Features built for continuous compliance
Scan your code and data, map findings to frameworks, and prove your posture — all in one platform.
Your KGAI Compliance & Security Advisory Board
A standing KGAI advisory board — Compliance Officer, Chief Security Officer, CTO, and CFO — reviews your tenant’s own live SOC 2 / HIPAA posture and returns grounded feedback. Every insight cites your real findings, targets, and control coverage, not generic best-practice advice. The board closes with a single prioritized path to audit-ready: what to fix first, why it matters, and roughly what it costs.
Compliance Officer
SOC 2 / HIPAA control coverage, evidence gaps, and what an auditor will flag first.
Chief Security Officer
Real exposure across your repos, databases, cloud, and web apps — ranked by blast radius.
CTO
Engineering effort, sequencing, and which fixes unblock the most controls at once.
CFO
Cost, audit timing, and where spend actually moves you toward audit-ready.
- Grounded in your real posture — reviewers read your live findings, not a generic template
- A prioritized path to audit-ready, sequenced by impact and effort
- Run it on-demand in the portal, or receive it as a weekly email
- Export any review as an auditor-ready PDF
- Free tenants get a Compliance-Officer preview; the full board is on every paid plan
Your real security posture, at a glance
One dashboard rolls every repo, database, cloud account, and web app into a single risk score — with severity breakdowns, SLA tracking, and day-over-day trends.
- Risk score weighted by severity, with 15-scan trend lines
- SLA breach and stale-target callouts before an auditor finds them
- Daily digest email with the same numbers, every morning

Every gap, mapped to the controls buyers ask about
Each finding carries its severity, the exact SOC 2 / HIPAA / ISO 27001 / PCI DSS controls it touches, the affected asset, and a plain-language KGAI explanation.
- Filter by project, run, severity, framework, or status
- Statuses that match reality: open, acknowledged, remediated, accepted risk
- KGAI explains the business impact — not just the CVE jargon

A system diagram that never goes stale
KollGuard reads your connected repos and generates an interactive, animated map of your stack — versioned on every change, exportable for your auditor.
- Auto-generated from real code, editable when you know better
- Import existing diagrams from images, PDF, Figma, Visio, or Word
- Versioned history — compare what changed between releases

Track the work, right where the findings are
Built-in issues and epics — Board, List, or Roadmap view — so “fix the RLS gap” lives next to the finding that raised it, not in a separate Jira tab.
- Roadmap view groups features under each epic with inline status, assignees, and progress
- KGAI drafts an epic and its features from one sentence, each with a watch-for and test plan
- KGAI generates an interactive workflow diagram for every epic — click a step to see what to build and how to test it

A support queue your whole team can run
Customer and internal requests tracked through to resolution — with KGAI triage that suggests priority and category, gated behind an explicit PHI-safe opt-in.
- Board, list, card, and calendar views
- PII/PHI is scrubbed before any ticket text reaches an LLM
- Import your existing queue from Zendesk or Freshdesk

Guardrails for the agents you let loose
KollGuard’s remediation agent proposes fixes — and your policy decides what runs unattended, what queues for approval, and what never happens.
- Per-tier autonomy: auto, approve, or off — plus a master kill switch
- Blast-radius caps: repo/path allowlists, max files & lines, daily PR cap
- Approval inbox with dry-run previews before anything executes

An audit trail you can cryptographically prove
Every consequential change lands in a hash-chained, append-only log. One click recomputes the whole chain and attests nothing was altered — in front of your auditor.
- sha256 hash chain: every entry sealed against the one before it
- “Verify chain” recomputes from genesis and flags any tampering
- Human, system, and AI-agent actions all attributed in one trail

And the rest of the platform
Continuous GitHub scanning
Connect organizations and repositories with a least-privilege token. KollGuard scans for security gaps, risky settings, and exposed secrets — then keeps watching.
Database security scanning
Read-only scans across Postgres, Supabase, MySQL, MongoDB, SQL Server & DynamoDB. Missing Row Level Security, over-permissive grants, and exposed tables on Postgres; auth and role hygiene on MySQL, MongoDB, and SQL Server; encryption and backups on DynamoDB — plus configuration drift on every engine.
Web app security scanning
Verify you own a URL, then run safe, non-destructive checks — security headers, TLS/HSTS, cookie flags, exposed .git/.env files, CORS — the automated portion of a pentest, between your independent ones.
Automatic SOC 2 & HIPAA mapping
Every finding is mapped to the relevant SOC 2 Trust Services Criteria and HIPAA safeguards, so you always know which control a gap affects.
Projects with rolled-up posture
Group related repos and databases into projects and get a single rolled-up posture score — perfect for reporting per product, team, or environment.
Auto-mapped architecture diagram
KollGuard reads your connected repos and database and generates an interactive map of your stack — features, services, and data flow. It is versioned on every change, so you can compare releases and hand auditors a current system description instead of a stale diagram.
Evidence & downloadable reports
Produce auditor-ready evidence and exportable reports directly from your latest scans — no manual screenshots or spreadsheets.
AI cost & usage dashboard
Monitor AI usage and spend across every project from one dashboard so you can keep costs predictable as you scale scanning.
Post-quantum readiness (preview)
A standards-mapped PQC checklist and a 0-100 readiness score, grounded in the finalized NIST standards (FIPS 203 ML-KEM, 204 ML-DSA, 205 SLH-DSA) and the NSA CNSA 2.0 clock — RSA/ECC deprecated by ~2030, disallowed by ~2035. KollGuard derives what it can from your TLS scan posture, you self-attest the rest, and KGAI drafts a migration plan. Because "harvest now, decrypt later" means long-lived PHI and financial data is already being recorded to break later.
Secure by design
Credentials are encrypted in Supabase Vault and never stored in the browser. Scanning is read-only and your source code is never retained.
