Running someone else's agent should be safer than building your own
Every agent on Kaoohi passes the same pipeline before it can touch your business. This page states what is enforced today — and what is still in progress.
The review pipeline
Four controls, applied to every agent in the store.
Reviewed by a human
An agent is listed only after review. Its container image is scanned, and the destinations it wants to reach are declared by its author up front — an undeclared destination found in the image forces review.
Scoped to what you grant
Credentials are encrypted at rest in a credential vault. An agent receives only the connectors you grant it, and an action outside its declared capabilities is denied before any credential is injected.
You approve every action
Calls, text messages, emails, direct messages and publishes wait for your approval. The list is a platform floor compiled into the server — no agent manifest and no tenant setting can lower it.
Isolated runtime
Your agents run in a namespace of their own, separated from every other tenant, under a restricted pod security policy. A running pod cannot widen its own permissions.
The six layers
From the outside in:
- 1Review — human-reviewed listings, scanned images
- 2Vault — credentials encrypted at rest
- 3Approval gate — consequential actions wait for a person
- 4Egress — destinations declared, screened and consented
- 5Isolation — one runtime per organisation
- 6Compliance — status stated honestly, in progress where it is
Review, vault, the approval gate and isolation are enforced in the platform today. Egress is declared, screened and consented at listing time; its per-pod runtime allowlist enforcement is in progress. Compliance status is stated below.
Encrypted at rest
Connector credentials are stored encrypted in the platform's credential vault. Model keys are encrypted in the platform database and again at the model gateway that routes the call.
Scoped grants
An agent can call only the connectors your organisation granted it. When an action is evaluated, the platform checks it against the agent's declared capabilities before any credential leaves the vault.
Tenant isolation
Each organisation's agents run in their own Kubernetes namespace, separated from every other tenant, under a restricted pod security policy enforced at namespace creation.
Where agents can connect
- Every actor declares the external destinations it may reach, tagged by who chose them: the deploying account (its own connector instance), the platform, or the actor's author.
- Destinations fixed by the actor's author are shown to the deploying user for consent before deployment.
- Declared and screened at listing time today; per-pod runtime allowlist enforcement is in progress.
Where it is hosted
Your agents run on Kaoohi's managed cluster, one namespace per organisation. We do not claim a hosting region on this page: the production hosting choice is agreed explicitly in pilot agreements.
GDPR
We process personal data under our published privacy and cookie policies.
Formal compliance documentation (records of processing, data-processing agreements) is being assembled — ask us for its current state before you rely on it.
The AI Act
Kaoohi acts as the provider of the agents it lists under the EU AI Act: the technical documentation an actor needs is filed before that actor can be approved for the store, and a prohibited classification can never be listed.
Sub-processors
Services that process customer data as part of running Kaoohi:
- Supabase — database, authentication and file storage
- Stripe — billing and payment processing
- Model providers — OpenAI, Anthropic, Google, Azure OpenAI, Z.AI, OpenRouter, selected per deployment
- Resend — transactional email
- Langfuse — observability of model calls
- Cal.com — demo booking, used only when you book a demo
Compliance status
No security certification (SOC 2, ISO 27001) is held or claimed today. Everything this page states as enforced is enforced in the code and reviewed as it changes; compliance work beyond that is in progress.
Questions?
Security questions go to the team that runs the platform.