Kelvex Security detects and classifies agentic-AI activity across your network and endpoints — which systems talk to which AI services, how often, in what pattern. On-premise, without data ever leaving your own network.
[!] Early alpha — Phase 1 (Visibility) is under active development. See roadmap below.
Agent frameworks, local LLM processes, and self-written scripts with API access are spreading faster than corporate IT can approve them. Without a dedicated visibility layer, this traffic stays invisible — especially once it's encrypted.
of enterprises name Shadow AI as the top SaaS security risk in 2026.
market for shadow-AI detection & governance by end of 2026 — 44% CAGR since 2024.
data that leaves your network — Kelvex runs fully on-premise.
The same information — here a sample alert with neutral placeholder data — appears across all four Kelvex surfaces at different levels of detail, but recognizably consistent: web for deep analysis, desktop/mobile tray for a quick status check, CLI for automated processing.
Local process repeatedly attempts to establish an autonomous connection to an external AI service — the pattern matches agent-typical behavior (loop structure, not a single request). IT decides on policy: observe, restrict, or block.
Kelvex Security is operated through four clients — consistent color palette, consistent terminology, each adapted to its context.
Central admin dashboard for IT teams — network overview, policy management, alerts, reporting.
Local client on monitored devices — agent status, local notifications, simple controls.
Alerts on the go, status at a glance — read-only, no critical actions from the app itself.
Integration into scripts, automation, CI pipelines — consistent terminology and status codes.
Passive network traffic monitoring, detection of connections to known LLM/agent APIs — no active intervention. Current development focus.
Pattern recognition: normal API usage vs. agent-typical behavior. Baseline for "normal" agent behavior in the respective network.
Allowlisting of approved models/APIs, role-based policies, local enforcement right at the endpoint.
SIEM integration, alerting channels, Entra ID SSO/group sync, Intune deployment — plus a dedicated block for mobile & rugged device support.
Automatic blocking/quarantine for clearly policy-violating behavior — only with explicit IT approval, exclusively within your own infrastructure.
Retrospective analysis for incident response, reporting templates for internal audits or regulatory notifications.
You run Kelvex on your own infrastructure — your data never leaves your network. In security-/compliance-sensitive environments (government, finance, many mid-size businesses) this is often a requirement, not just a preference.
Customer operates everything themselves, regular internet connection for license checks/updates.
Offline license activation, updates as manually installable packages — for environments without internet connectivity.
Local backends only, no cloud API calls — for customers with data sovereignty requirements.