Kindo is the operational control plane where agents run. AIRS, CrowdStrike, and Microsoft are the security inspection layer. They are not competitors โ they are partners. This document shows the hard moats, the soft moats, and what Krishna can sell when.
Verified by Odin K against guardrail.py, ADR-0028, ADR-0031, MCP gateway. Pillars 1-2 confirmed live in production.
Partial. Network Intercept deploys in customer cloud, but API Intercept is cloud-hosted. Not fully air-gappable. Taking partial as a no.
No. Different spaces. Kindo = operational control plane. AIRS = security inspection layer. Not competitors โ partners.
For 5 key gaps (shadow AI, model scanning, red teaming, network interception, endpoint detection): DO NOT BUILD. ORCHESTRATE via MCP instead.
We are at a crossroads now and we are thinking how much we build versus how much we rely on partners. If we are six months behind this, it's going to be really hard for us.
โ Krishna Marella, Portfolio Meeting, Aug 10Where agents run. Where governance executes. Where credentials live. Where execution is sandboxed. Governance isn't a layer Kindo added โ it's how the platform works.
Where network traffic is inspected. Where endpoints are monitored. Where shadow AI is discovered. Where models are scanned for backdoors. Infrastructure-level security โ by design.
K8s Helm, 100% local, no internet required. Proven at Deloitte. AIRS = partial (network intercept in customer cloud, control plane stays in PANW). CrowdStrike = no. Microsoft = no.
Action Bots, Action Chat, VMI Sandbox (SQL, Object Store, VectorDB). No security vendor runs agents โ they inspect them from outside.
Native AI-powered security intelligence running inside the execution platform. No equivalent in AIRS, CrowdStrike, Google, or Microsoft.
Any LLM, any security partner, any deployment. AIRS = PANW only. CrowdStrike = CS ecosystem. Microsoft = MSFT ecosystem.
Kindo: live, federated, Cerbos RBAC. AIRS: via Portkey acquisition. CrowdStrike: built-in connectors. Microsoft: partial.
Both route and control model access. Kindo sees execution context (intent, decision chains). AIRS sees API traffic.
Both inspect content. Kindo's runs inside the execution layer (guardrail.py). AIRS inspects at the network boundary.
Both enforce rules and log actions. Kindo's policies are embedded in agent execution. AIRS policies apply at the network/API layer.
AI Inference Governance. All CDA agent traffic routes through Kindo. Model access control, DLP, audit logging on every call.
MCP Tool Gateway with Cerbos RBAC. Which agents get which tools โ Jira, ITSM, CrowdStrike โ is policy, not code.
Client-configurable policy engine. Per-client rules on CDA agents. Configurable by Deloitte operators, not hardcoded.
OTel telemetry export to Google SecOps, Splunk, whatever the client runs. Every agent action in their audit log.
Governance dashboard. Which agents are active, what tools they use, policy compliance status. What the CISO sees in the QBR.
Behavioral anomaly detection. Agent A normally calls 3 tools โ it just called 47. CDA catches it because it knows the baseline. The demo that closes.
Our initial AI's assessment is faster than next year. It's โ we're estimating early October.
โ Tony, Portfolio Meeting, Aug 10Prioritize GA solutions independent of AI agent platforms to ensure cross-cloud governance, full enterprise information governance, and avoid vendor lock-in.
โ Gartner, Market Guide for Guardian Agents, Feb 2026Kindo governs only workloads on its platform. But this is a design choice, not a gap. Answer for CISOs: Kindo ORCHESTRATES partner detection (CrowdStrike on endpoints, AIRS on network) via MCP into one dashboard. "You don't choose between us and them โ you use us together."
3-engineer staffing assumption has no Linear tickets and no Charlie commitment yet. Mitigation: Scope to MVP surface. Generalize existing pipeline, don't greenfield.
AIRS 3.0 + Portkey acquisition assembling AI gateway. Microsoft has Defender + Purview + Sentinel across enterprise. Mitigation: Don't play feature-for-feature. Lead with hard moats (on-prem, execution platform) and operational control plane positioning.
Krishna: "If we are six months behind this, it's going to be really hard." Mitigation: Early-October target for 6-feature MVP. Ship 03โ04 first to show momentum.
ENG-11252 / PR #12155 (conflicting, off main). Upside โ not a gate for the 6-feature build. Mitigation: 6 features ship without Turbo. If it lands, behavioral baselines get compiled intelligence as a bonus.
Microsoft may be as capable as AIRS on shadow AI, model scanning, endpoint detection (Defender + Purview + Sentinel + Copilot Studio). Needs full mapping before the Krishna meeting.
AIRS claims governance over SaaS agents, browser agents, model training. How much is shipped vs. announced? Verification needed before assuming their breadth is real.
Kindo runs repeatable workflows. Does execution data compound into operational intelligence? If yes โ compounding moat. If no โ architectural advantage only.
No metric exists to show Kush how much smarter governance is this quarter vs. last. Proposed: hook accuracy, policy violations caught, anomalies detected.
Your agents run on Kindo. The security partners you already use โ CrowdStrike, AIRS โ feed into Kindo's dashboard via MCP. You don't choose between us and them. You use us together. We're the operational control plane. They're the inspection layer.
Kindo and AIRS are in two different spaces. Don't play feature-for-feature against Palo Alto and Microsoft. Lead with air-gapped on-prem (hard moat), agent execution platform (hard moat), and the operational control plane positioning.
The governance pipeline runs in production. The 6-feature build generalizes what's hardcoded. Ship small, T&C amplifies. The capabilities we DON'T build (shadow AI, model scanning, network interception) are orchestrated via MCP from partners.
Technical implementation plan โ four pillars, backlog grounding, October timeline. Architecture-corrected per Odin K.
Aug 2026 โ Tony's framework. Capabilities categorized by competitive defensibility against AIRS, CrowdStrike, Microsoft.
Aug 2026 โ Build vs Orchestrate analysis for 8 security capabilities. Plain-English explainers for each.
Aug 2026 โ 5-column comparison (Kindo, AIRS, CrowdStrike, Google SecOps, Microsoft) with verification status.
Aug 10, 2026 โ Krishna's competitive urgency, build-vs-resell framing, six-month lag risk.
Aug 13, 2026 โ Tony, Joana, Victor. Key insight: two different spaces. Hard moat / soft moat framework.
Feb 2026 Market Guide โ Guardian Agent category definition. Eight mandatory features. $3B+ annually by 2030.
Aug 2026 โ Corrected assessment. AIRS coverage wider than V1 assumed. On-prem = partial (not air-gappable).