Kelvex Security
Enterprise AI-Warden Network Security

Make Shadow AI in your enterprise network visible — before it becomes a risk.

Kelvex Security detects and classifies agentic-AI activity across your network and endpoints — which systems talk to which AI services, how often, in what pattern. On-premise, without data ever leaving your own network.

[!] Early alpha — Phase 1 (Visibility) is under active development. See roadmap below.

The starting point

Employees are already using AI agents — your IT department just doesn't know it yet.

Agent frameworks, local LLM processes, and self-written scripts with API access are spreading faster than corporate IT can approve them. Without a dedicated visibility layer, this traffic stays invisible — especially once it's encrypted.

71%

of enterprises name Shadow AI as the top SaaS security risk in 2026.

~$2.7B

market for shadow-AI detection & governance by end of 2026 — 44% CAGR since 2024.

0

data that leaves your network — Kelvex runs fully on-premise.

How it works

One alert, consistent across every surface.

The same information — here a sample alert with neutral placeholder data — appears across all four Kelvex surfaces at different levels of detail, but recognizably consistent: web for deep analysis, desktop/mobile tray for a quick status check, CLI for automated processing.

Sample alert (placeholder data)
[!] CRITICAL — ALRT-9942 2026-10-08 05:42:11
Source
[•] DEV-WS-94
10.0.4.22 · /usr/bin/python3
Target / Pattern
llm-api.example.com
≈≈≈> Agentic Loop (12 req/sec)

Local process repeatedly attempts to establish an autonomous connection to an external AI service — the pattern matches agent-typical behavior (loop structure, not a single request). IT decides on policy: observe, restrict, or block.

One design system, four surfaces

Same language, adapted to the context of use.

Kelvex Security is operated through four clients — consistent color palette, consistent terminology, each adapted to its context.

01

Web-GUI (Management)

Central admin dashboard for IT teams — network overview, policy management, alerts, reporting.

02

Desktop-GUI (Endpoint)

Local client on monitored devices — agent status, local notifications, simple controls.

03

Mobile-GUI

Alerts on the go, status at a glance — read-only, no critical actions from the app itself.

04

CLI

Integration into scripts, automation, CI pipelines — consistent terminology and status codes.

View full mockups of all four surfaces →
Roadmap

Six phases, from passive monitoring to forensics.

PHASE 1

Visibility (Monitoring only)

Passive network traffic monitoring, detection of connections to known LLM/agent APIs — no active intervention. Current development focus.

PHASE 2

Classification

Pattern recognition: normal API usage vs. agent-typical behavior. Baseline for "normal" agent behavior in the respective network.

PHASE 3

Policy Engine

Allowlisting of approved models/APIs, role-based policies, local enforcement right at the endpoint.

PHASE 4

Integration

SIEM integration, alerting channels, Entra ID SSO/group sync, Intune deployment — plus a dedicated block for mobile & rugged device support.

PHASE 5

Active Response

Automatic blocking/quarantine for clearly policy-violating behavior — only with explicit IT approval, exclusively within your own infrastructure.

PHASE 6

Behavioral Analysis & Forensics

Retrospective analysis for incident response, reporting templates for internal audits or regulatory notifications.

Deployment

On-premise as the default, not the exception.

You run Kelvex on your own infrastructure — your data never leaves your network. In security-/compliance-sensitive environments (government, finance, many mid-size businesses) this is often a requirement, not just a preference.

Self-Hosted (Standard)

Customer operates everything themselves, regular internet connection for license checks/updates.

Air-Gapped (Enterprise)

Offline license activation, updates as manually installable packages — for environments without internet connectivity.

Sovereign Mode

Local backends only, no cloud API calls — for customers with data sovereignty requirements.