Kindo
SOC for AI ยท Strategic Decision Brief
August 2026
Strategic Decision Brief โ€” August 2026

SOC for AI: Two Different Spaces.

Kindo is the operational control plane where agents run. AIRS, CrowdStrike, and Microsoft are the security inspection layer. They are not competitors โ€” they are partners. This document shows the hard moats, the soft moats, and what Krishna can sell when.

๐Ÿ”’ Air-Gapped On-Prem
๐ŸŽฏ 6 Features for Krishna
๐Ÿ“Š Guardian Agent (Gartner)
01
This analysis was built by cross-referencing: Charlie's four-pillar SOC for AI strategy (Aug 8), Krishna's competitive pressure from AIRS (Portfolio Meeting, Aug 10), Kishore's five SOC for AI objectives, Odin K's codebase verification (ADR-0028, ADR-0031), and Palo Alto's actual product documentation. Every capability claim was verified against source โ€” not marketing.

1. Are these features live in Kindo's codebase?

Verified by Odin K against guardrail.py, ADR-0028, ADR-0031, MCP gateway. Pillars 1-2 confirmed live in production.

2. Does AIRS really have on-prem?

Partial. Network Intercept deploys in customer cloud, but API Intercept is cloud-hosted. Not fully air-gappable. Taking partial as a no.

3. Are we in the same category as AIRS?

No. Different spaces. Kindo = operational control plane. AIRS = security inspection layer. Not competitors โ€” partners.

4. Should Kindo build what it doesn't have?

For 5 key gaps (shadow AI, model scanning, red teaming, network interception, endpoint detection): DO NOT BUILD. ORCHESTRATE via MCP instead.

We are at a crossroads now and we are thinking how much we build versus how much we rely on partners. If we are six months behind this, it's going to be really hard for us.

โ€” Krishna Marella, Portfolio Meeting, Aug 10
02
Operational Control Plane

KINDO

Where agents run. Where governance executes. Where credentials live. Where execution is sandboxed. Governance isn't a layer Kindo added โ€” it's how the platform works.

  • Agent Execution Platform (Action Bots, Action Chat)
  • VMI Sandbox (SQL, Object Store, VectorDB)
  • Deep Hat Security Model
  • Secrets Manager
  • Full Air-Gapped On-Prem
  • Cross-Vendor Independence
  • MCP Federated Gateway (Cerbos RBAC)
Security Inspection Layer

AIRS ยท CrowdStrike ยท Microsoft

Where network traffic is inspected. Where endpoints are monitored. Where shadow AI is discovered. Where models are scanned for backdoors. Infrastructure-level security โ€” by design.

  • Network Traffic Interception (AIRS)
  • Shadow AI Discovery (AIRS + CrowdStrike + Microsoft)
  • AI Model Scanning (AIRS / Protect AI)
  • Automated Red Teaming (AIRS โ€” 500+ attacks)
  • Endpoint Agent Detection (CrowdStrike + Microsoft Defender)
  • SIEM/SOAR Native (Google SecOps + Microsoft Sentinel)
Kindo orchestrates security partners via MCP โ€” it doesn't replace them. CrowdStrike detects shadow AI on endpoints, AIRS inspects network traffic, Google SecOps aggregates logs. All of it flows into Kindo's governance dashboard. One control plane.
03
Hard moat = competitors genuinely cannot match this. Soft moat = both have a version, but Kindo's is embedded in the execution layer โ€” switching cost is the moat.
Hard Moat โ€” Only Kindo

Full Air-Gapped On-Prem HARD MOAT

K8s Helm, 100% local, no internet required. Proven at Deloitte. AIRS = partial (network intercept in customer cloud, control plane stays in PANW). CrowdStrike = no. Microsoft = no.

Agent Execution Platform HARD MOAT

Action Bots, Action Chat, VMI Sandbox (SQL, Object Store, VectorDB). No security vendor runs agents โ€” they inspect them from outside.

Deep Hat Security Model HARD MOAT

Native AI-powered security intelligence running inside the execution platform. No equivalent in AIRS, CrowdStrike, Google, or Microsoft.

Cross-Vendor Independence HARD MOAT

Any LLM, any security partner, any deployment. AIRS = PANW only. CrowdStrike = CS ecosystem. Microsoft = MSFT ecosystem.

Soft Moat โ€” Both Have It, Kindo Has Context

MCP Federated Gateway SOFT MOAT

Kindo: live, federated, Cerbos RBAC. AIRS: via Portkey acquisition. CrowdStrike: built-in connectors. Microsoft: partial.

AI Inference Governance SOFT MOAT

Both route and control model access. Kindo sees execution context (intent, decision chains). AIRS sees API traffic.

DLP + Prompt Inspection SOFT MOAT

Both inspect content. Kindo's runs inside the execution layer (guardrail.py). AIRS inspects at the network boundary.

