---
source_url: "https://kimss.ai/?utm_source=openai"
title: Kimss AI — Secure Enterprise Agent Control Plane
mirrored_at: 2026-08-31T01:32:01.350Z
host: kimss.ai
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/kimss.ai/index__q__utm_source_openai"
---

> **Original source:** https://kimss.ai/?utm_source=openai

Secure Enterprise Agent Control Plane

## Bring your AI agents.  
We provide the control plane.

Register every agent, verify identity at the gateway, sever access with one switch — and keep the audit trail that survives the incident.

Scroll anytime to keep reading. The tour plays end to end once you start it.

control plane

## Three pillars. _No soft promises._

01

### Centralized Registry & Governance

Register externally built agents and map each one to a human Entra identity. Provision the fleet with SCIM.

02

### Authoritative Execution Guardrails

Tool-level authorization at the gateway. Flip one switch and Kimss severs the agent’s access for routed traffic.

03

### Immutable Audit Trails

Append-only telemetry and audit records for governed requests. Optional APIM GatewayLogs into Log Analytics when the compliance gateway path is enabled.

product

## The control plane you _actually open_ every day

Not a slide deck — the same Vault, Agents, and Gateway views your team uses after signup. Identity-tied keys, spend caps, and logged calls in one shell.

[Open the workspace](https://kimss.ai/app/signup)

-   Azure AI Foundry ready
-   Logged API calls
-   Spend caps
-   Identity-tied keys

kimss workspace · production · gateway live

### Registered agents

Gateway-routed · identity mapped · kill switch ready

ALL ROUTED

Governed today **12,480**

Spend cap **68%**

Intercepted **3**

AgentOwnerStatusCalls

support-routerentra:eyalmlive4.2k

rag-analystentra:opslive2.8k

tool-runnerentra:svccapped890

architecture

## Separate _AI intelligence_ from the _body_ that executes it

Stateless LLM providers stay yours. Memory, tools, and security run through Kimss — identity, guardrails, and audit in the gap.

### The Brain

Your keys. Your tenancy.

-   Azure OpenAI
-   OpenAI
-   Anthropic
-   Any OpenAI-compatible endpoint

**Kimss** Identity Kill Audit

### The Body

Execution you can govern.

-   Registered agents
-   Memory & checkpoints
-   Tools & MCP
-   Runtime authorization

security

## You hold the keys. We _enforce the rules_.

Kimss is a control plane, not a second model vendor. Provider credentials stay yours. The proxy meters the hop without archiving proprietary text.

-   **Key Vault envelope encryption.** BYO API keys are AES-GCM sealed with a per-secret DEK, then wrapped RSA-OAEP-256 by Azure Key Vault. The API is client-write-only.
-   **No default prompt retention.** The proxy records correlation IDs, identity claims, and token counts — not full request/response bodies in the telemetry pipeline.

[Read the Trust Center](https://kimss.ai/trust)

compliance

## Built for _regulated industries_

Microsoft Entra SSO SCIM 2.0 APIM GatewayLogs Retention controls Article 12–oriented

### Gateway-verified records

When APIM gateway mode is enabled, diagnostics feed Log Analytics for gateway-level records alongside app-side telemetry.

### Your providers, your regions

Inference stays on the vaulted endpoints you registered (OpenAI-compatible or native Anthropic). First use: vault a model, create an agent, then `POST /v1/agents/run` with an API key. Kimss does not host or relocate your models.

### Identity-bound agents

Human access via Entra ID. Agents map to people. The kill switch severs gateway access.

pricing

## Unlimited workspace members. Priced on _governed requests_.

Meter what the control plane governs — register, report, and routed calls. Inference on your vaulted endpoints remains your provider bill.

## Bring your agents.  
_Take the control plane._

Free tier includes 25,000 governed requests/month. No credit card required.