One Binary, One Connection, No Runtime Dependencies
Kraitos AIDR is a single self-contained agent that registers as a native service, streams telemetry over mutual TLS, and evaluates policy locally so nothing sits in the developer's critical path.
From Endpoint to Dashboard
- 01Endpoint agentSingle binary · 7 engines · local policy eval
- 02Encrypted transportMutual TLS 1.3 · per-device certs · offline buffering
- 03Ingestion serviceScaled separately from the API
- 04ProcessingAttribution · pricing · policy · evidence
- 05DashboardAlerts · evidence · response
A Single Binary With No Dependencies
Built natively for macOS, Linux, and Windows and registered as a LaunchDaemon, systemd unit, or Windows Service. No runtime to install, no framework to patch.
- Memory
- < 50 MB
- CPU
- < 1%
- Platforms
- macOS (Apple Silicon + Intel), Linux (x64 + ARM), Windows
- WSL
- Full cross-boundary support
- Service model
- LaunchDaemon · systemd · Windows Service
- Updates
- Automatic - verified before install, applied atomically
- Agent version
- 0.29.0
- Binary signing
- Cryptographically signed releases on every platform
Three Steps, About Sixty Seconds
Enrollment tokens carry their own constraints: OS restrictions, CIDR allowlists, team auto-assignment, single- or multi-use, and an expiry window.
- Step 01
Create an enrollment token
Set OS restrictions, CIDR allowlists, team auto-assignment, single- or multi-use, and an expiry window.
- Step 02
Deploy it
Push the installer through your existing MDM or endpoint management tooling, or hand the token to the person setting the machine up. No reboot, no imaging, no developer interaction.
- Step 03
Devices report instantly
AI tools, sessions, posture, and inventory flow into the dashboard within seconds of the agent starting.
What Is Collected, and What Is Not
The platform collects metadata about AI usage patterns and policy-relevant findings - not wholesale copies of proprietary code.
Collected
- AI tool presence, version, and usage
- Session structure: prompts, responses, tool calls, file paths, shell commands, MCP destinations
- Per-turn token counts and computed cost
- Policy evaluations, enforcement events, and DLP findings
- Hardware, software, browser extension, and repository inventory
- Endpoint posture: disk encryption, screen lock, firewall
Handled carefully
- Detected secrets can be redacted out of session data on the endpoint
- Sensitive values are stripped from AI Profiles before distribution
- Telemetry buffers to local disk and replays on reconnect, so an offline laptop loses nothing
- Tenant data is isolated at four independent layers, down to the database row
Automatic, Verified, Atomic
The agent keeps itself current. Every release is cryptographically signed, every download is verified before install, and upgrades apply atomically - no maintenance window, no half-updated endpoint.
The Platform Behind the Agent
| Layer | How it works |
|---|---|
| Agent | A single self-contained binary for macOS, Linux, and Windows with native service registration |
| Transport | Streaming telemetry over mutual TLS 1.3, buffered locally and replayed on reconnect |
| Ingestion | A dedicated ingestion tier, scaled separately from the API so telemetry bursts never slow the dashboard |
| Data isolation | Tenant boundaries enforced at four independent layers, down to database row-level security |
| Delivery | Every release is vulnerability-scanned, signed, and rolled out with zero downtime |
| Reliability | Continuous health monitoring at every layer, with alerts the moment an endpoint goes quiet |
Built for Many Tenants at Once
Full isolation at every layer means MSSPs and MSPs run many clients on one platform with guaranteed data boundaries.
- Tenant isolation enforced at four independent layers, down to the database row
- Ingestion scaled independently of the API, so telemetry bursts do not degrade the dashboard
- Zero-downtime rollouts from pinned, reproducible releases
- Per-agent health monitoring with automatic alerts when an endpoint stops reporting
Evaluate It on Your Own Fleet
Start free on up to 5 endpoints, or book a technical walkthrough of the architecture and data flow.
[email protected]kraitos.io