Security built into every agent
Kosem agents are isolated, identified and limited by rules your team sets, and every action is on the record. Ask us for our SOC 2 report.
Security
Ready for your security review
Every agent is isolated, identified and limited by rules your team sets, enforced outside the agent’s reach.
The real key never enters the microVM.
A microVM per agent
Each agent works in its own microVM with its own kernel, wherever it runs, apart from your files and other agents.
Its own identity
Each agent is an identity with a named owner. Its commits, requests and questions are its own, never yours.
Network rules per agent
Each agent reaches only the destinations its badge names. Everything else is blocked.
Vaults with short-lived keys
Secrets and network credentials stay in the vault. Agents get short-lived keys scoped to their task, never the real key.
Audit log export
Every agent’s actions and every change to its access, in a log you can export to your own tools.
SSO and SOC 2
Sign in through your identity provider, with a SOC 2 report for your review.
Self-hosted runners
Run agents on your own servers, next to your code, data and network, with the same microVMs, identities and rules as anywhere else.
SOC 2 report
We share our SOC 2 report with teams evaluating Kosem. Ask for it, and for anything else your review needs.
Request the SOC 2 reportRun agents where you choose
Developers’ laptops
Each agent in its own microVM, apart from the developer’s files and keys.
Your own servers
Self-hosted runners keep agents next to your code, data and network.
Kosem cloud
MicroVMs on demand, for long tasks and agents nobody’s laptop has to carry.
Give your agents badges, not keys
Kosem is in early access with a small group of engineering teams. Tell us about yours.