Security

Enterprise trust by design

Automation without surrendering control. Kairo encrypts secrets, gates mutations, and fails closed when evidence is missing.

  • Encryption

    Server credentials are encrypted at rest. Sensitive fields are never echoed in list/detail API responses for browser clients.

  • Policies & guardrails

    Dangerous recursive host operations are blocked. Deploy paths must be confirmed. Success claims require remote tool evidence.

  • Human approval

    Mutating remote work surfaces approval UI. Operators choose persistent yes per server or stay read-only per action.

  • Compliance-ready posture

    httpOnly session cookies for the dashboard BFF, rate limiting defaults in production, CSP/HSTS on the frontend, and redacted error surfaces in prod.

  • Audit logs

    Deployment history and run records track webhook and chat-driven work for operator review.

  • Infrastructure safety

    Agent-transport runs as least-privilege. Sudo is elevated carefully where allowed; agent hosts avoid sudo loops entirely.

For questionnaire requests or architecture deep-dives, contact us.