Enterprise security

Security boundaries you can inspect

Kavros provides a self-hosted control plane for autonomous agents and employee AI access. Signed policy, isolated evaluation, identity, usage controls, and audit evidence work together inside your AWS environment.

Agent enforcement

Authenticate workload traffic, evaluate outbound targets and DLP rules, and record the decision before the request continues.

Employee AI governance

Give teams approved model access with OIDC SSO, BYOK providers, quotas, budgets, routing controls, usage visibility, and configurable Chat retention.

What Kavros provides

What attestation does not prove

Attestation provides evidence about enclave measurement and execution context. It does not prove that a customer policy is correct, that an allowed action is safe, that a model provider is trustworthy, or that surrounding customer infrastructure is uncompromised.

Kavros supports compliance evidence collection. It does not make an organization SOC 2 compliant by itself.

Employee Chat privacy

Chat messages are stored in the customer control-plane database for user history and usage attribution. Organization admins can configure unlimited retention or a 7, 30, 90, 365, or 730-day inactivity window. Expired chats and messages are deleted server-side, while usage records remain for metering and audit.

Procurement and compliance checklist

Capabilities enterprises evaluate during security review, all part of the self-hosted deployment.

Identity and access

  • OIDC single sign-on with per-organization identity providers
  • SCIM 2.0 user and group provisioning, with soft deactivation
  • TOTP multi-factor authentication, enforceable org-wide
  • Role-based access: Super Admin, Org Admin, Auditor

Audit and evidence

  • Hash-chained administrative audit log with integrity verification
  • SOC 2 evidence bundle export (JSON) and CSV exports
  • Policy approval history, incident timelines, attestation records
  • Two-person approval with Ed25519-signed policy enforcement

Data controls

  • Self-hosted: traffic and database stay in your AWS account
  • Configurable employee-chat retention (7 to 730 days)
  • Content policy rules with block, redact, warn, and audit actions
  • Workload API keys hashed at rest; provider keys encrypted at rest

Deployment

  • Terraform module with hardened defaults (private hosts, no SSH, RDS deletion protection)
  • Nitro Enclave evaluation with NSM attestation records
  • Policy signing key custody: Kavros-held or customer-held
  • Documented backup, restore, and key-rotation procedures

Detailed architecture and deployment security review materials are available on request. Machine-readable disclosure: /.well-known/security.txt.

Security review and disclosure

Request the detailed architecture and deployment security review materials, or report a vulnerability privately.