external services — the only download is two small open models on the first run. Green build on every commit, safe for any CI gate, and because Nexus is open source, you can read every one of them.
Nexus is released under the Apache License 2.0 — free to use, modify, and ship commercially. The retrieval, guardrails, encryption, and audit logic that decide what your AI is allowed to say are all readable, testable, and forkable.
Every PII pattern, every policy check, every key-derivation step is in the open. Reviewers audit real source instead of taking a datasheet on trust — which is the difference between a two-week security review and a two-month one.
Apache-2.0 includes an express patent grant and cannot be revoked for any version you already have. If our commercial relationship ends tomorrow, everything you built on Nexus keeps running.
Build it into your own product, commercial or not. Every external dependency sits behind a documented extension contract, so replacing our embedder, store, or policy engine with yours is a documented swap — not a rewrite.
Nexus is not a side project we open-sourced and walked away from — it is the core we build our own products on. Every fix and hardening pass those products need lands in the open-source framework you install.
Turn every connection into context. Branded digital business cards, intelligent lead capture, and AI-powered relationship intelligence for individuals, teams, and enterprises.
Take a tour →Your context-aware chief-of-staff — capturing context, automating follow-ups, and keeping you continuously informed across every channel.
Get early access →Conversational commerce for local brands — conversational ordering, personalized recommendations, and automated delivery coordination.
Join the waitlist →Install it, read it, run it — no sales call, no licence key, no trial period. From a single-process library to a full per-layer microservice deployment.
Need it operated for you, with support and an SLA? Talk to us.