Home
Checking protection…
Runtime protection for AI agents

Protect an agent action in under five minutes.

Kitchain sits between agents and enterprise tools, allowing safe work, stepping up risky actions, and blocking data from leaving—even when credentials are valid.

No Salesforce account required for the demo. Hosted demo uses fixture upstreams unless a live DE org is configured (see HOSTED.md).

Guided demo

Support agent is handling STG-1104

Synthetic contacts · no customer data
1
Read 5 contactsWaiting to run
2
Update permitted contactWaiting to run
3
Export all contactsWaiting to run
4
Upload CRM data to DriveWaiting to run
Kitchain allowed the work, stepped up the risky action, and blocked external exfiltration.
Protected actions
0
Pending approvals
0
Receipt chain
Valid

Connections

Kitchain holds upstream credentials. Agents only authenticate to Kitchain.

Two separate trust hops: Agent → Kitchain agent key · Kitchain → upstream MCP credential. Upstream tokens are encrypted and never returned to agents.

Agents

Register execution identities and assign only the connections they need.

Policies

Plain-language controls backed by an editable external Rego policy pack.

Activity

Every decision includes proof of what was evaluated and whether the target was contacted.