Isolation, network rules and vaults
How Kosem limits what each agent can reach, and keeps a record of what it does.
Every agent is isolated, identified and limited by rules your team sets, enforced outside the agent's reach.
Isolation
Each agent works in its own microVM, with its own kernel, wherever it runs. Agents don't share machines with each other or with your files.
Network rules
Each agent reaches only the destinations its badge names. Everything else is blocked, and blocked attempts show up in its activity.
Vaults
Secrets and network credentials stay in the vault. When an agent needs one, the vault issues a short-lived key scoped to that task and destination. The real key never enters the microVM.
Audit, SSO and SOC 2
Every agent's actions and every change to its access are recorded in an audit log you can export to your own tools. Your team signs in through your identity provider, and we share our SOC 2 report on request.