Security & data handling

Where your data goes.

You are trusting us with security telemetry and your detection logic. This page states exactly where that data goes.

What leaves your environment

Your logs stay in Splunk. Kyrolan is not a SIEM: it does not ingest or store your telemetry. Agents run read-only searches and receive the query results, rule text and report text a task needs, not raw index access.

Those inputs are sent to the model provider so the agents can do the task. Where the agents run (hosted by Kyrolan or inside your environment), the route to the model and how long data is retained are agreed per engagement, before any access is granted.

Credentials

Agents use read-only search credentials that you create and scope to the indexes you choose. You can revoke them at any time.

Secrets

Every write is scanned for secrets first. No credentials end up in rules, reports or other artifacts.

Change control

In your repository agents push to their own branches and open merge requests. No merge rights, no protected branches. Agents never deploy: your engineers merge and deploy through your CI/CD.

Audit trail

Every query, model call, proposal and approval is logged and exportable.

Model provider

Kyrolan agents are built with Claude by Anthropic.

Contact

security@kyrolan.com for security questions and vulnerability reports.