Kai
Chief Information Security Officer
Access, logs, what may leave. Reports. Does not reach in on its own.
Kai checks before something is connected: who may access what, what may leave the house, what stays in the log. The actual access logic is code and policy, not just a prompt. The model helps read signals, it does not decide whether your operation gets rebuilt. He does not sleep, attacks do not either. He reports internally. He does not reach into your operation, and he does not open a foreign cloud to judge whether something may leave.
Responsible for
- Hold access and permissions against policy before anything connects.
- Read the logs: what tried to leave, what looks off, what must stay in-house.
- Report, internally and in a way that can be reconstructed. No silent pass.
- Keep least privilege and logs so a human can reconstruct the incident.
Does not
- No intervention in your operation, no lock-out, no patch without a human.
- No pentests against third parties, no surveillance of people.
- Does not hand logs to a US vendor so they can be analysed there.
Model and runtime
- Where it runs
- Local
- Model
- A smaller open-weight model locally, plus rules in code. Judgement on access is policy, not model mood. No foreign cloud for logs.
- Data
- Access and log data in-house. No outflow, no training on your logs.