Security as an architectural property, not a checkbox.
Kovac is designed so AI, tools and users never access enterprise data directly. Every action runs through policy evaluation, signed execution and audit.
Security posture at a glance
Zero-trust for data
No user, tool or AI agent accesses enterprise data directly.
No-IO control kernel
Deterministic, replayable policy decisions – auditable by inspection.
Cryptographic chain of custody
Plans, grants and decisions are signed, immutable artifacts.
How data flows
Sources → governed connectors → policy evaluation → bounded execution → audited output. AI and orchestration are governed clients; retrieval happens outside the kernel boundary.
Access control
Policy-as-code and a permission graph; column-level clearances; scoped, time-boxed grants. Authentication via OIDC, with SSO and SCIM available on higher tiers.
Audit and lineage
Signed decision traces, full lineage, and time-travel reconstruction of governed state – audit-readiness generated by the architecture, not assembled by hand.
Deployment and isolation
Multi-tenant, single-tenant, private cloud, and on-premise or air-gapped where required, across AWS, Azure or GCP, with data-residency control.
Compliance support
Kovac provides GDPR-aware governance and is designed to support control expectations around access control, audit evidence, data minimisation, segregation of duties and lineage. Cyber Essentials held; SOC 2 and ISO 27001 on the roadmap.
GDPR-aware governance; not legal compliance advice.
Need the security detail?
Request the Security Summary, or book a walkthrough to discuss deployment, data handling and audit requirements.