KPATH

What is KPATH Defence?

The same enforcement layer, for defence and sovereign environments, as a neutral accountability layer that keeps a person in control. KPATH runs air-gapped inside your boundary, keys stay in your custody, every agent action is checked against your policy before it happens, and every decision lands in a record a third party can verify. KPATH enforces human control; it is not autonomous decisioning.

The control layer, never the trigger.

What KPATH Defence is

KPATH Defence is the same enforcement layer as KPATH Enterprise, deployed for defence and sovereign environments. It is an enforcement and accountability layer. It sits on the one path between agents and the systems they reach, verifies who is calling, enforces the policy you set, can stop any agent or chain of agents, and records every decision. It does not originate actions and it does not decide outcomes. KPATH enforces human control; it is not autonomous decisioning.

Human control, enforced on the call

Policy can require that any designated action waits for a named person, inline, before it proceeds. Routine work goes through; anything you mark as consequential stops until a person approves it, and the approval is recorded against the call it released. High-risk agents can be required to present a workload identity your identity provider verifies, and when an agent acts for a person, policy can insist the person is verified.

Any agent, or a whole chain of agents, can be stopped immediately and stays stopped. Afterwards a containment proof shows nothing in the chain was authorised after the stop.

Inside your boundary

Property How it holds
Deployment Self-hosted, on premises, air-gapped; no outside connectivity required
Keys Held in your own vault or key service; KPATH is a crypto user, not a custodian
Content KPATH governs the request envelope and reads only the payload values you declare for a rule; a self-hosted guardrail keeps inspected content inside the boundary
Evidence Signed, tamper-evident record streamed to your SIEM, exported to write-once storage and verifiable offline without trusting KPATH
Failure You choose in advance: continue on the last decision, or refuse until recovery

Accountability a third party can check

Every call, approval, refusal and stop is recorded with who acted and what was decided, never a secret or a message body. A standalone verifier proves the record without trusting KPATH’s console. A log you control is not evidence; a record anyone can verify is.

FAQ

Common questions

Does KPATH make decisions on its own?

No. KPATH enforces human control; it is not autonomous decisioning. Your policy and your identity provider decide what an agent may do, and KPATH enforces that decision on each call. Actions you designate wait for a named person.

Can KPATH run without any outside connectivity?

Yes. KPATH runs self-hosted, on premises and air-gapped. Enforcement, key custody, evidence and offline verification all stay inside the boundary.

Who holds the keys?

You do. Credentials are encrypted under a key held in your own vault or key service. KPATH is a crypto user, not a custodian.

Published Updated

Talk to the team

See KPATH running on a live agent estate.

A 30-minute call with the people building it. We reply within one working day.

Book a demo Read the trust pages first