Policy Enforcement + Audit SOFT MOAT

Both enforce rules and log actions. Kindo's policies are embedded in agent execution. AIRS policies apply at the network/API layer.

04
Capability
Kindo
AIRS
CrowdStrike
Microsoft
Hard Moat (Kindo Only)
Full Air-Gapped On-Prem
YES
PARTIAL
NO
NO
Agent Execution Platform
YES
NO
NO
NO
Deep Hat Security Model
YES
NO
NO
NO
Cross-Vendor Independence
YES
PANW only
CS only
MSFT only
Secrets Manager
YES
NO
NO
Partial
Soft Moat (Both โ€” Kindo has context)
AI Inference Governance
LIVE
YES
NO
YES
MCP / Tool Orchestration
LIVE
Portkey acq.
Built-in
Partial
DLP
LIVE
YES
NO
YES (Purview)
Prompt / Response Inspection
LIVE
YES
Partial
YES
Policy Enforcement
LIVE
YES
Partial
YES
Audit Logging
LIVE
YES
YES
YES
Security Partner Territory (Do Not Build)
Shadow AI Discovery
ORCHESTRATE
YES
YES
YES
AI Model Scanning
Leave to partners
YES
NO
NO
Automated Red Teaming
LIGHTWEIGHT
YES
Partial
NO
Network Traffic Interception
N/A โ€” by design
YES
NO
NO
Endpoint Agent Detection
ORCHESTRATE
NO
YES
YES (Defender)
SIEM/SOAR Native
ORCHESTRATE
NO
NO
YES (Sentinel)
05
Feature 01 LIVE

"Who controls which models our agents use?"

AI Inference Governance. All CDA agent traffic routes through Kindo. Model access control, DLP, audit logging on every call.

Feature 02 LIVE

"Can an agent access systems it shouldn't?"

MCP Tool Gateway with Cerbos RBAC. Which agents get which tools โ€” Jira, ITSM, CrowdStrike โ€” is policy, not code.

Feature 03 AUG

"Can we set our own governance rules?"

Client-configurable policy engine. Per-client rules on CDA agents. Configurable by Deloitte operators, not hardcoded.

Feature 04 AUG

"Can we audit every AI decision in our own SIEM?"

OTel telemetry export to Google SecOps, Splunk, whatever the client runs. Every agent action in their audit log.

Feature 05 SEP

"Show me what our AI agents are doing right now."

Governance dashboard. Which agents are active, what tools they use, policy compliance status. What the CISO sees in the QBR.

Feature 06 OCT

"What if an agent goes rogue?"

Behavioral anomaly detection. Agent A normally calls 3 tools โ€” it just called 47. CDA catches it because it knows the baseline. The demo that closes.

Dropped 4 features from the AIRS-matching version (Agent Identity, Runtime Security Upgrade, Agent Registry, Turbo Hooks). They matter for security maturity โ€” they don't close Krishna's sale. Ship the 6, layer the rest.
06
NOW โ€” Live Demo Ready
Features 01โ€“02: Inference Governance + MCP Tool Gateway
Krishna can demo these today. "Your agents are already governed. Model access, tool access, DLP, audit logging โ€” all live."
September โ€” First Expansion
Features 03โ€“04: Policy Engine + SIEM Export
"Your clients can set their own governance rules and audit every AI decision in their existing SIEM." ~3โ€“4 weeks with dedicated engineers.
October โ€” Full Story
Features 05โ€“06: Dashboard + Behavioral Anomaly Detection
"Show me what agents are doing right now. Alert me when one goes rogue." The demo that closes. ~2โ€“4 weeks after 03โ€“04.
Q4 2026 โ€” Compounding
Turbo Mode (if ENG-11252 lands)
Compiled patterns powering governance at code speed. Upside, not gate. 6-feature build ships without it.
With 3 dedicated engineers: features 01โ€“04 demoable in September, full 6-feature stack by mid-October. ~65โ€“95 eng-days (Odin sizing). Getting 3 engineers is a separate problem.

Our initial AI's assessment is faster than next year. It's โ€” we're estimating early October.

โ€” Tony, Portfolio Meeting, Aug 10
07
Platform
Kindo ยท Charlie's eng team
Builds the pillars: inference proxy, MCP gateway, telemetry, policy hooks
Platform licensing
Deployment & Amplification
T&C ยท Tony, Joana, Victor, Warren
Deploys platform at Deloitte, manages operating rhythm, amplifies each shipped feature into captured value
Utilization fee
Service Delivery
Deloitte ยท Kush, Krishna, Nathan
Charges consulting hours, delivers to end clients, captures EBITDA gains from platform + amplification
EBITDA + service revenue
Charlie builds. T&C deploys. Deloitte sells. Each layer enables the others. Nobody is displaced.
08

Prioritize GA solutions independent of AI agent platforms to ensure cross-cloud governance, full enterprise information governance, and avoid vendor lock-in.

