Skip to content

Running someone else's agent should be safer than building your own

Every agent on Kaoohi passes the same pipeline before it can touch your business. This page states what is enforced today — and what is still in progress.

The review pipeline

Four controls, applied to every agent in the store.

Reviewed by a human

An agent is listed only after review. Its container image is scanned, and the destinations it wants to reach are declared by its author up front — an undeclared destination found in the image forces review.

Scoped to what you grant

Credentials are encrypted at rest in a credential vault. An agent receives only the connectors you grant it, and an action outside its declared capabilities is denied before any credential is injected.

You approve every action

Calls, text messages, emails, direct messages and publishes wait for your approval. The list is a platform floor compiled into the server — no agent manifest and no tenant setting can lower it.

Isolated runtime

Your agents run in a namespace of their own, separated from every other tenant, under a restricted pod security policy. A running pod cannot widen its own permissions.

The six layers

From the outside in:

  1. 1Review — human-reviewed listings, scanned images
  2. 2Vault — credentials encrypted at rest
  3. 3Approval gate — consequential actions wait for a person
  4. 4Egress — destinations declared, screened and consented
  5. 5Isolation — one runtime per organisation
  6. 6Compliance — status stated honestly, in progress where it is

Review, vault, the approval gate and isolation are enforced in the platform today. Egress is declared, screened and consented at listing time; its per-pod runtime allowlist enforcement is in progress. Compliance status is stated below.

Encrypted at rest

Connector credentials are stored encrypted in the platform's credential vault. Model keys are encrypted in the platform database and again at the model gateway that routes the call.

Scoped grants

An agent can call only the connectors your organisation granted it. When an action is evaluated, the platform checks it against the agent's declared capabilities before any credential leaves the vault.

Tenant isolation

Each organisation's agents run in their own Kubernetes namespace, separated from every other tenant, under a restricted pod security policy enforced at namespace creation.

Where agents can connect

  • Every actor declares the external destinations it may reach, tagged by who chose them: the deploying account (its own connector instance), the platform, or the actor's author.
  • Destinations fixed by the actor's author are shown to the deploying user for consent before deployment.
  • Declared and screened at listing time today; per-pod runtime allowlist enforcement is in progress.

Where it is hosted

Your agents run on Kaoohi's managed cluster, one namespace per organisation. We do not claim a hosting region on this page: the production hosting choice is agreed explicitly in pilot agreements.

GDPR

We process personal data under our published privacy and cookie policies.

Formal compliance documentation (records of processing, data-processing agreements) is being assembled — ask us for its current state before you rely on it.

The AI Act

Kaoohi acts as the provider of the agents it lists under the EU AI Act: the technical documentation an actor needs is filed before that actor can be approved for the store, and a prohibited classification can never be listed.

Sub-processors

Services that process customer data as part of running Kaoohi:

  • Supabase — database, authentication and file storage
  • Stripe — billing and payment processing
  • Model providers — OpenAI, Anthropic, Google, Azure OpenAI, Z.AI, OpenRouter, selected per deployment
  • Resend — transactional email
  • Langfuse — observability of model calls
  • Cal.com — demo booking, used only when you book a demo

Compliance status

No security certification (SOC 2, ISO 27001) is held or claimed today. Everything this page states as enforced is enforced in the code and reviewed as it changes; compliance work beyond that is in progress.

Questions?

Security questions go to the team that runs the platform.