Bring your agents.
Kimss is the control plane.

Kimss is the Model-Agnostic Enterprise Gateway: one API key for chat and agents, Entra SSO, tenant isolation, spend controls, and audit-ready telemetry. Route to your own OpenAI-compatible endpoint or Azure AI Foundry.

You keep the runtime. Kimss adds governance, billing, and a single developer surface — the secured multi-tenant control plane your platform team would otherwise build on top of Foundry or BYO models.

Comparison

A hosted model account alone vs Kimss as the gateway

Kimss does not replace your model provider. It is the product layer that turns Foundry, OpenAI-compatible BYO, or mixed fleets into a governed, multi-tenant AI platform.

Capability Model account alone Kimss gateway
Model & agent execution Native Foundry projects and deployments Foundry, vaulted custom:*, or mixed — Kimss routes per workspace
Multi-tenant workspaces Build and operate yourself Built-in PostgreSQL row-level isolation + workspace model
Identity (Entra SSO, SCIM) Wire Entra and provisioning yourself Entra SSO, admin consent, optional SCIM 2.0 (Identity & SSO)
One key: chat + agents Separate integration paths per modality One gateway — Studio to build, Gateway to integrate
Spend control Ad-hoc or per-project budgets Governed-request meters, kill switch, FinOps estimated spend
Usage & chargeback Custom metering and exports Trust-labeled meters, execution logs, per-tenant reporting
Audit trail for procurement You design the logging sink Optional APIM gateway logs to Log Analytics (compliance architecture)
Time to embed agents in product Weeks to months of orchestration work Script-tag widget in minutes, or pip install kimss for backend - embed guide
Procurement Foundry billing only Azure Marketplace Kimss Enterprise PAYG + invoice options

Model & agent execution

Foundry alone
Native Foundry projects and deployments
With Kimss
Same Foundry backend - Kimss routes per workspace

Multi-tenant workspaces

Foundry alone
Build and operate yourself
With Kimss
Built-in PostgreSQL row-level isolation + workspace model

Identity (Entra SSO, SCIM)

Foundry alone
Wire Entra and provisioning yourself
With Kimss
Entra SSO, admin consent, optional SCIM 2.0

One key: chat + agents

Foundry alone
Separate integration paths per modality
With Kimss
One gateway, two playgrounds - same Kimss API key

Spend control & chargeback

Foundry alone
Ad-hoc budgets; custom metering
With Kimss
governed-request allowances, caps, normalized credits, execution logs

Embed in your product

Foundry alone
Build UI, auth, and metering yourself
With Kimss
Avatar UI-in-a-Box: script / React / Vue + token exchange

Audit & procurement

Foundry alone
You design the logging sink
With Kimss
Optional APIM → Log Analytics; Marketplace PAYG

Evaluating vendors? Read the full Kimss vs Azure AI Foundry comparison or browse all evaluation pages at /compare. For Shadow AI risk, see /shadow-ai.

Differentiators

What CTOs get with Kimss

Six reasons platform and security teams choose Kimss on top of Foundry - not instead of it.

The integration gap

Using AI to write code is not the same as shipping governed agents in your product. Kimss is the orchestration layer you would otherwise staff with platform engineers.

Flip the order

Do not prototype on raw APIs then scramble for identity, metering, and audit. Start with the control plane; ship features on a governed foundation.

One gateway

Chat inference and full agentic flows - tools, retrieval, code interpreter - on one Kimss key. Foundry routing per workspace, not separate vendor stacks.

Shadow agents & prompt ownership

Workspace visibility and execution logs answer “who changed that prompt?” without a crisis email. Govern agents like production software.

Audit-ready by design

Gateway logs to Log Analytics, admin audit trail, and security questionnaire evidence. Formal attestations available under NDA during procurement.

Gateway: governed integrations

Make a first call and watch live telemetry light up. Secure chat embed (UI-in-a-Box), endpoint registration, and links to Usage, Audit, and Product integrations - your control plane demo in one console.

Azure-native, not another cloud

Managed Identity, Entra, dedicated Foundry mapping per tenant - the same stack your CISO already approved. Procure via Azure Marketplace.

Architecture

How the stack fits together

Kimss sits between your applications and Foundry - auth, governed requests, and routing before models run.

Client / SDK / SPA
Kimss Gateway (auth, governed requests, routing)
Optional APIM (audit, token metrics)
Model providers (BYO / Foundry / external)

See the full interactive system spec: Kimss Architecture →

FAQ

Questions CTOs ask

We already pay for Foundry - why Kimss?
Foundry (or any OpenAI-compatible endpoint) is the execution plane. Kimss is the Model-Agnostic Enterprise Gateway: identity, billing, logs, SDK, and workspace governance. You keep the runtime; Kimss removes the platform engineering work to make it safe for every team and customer.
Can we build this ourselves?
Yes - budget platform engineering for orchestration, metering, audit sinks, and ongoing provider API churn. Kimss ships that layer as a managed product. Many teams underestimate months of work before the first governed agent ships in production.
Is this another vendor or cloud?
No. Kimss runs on Azure, uses Entra for identity and Azure Marketplace for procurement, and routes inference to your vaulted OpenAI-compatible, Azure OpenAI, or native Anthropic endpoint. It is an Azure-native control plane - not a separate hyperscaler.
What about security review?
Start with the Trust Center, then Security & Trust Architecture and Security & compliance architecture. Formal third-party attestations and certification specifics are provided under NDA as part of procurement; your order form and DPA remain the legal source of truth.
Does Kimss store our prompts?
Kimss default telemetry is metadata and token counts, not full prompt archives. See the Trust Center and Security & Trust Architecture for the payload contract.
How do we buy it?
Three paths: Azure Marketplace Kimss Enterprise PAYG, self-serve Developer / Production / Scale, or sales-led Enterprise contracts. See Plans & subscriptions and Enterprise for onboarding.
Customer proof

Every worker uses kimss.KimssClient for chat and agents. No direct OpenAI or Azure AI SDK calls in application code - a runtime guard enforces that policy.

- worksfusion Digital Employee fleet on Kimss · Read the story →

Ready for the CTO brief conversation?

Share this page with your platform team, or dive into the full documentation.