โ€” Gartner, Market Guide for Guardian Agents, Feb 2026
The entire capability space โ€” Kindo AND the security partners โ€” falls within Gartner's Guardian Agent category. Kindo occupies the operational control plane end. AIRS/CrowdStrike/Microsoft occupy the security inspection end. Same category, different positions. $3B+ market by 2030.
09

๐Ÿ”ด Coverage Gap โ€” Reframed

Kindo governs only workloads on its platform. But this is a design choice, not a gap. Answer for CISOs: Kindo ORCHESTRATES partner detection (CrowdStrike on endpoints, AIRS on network) via MCP into one dashboard. "You don't choose between us and them โ€” you use us together."

๐ŸŸก Engineering Capacity

3-engineer staffing assumption has no Linear tickets and no Charlie commitment yet. Mitigation: Scope to MVP surface. Generalize existing pipeline, don't greenfield.

๐ŸŸก AIRS + Microsoft Momentum

AIRS 3.0 + Portkey acquisition assembling AI gateway. Microsoft has Defender + Purview + Sentinel across enterprise. Mitigation: Don't play feature-for-feature. Lead with hard moats (on-prem, execution platform) and operational control plane positioning.

๐ŸŸก Six-Month Lag Risk

Krishna: "If we are six months behind this, it's going to be really hard." Mitigation: Early-October target for 6-feature MVP. Ship 03โ€“04 first to show momentum.

๐ŸŸก Turbo Mode Dependency

ENG-11252 / PR #12155 (conflicting, off main). Upside โ€” not a gate for the 6-feature build. Mitigation: 6 features ship without Turbo. If it lands, behavioral baselines get compiled intelligence as a bonus.

10
Blocking ยท Before Monday

Microsoft's Full Capability Surface

Microsoft may be as capable as AIRS on shadow AI, model scanning, endpoint detection (Defender + Purview + Sentinel + Copilot Studio). Needs full mapping before the Krishna meeting.

Open ยท Needs Research

AIRS Claims vs. AIRS Reality

AIRS claims governance over SaaS agents, browser agents, model training. How much is shipped vs. announced? Verification needed before assuming their breadth is real.

Critical ยท Joana Validating

Does Context Actually Compound?

Kindo runs repeatable workflows. Does execution data compound into operational intelligence? If yes โ†’ compounding moat. If no โ†’ architectural advantage only.

Open ยท No Owner Yet

Measurement Framework

No metric exists to show Kush how much smarter governance is this quarter vs. last. Proposed: hook accuracy, policy violations caught, anomalies detected.

11
For Krishna (Current Clients)

Your agents run on Kindo. The security partners you already use โ€” CrowdStrike, AIRS โ€” feed into Kindo's dashboard via MCP. You don't choose between us and them. You use us together. We're the operational control plane. They're the inspection layer.

For Ron / Charlie

Kindo and AIRS are in two different spaces. Don't play feature-for-feature against Palo Alto and Microsoft. Lead with air-gapped on-prem (hard moat), agent execution platform (hard moat), and the operational control plane positioning.

For Kindo Engineering

The governance pipeline runs in production. The 6-feature build generalizes what's hardcoded. Ship small, T&C amplifies. The capabilities we DON'T build (shadow AI, model scanning, network interception) are orchestrated via MCP from partners.

12

๐Ÿ“„ SOC for AI PRD v4

Technical implementation plan โ€” four pillars, backlog grounding, October timeline. Architecture-corrected per Odin K.

๐Ÿ“Š Hard Moat / Soft Moat Analysis

Aug 2026 โ€” Tony's framework. Capabilities categorized by competitive defensibility against AIRS, CrowdStrike, Microsoft.

๐Ÿ“‹ Security Capabilities Appendix

Aug 2026 โ€” Build vs Orchestrate analysis for 8 security capabilities. Plain-English explainers for each.

๐Ÿ“‹ Capability Comparison Appendix

Aug 2026 โ€” 5-column comparison (Kindo, AIRS, CrowdStrike, Google SecOps, Microsoft) with verification status.

๐Ÿ“‹ Portfolio Meeting Transcript

Aug 10, 2026 โ€” Krishna's competitive urgency, build-vs-resell framing, six-month lag risk.

๐Ÿ“‹ Product Strategy Meeting

Aug 13, 2026 โ€” Tony, Joana, Victor. Key insight: two different spaces. Hard moat / soft moat framework.

๐Ÿ“Š Gartner Guardian Agents

Feb 2026 Market Guide โ€” Guardian Agent category definition. Eight mandatory features. $3B+ annually by 2030.

๐Ÿ”’ AIRS Coverage Analysis v2

Aug 2026 โ€” Corrected assessment. AIRS coverage wider than V1 assumed. On-prem = partial (not air-gappable).