Trust & compliance
EU residency, the hard guardrails, and proof you can hand to an auditor.
Kissaki is built to be pointed at production and to produce an artefact an auditor will accept.
EU data residency
All model access goes through a single EU-resident router with zero data retention, enforced as a hard guardrail. There is no direct vendor SDK anywhere in the pipeline, so data stays in the EU by construction.
Hard guardrails
Every scan is bounded before it starts:
- Ownership proof - nothing is scanned that you have not verified you own.
- Rules of engagement and scope-lock - the scan stays inside the hosts and paths you authorised. See RoE and consent.
- Non-destructive by default, with a kill-switch.
- Full audit trail - who authorised what, and when.
Proof, not guesswork
No HIGH or CRITICAL exploitation finding is delivered without a reproducible proof of exploit. That is what makes a Kissaki report defensible: every serious claim can be reproduced. See findings and proof.
Reporting
A report covers one asset over a period, so it maps to the object your authorisation and scope attach to. Reports render as Markdown, PDF and SARIF.