How Kindo becomes the independent governance control plane for enterprise AI — re-anchored to Kindo's live engineering backlog.
AI agents are making tool calls, accessing sensitive data, executing code, and interacting with production systems — with minimal oversight. Traditional security tools were not built for autonomous AI workloads.
Palo Alto Networks launched Prisma AIRS. CrowdStrike has Falcon AI Protection. Google SecOps is adding AI detection. Microsoft has Security Copilot. Each vendor is racing to own "AI security."
But every one of these products has the same structural limitation: they only govern what passes through their own ecosystem.
"Prioritize Guardian Agent solutions independent of AI agent platforms to ensure cross-cloud governance, full enterprise information governance, and avoid vendor lock-in."— Gartner, Market Guide for Guardian Agents, February 2026 (G00836388)
Gartner projects this market at $3B+ annually by 2030, with Guardian Agents eliminating ~50% of incumbent risk/security systems in 70%+ of organizations by 2029.
Palo Alto Networks' Prisma AIRS = runtime security product. Inline network/API intercept. Infrastructure-layer security applied to AI traffic.
Kindo = governance control plane. The platform AI workloads run through — not a filter traffic passes by.
Kindo and runtime security vendors are not competitors. They are different layers. The demo is not "Kindo does what Prisma AIRS does." It is "Kindo governs your entire AI landscape including your Prisma AIRS deployment." The two differentiators that genuinely hold as architectural differences: cross-vendor independence and custom-built to requirements.
Route all AI inference through Kindo. Policies, model blocking, Data Loss Prevention (Presidio), RBAC, complete audit trail.
● Live — General AvailabilityFederated Model Context Protocol gateway. Per-integration/per-action access controls. One connection point, full audit trail.
● Live — General AvailabilityExport path: SHIPPED behind flag (ENG-10891, merged to main). Google SecOps = validate config, not build.
Native storage + dashboard: DESIGN STAGE (ENG-11460). This is the real work.
Inbound ingest: DESIGN STAGE (ENG-11461).
Core hook engine: IN REVIEW (ENG-11023, M0 contract + pipeline).
Policy-judge layer: PROJECT EXISTS (Guardian Model, owner: Nick).
Admin guardrails: OWNED (AI Guardrails spec, owner: Josh).
Compiled artifacts for accelerating policy hooks. PR #12155 is OPEN and CONFLICTING — not on main. LLM-only hooks are the base case for October. Turbo acceleration is a bonus if the PR lands.
⚠ At Risk — PR Conflicting ENG-11252 (In Review) · PR #12155 (conflicting/dirty)Prisma AIRS · Network/API Intercept · AI Runtime Security
Falcon AI Protection · Endpoint · Shadow AI · Threat Intel
SIEM · Investigation · Threat Detection · OpenTelemetry
Security Copilot · Defender · Sentinel · Entra · Purview
| Capability | Prisma AIRS | CrowdStrike | Google SecOps | Microsoft | Kindo |
|---|---|---|---|---|---|
| AI Inference Governance | No | No | No | No | Live |
| Federated Tool Governance | No | No | No | No | Live |
| Cross-Vendor Independence | No | No | Partial | No | Yes |
| Custom-Built to Requirements | No | No | No | No | Yes |
| Agent-as-Judge Enforcement | No | No | No | Partial | Planned |
| Session-Level Behavioral Analysis | No* | No | No | No | Planned |
| Turbo-Accelerated Enforcement | No | No | No | No | At Risk |
| Prompt Injection Defense | Yes | Yes | No | Yes | Planned |
| Network Traffic Inspection | Yes | Yes | No | No | No |
| Endpoint Protection | No | Yes | No | Yes | No |
*Prisma AIRS has "Agentic Threat Protection" (identity impersonation, memory manipulation, tool misuse) at the network layer — closer to behavioral analysis than a simple "No" implies. Kindo's planned hook model provides deeper session look-back with agent reasoning. Gap is narrower than it appears.
Sources: Prisma AIRS datasheet (primary). CrowdStrike, Google SecOps, Microsoft from web research — verify against vendor datasheets.
"You have Palo Alto Networks protecting your network traffic. You have CrowdStrike on your endpoints. You have Google SecOps in your SOC. None of them can see across each other. That's what Cyber Digital Analyst does — it's the independent governance layer that orchestrates all of them. Gartner calls this a Guardian Agent."
"Here are your AI agents. Here are the high-risk ones. Click one."
"Here's what this agent has been doing. This data also flows to your Google SecOps."
"No agent accesses PII without authorization. Hook caught it. Blocked. Logged."
"This agent's behavior is anomalous. AI judge reviewed the session."
GA-ing the export flag = the easy 20%. Native storage + dashboard + shipping hook attachment points from existing specs = the genuinely hard 80%.
Inbound telemetry collector (ENG-11461). Full 4 hook attachment points. Cross-session behavioral scoring. Auto-remediation. Palo Alto / CrowdStrike integrations. Shadow AI discovery. Turbo-accelerated hooks (unless PR #12155 lands).
Kindo will not run software on endpoints. Will not inspect network traffic. Will not guarantee detection of unsanctioned AI. These are deliberate architectural boundaries — Kindo orchestrates the tools that DO those things.
Strongest posture: "Only hand out Kindo API keys for AI use."
"AI models are getting smaller and smaller. At some point, there's gonna be local models proliferating on machines. You won't have the opportunity to just turn off the API keys." — Charlie, Aug 7. No vendor has an answer to fully-local shadow AI.
"I don't know who can build pillars three and four at Kindo. No one. I literally had to do pillars one and two against Ryan." — Charlie, Aug 10. Charlie is going on vacation. The PRD builds on existing initiatives with named owners (Josh, Nick) rather than requiring new architecture.
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Charlie unavailable + no one else can architect pillars 3-4 | High | Critical | Build from existing specs with named owners (Josh, Nick). Scope to minimum. |
| Turbo mode PR stays conflicting | Medium | Medium | LLM-only hooks = base case. Turbo = bonus. |
| Stakeholders continue feature-parity comparison | High | High | Follow-up meeting must reframe positioning before product demo. |
| Deloitte agent-run reliability issues (ALI-41, ENG-10478, ENG-9375, ALI-36) | High | Medium | Prioritize reliability tickets. Governance pitch on unreliable platform undercuts itself. |
| Dashboard design not started (ENG-11460) | Medium | High | Scope to extending Command Center, not new surface. |
| Cyber Digital Analyst scope undefined | High | Medium | Resolve before engineering scopes October. |
Positioning: Independent Guardian Agent platform. What Kindo actually is — not a marketing reframe.
The two rows that win: Cross-vendor independence + custom-built to requirements. Genuine architectural differences no vendor can replicate.
October scope: GA telemetry export + 2 hook attachment points + extend Command Center with risk scoring + validated Google SecOps config. Credible-hard.
Base case: LLM-only hooks (no turbo). Full vision (4 hooks + behavioral + turbo + inbound ingest) = Q1 2027.
"No vendor can credibly sell independence from itself. That's why the governance layer must be independent. That's Kindo."