Add governance to your app
Route agent traffic through the control plane. Identity-tied keys, spend caps, and logged calls from day one.
QuickstartSecure Enterprise Agent Control Plane
Stop the Confused Deputy: validate where tool commands come from mid-loop, sever access with one switch, and keep the audit trail that survives the incident.
Space pauses. M mutes. Esc exits.
what kimss is
Bottom line: Kimss AI is the Secure Enterprise Agent Control Plane — a model-agnostic gateway in front of your vaulted providers. It registers agents, binds identity, enforces an Authority Boundary against the Confused Deputy (OWASP ASI03), meters governed requests, and keeps gateway-verified audit. It does not host models and is not Kimi (Moonshot AI).
https://api.kimss.ai/v1 and Anthropic listeners that accept a Kimss Gateway key and forward to Provider Vault endpoints.basic gateway vs kimss
| Concern | Basic gateway | Kimss |
|---|---|---|
| Caller auth | Yes | Yes |
| Tool-argument provenance | No | Authority Boundary mid-loop |
| Stop dangerous actions in-process | Edge only | Kill switch + intercept before tool fires |
| Pricing meter | Often per-token / custom quote | Published governed requests |
developer hub
Route agent traffic through the control plane. Identity-tied keys, spend caps, and logged calls from day one.
QuickstartTool-level authorization at the gateway. Content safety, kill switch, and Threat Intercepts when traffic is blocked.
Guardrails docsPaste one prompt into Cascade, Cursor, or Claude Code. The agent fetches the public control-plane contract and rewires this repo. New Python agents start from Kimss Forge.
Route your trafficintegrations
Model-agnostic control plane. Keep the OpenAI or Anthropic client you already ship, or start from Kimss Forge. Coding agents onboard from the public control-plane contract.
See all docscontrol plane
Register externally built agents and map each one to a human Entra identity. Provision the fleet with SCIM.
Tool-level authorization at the gateway. Flip one switch and Kimss severs the agent’s access for routed traffic.
Append-only telemetry and audit records for governed requests. Optional APIM GatewayLogs into Log Analytics when the compliance gateway path is enabled.
product
Not a slide deck — the same Vault, Agents, and Gateway views your team uses after signup. Identity-tied keys, spend caps, and logged calls in one shell.
Open the workspaceGateway-routed · identity mapped · kill switch ready
architecture
Stateless LLM providers stay yours. Memory, tools, and security run through Kimss — identity, guardrails, and audit in the gap.
Your keys. Your tenancy.
Execution you can govern.
security
Kimss is a control plane, not a second model vendor. Provider credentials stay yours. The proxy meters the hop without archiving proprietary text.
compliance
When APIM gateway mode is enabled, diagnostics feed Log Analytics for gateway-level records alongside app-side telemetry.
Inference stays on the vaulted endpoints you registered (OpenAI-compatible or native Anthropic). First use: vault a model, create an agent, then POST /v1/agents/run with an API key. Kimss does not host or relocate your models.
Human access via Entra ID. Agents map to people. The kill switch severs gateway access.
pricing
Priced per governed request — not per model token, no hidden enterprise quote for standard tiers. Inference on your vaulted endpoints remains your provider bill.
Meter what the control plane governs — register, report, and routed calls.
Free tier includes 25,000 governed requests/month. No credit card required.