Security boundaries you can inspect
Kavros provides a self-hosted control plane for autonomous agents and employee AI access. Signed policy, isolated evaluation, identity, usage controls, and audit evidence work together inside your AWS environment.
Agent enforcement
Authenticate workload traffic, evaluate outbound targets and DLP rules, and record the decision before the request continues.
Employee AI governance
Give teams approved model access with OIDC SSO, BYOK providers, quotas, budgets, routing controls, usage visibility, and configurable Chat retention.
What Kavros provides
- Runtime policy proposals, two-person approval, signatures, version history, simulation, and rollback requests.
- AWS Nitro Enclave evaluation with attestation records for protected traffic.
- Hash-chained administrative audit logs with integrity verification and evidence exports.
- Workload, team, user, model, and organization-level usage controls.
- Self-hosted deployment so customer traffic and databases stay in the customer AWS account.
What attestation does not prove
Attestation provides evidence about enclave measurement and execution context. It does not prove that a customer policy is correct, that an allowed action is safe, that a model provider is trustworthy, or that surrounding customer infrastructure is uncompromised.
Kavros supports compliance evidence collection. It does not make an organization SOC 2 compliant by itself.
Employee Chat privacy
Chat messages are stored in the customer control-plane database for user history and usage attribution. Organization admins can configure unlimited retention or a 7, 30, 90, 365, or 730-day inactivity window. Expired chats and messages are deleted server-side, while usage records remain for metering and audit.
Procurement and compliance checklist
Capabilities enterprises evaluate during security review, all part of the self-hosted deployment.
Identity and access
- OIDC single sign-on with per-organization identity providers
- SCIM 2.0 user and group provisioning, with soft deactivation
- TOTP multi-factor authentication, enforceable org-wide
- Role-based access: Super Admin, Org Admin, Auditor
Audit and evidence
- Hash-chained administrative audit log with integrity verification
- SOC 2 evidence bundle export (JSON) and CSV exports
- Policy approval history, incident timelines, attestation records
- Two-person approval with Ed25519-signed policy enforcement
Data controls
- Self-hosted: traffic and database stay in your AWS account
- Configurable employee-chat retention (7 to 730 days)
- Content policy rules with block, redact, warn, and audit actions
- Workload API keys hashed at rest; provider keys encrypted at rest
Deployment
- Terraform module with hardened defaults (private hosts, no SSH, RDS deletion protection)
- Nitro Enclave evaluation with NSM attestation records
- Policy signing key custody: Kavros-held or customer-held
- Documented backup, restore, and key-rotation procedures
Detailed architecture and deployment security review materials are available on request. Machine-readable disclosure: /.well-known/security.txt.
Security review and disclosure
Request the detailed architecture and deployment security review materials, or report a vulnerability privately.