Private betaRequest access

Legal · Security

Security

What we do to protect the agent telemetry you hand us, where that data lives, and how to reach us if you find a hole.

Last updated June 2026

01How we think about it

Kowari sits in the path of what your agents do — the plans, the tool calls, the money they move. A control plane that leaks is worse than no control plane. So security is not a section we bolt on; it is the reason the product is allowed to exist.

We are early, and we say so. The controls below are real and in place today; SOC 2 and a formal third-party audit are on the roadmap, not behind us. We would rather tell you that than imply a badge we have not earned.

02Where your data lives

Self-host Kowari inside your own VPC and your trace data never crosses your network boundary. For teams that cannot send agent telemetry to a third party, this is the default.

On our cloud, each customer gets an isolated tenant. Trace data is encrypted in transit with TLS 1.2+ and at rest with AES-256, and one tenant cannot reach another's data.

03Access and keys

Access to production is limited to the engineers who need it, gated behind SSO and hardware-backed multi-factor auth, and logged. We grant the least access that does the job and review it regularly.

Secrets and API keys are stored in a managed secret store, never in source. We do not train models on your data and we do not move it out of your tenant.

04Reporting a vulnerability

If you have found a security issue, email security@kowarilabs.com. Tell us what you found and how to reproduce it. We will acknowledge within two business days and keep you posted while we fix it.

We will not threaten or pursue researchers who act in good faith — test only against your own account, do not access or destroy other people's data, and give us a reasonable window to ship a fix before going public. Do that and we will thank you, publicly if you want.