Skip to content
How It Works

One Binary, One Connection, No Runtime Dependencies

Kraitos AIDR is a single self-contained agent that registers as a native service, streams telemetry over mutual TLS, and evaluates policy locally so nothing sits in the developer's critical path.

Architecture

From Endpoint to Dashboard

  1. 01
    Endpoint agent
    Single binary · 7 engines · local policy eval
  2. 02
    Encrypted transport
    Mutual TLS 1.3 · per-device certs · offline buffering
  3. 03
    Ingestion service
    Scaled separately from the API
  4. 04
    Processing
    Attribution · pricing · policy · evidence
  5. 05
    Dashboard
    Alerts · evidence · response
The Agent

A Single Binary With No Dependencies

Built natively for macOS, Linux, and Windows and registered as a LaunchDaemon, systemd unit, or Windows Service. No runtime to install, no framework to patch.

Memory
< 50 MB
CPU
< 1%
Platforms
macOS (Apple Silicon + Intel), Linux (x64 + ARM), Windows
WSL
Full cross-boundary support
Service model
LaunchDaemon · systemd · Windows Service
Updates
Automatic - verified before install, applied atomically
Agent version
0.29.0
Binary signing
Cryptographically signed releases on every platform
Deployment

Three Steps, About Sixty Seconds

Enrollment tokens carry their own constraints: OS restrictions, CIDR allowlists, team auto-assignment, single- or multi-use, and an expiry window.

  1. Step 01

    Create an enrollment token

    Set OS restrictions, CIDR allowlists, team auto-assignment, single- or multi-use, and an expiry window.

  2. Step 02

    Deploy it

    Push the installer through your existing MDM or endpoint management tooling, or hand the token to the person setting the machine up. No reboot, no imaging, no developer interaction.

  3. Step 03

    Devices report instantly

    AI tools, sessions, posture, and inventory flow into the dashboard within seconds of the agent starting.

Data Flow

What Is Collected, and What Is Not

The platform collects metadata about AI usage patterns and policy-relevant findings - not wholesale copies of proprietary code.

Collected

  • AI tool presence, version, and usage
  • Session structure: prompts, responses, tool calls, file paths, shell commands, MCP destinations
  • Per-turn token counts and computed cost
  • Policy evaluations, enforcement events, and DLP findings
  • Hardware, software, browser extension, and repository inventory
  • Endpoint posture: disk encryption, screen lock, firewall

Handled carefully

  • Detected secrets can be redacted out of session data on the endpoint
  • Sensitive values are stripped from AI Profiles before distribution
  • Telemetry buffers to local disk and replays on reconnect, so an offline laptop loses nothing
  • Tenant data is isolated at four independent layers, down to the database row
Transport is mandatory TLS 1.3 with mutual TLS between agent and ingestion. The codebase has no insecure fallback and no plaintext mode to misconfigure.
Updates

Automatic, Verified, Atomic

The agent keeps itself current. Every release is cryptographically signed, every download is verified before install, and upgrades apply atomically - no maintenance window, no half-updated endpoint.

Backend

The Platform Behind the Agent

Architecture at a glance
LayerHow it works
AgentA single self-contained binary for macOS, Linux, and Windows with native service registration
TransportStreaming telemetry over mutual TLS 1.3, buffered locally and replayed on reconnect
IngestionA dedicated ingestion tier, scaled separately from the API so telemetry bursts never slow the dashboard
Data isolationTenant boundaries enforced at four independent layers, down to database row-level security
DeliveryEvery release is vulnerability-scanned, signed, and rolled out with zero downtime
ReliabilityContinuous health monitoring at every layer, with alerts the moment an endpoint goes quiet
Scale & Reliability

Built for Many Tenants at Once

Full isolation at every layer means MSSPs and MSPs run many clients on one platform with guaranteed data boundaries.

  • Tenant isolation enforced at four independent layers, down to the database row
  • Ingestion scaled independently of the API, so telemetry bursts do not degrade the dashboard
  • Zero-downtime rollouts from pinned, reproducible releases
  • Per-agent health monitoring with automatic alerts when an endpoint stops reporting

Evaluate It on Your Own Fleet

Start free on up to 5 endpoints, or book a technical walkthrough of the architecture and data flow.

[email protected]kraitos.io