SecKav // application · api · agent · access

Read every request.
Score every actor.
Decide in real time.

One security layer across your applications, APIs, AI agents, and private access — inspected at the edge in under two milliseconds, governed by intent, never trusted by default.

< 2 ms
edge decision
43
inspection modules
0–100
trust, per request
1
DNS change to deploy
fabric · live topology3 systems
applications · agents · infrastructure
edge · live verdict streamlive

Three systems. One fabric. Every request judged the same way.

// the life of a request

Every request runs a gauntlet — and carries a verdict out the other side.

The first request costs about 2 ms while the tenant’s policy is cached at the edge. The next ten thousand are decided in under a tenth of a millisecond, without touching a database.

Trace the full pipeline
req 0x7af3 · GET /account/orders/8813ALLOW · 1.4ms
1resolveDNS → SecKav edgeROUTE
2penalty boxbanned IP? O(1) ValkeyPASS
3normalizedecode · strip evasionCLEAN
4inspectWAF · bot · API shieldSCORE 12
5trustactor score 0–100TRUST 88
6originforward to hidden originPROXY
7responsemask Aadhaar / PAN in RAMMASK

// the surface, in full

Roughly a hundred and thirty controls, grouped by what they defend.

Applications & APIs

  • WAF — SQLi · XSS · LFI · RCE · zero-day
  • Bot & AI-crawler management
  • L7 DDoS penalty box · 0 ms drop
  • API shield — SSRF · BOLA · GraphQL · JWT
  • India DLP — Aadhaar · PAN in memory
  • Supply-chain & script firewall
Open applications

AI agents

  • Agent identity registry & rotation
  • Living trust score, every request
  • Intent-based access control
  • MCP shield & tool-call inspection
  • Shadow-agent discovery
  • AI-generated least-privilege policy
Open ai

Access & governance

  • Device posture — pass · restricted · fail
  • Hybrid post-quantum handshake
  • Guest & contractor time-boxed links
  • Magic DNS — private addressing
  • Compliance across 8 frameworks
  • Signed audit & attestation exports
Open access

// governance

Evidence, not adjectives.

Coverage across eight frameworks, with signed exports, breach register, RoPA, config versioning, and content-hash-verified attestations.

GET /v1/compliance/attestation200 · verified
DPDPCERT-InRBINIST-PQCSEBI CSCRFISO 27001SOC 2GDPR
sig=hmac-sha256 · contentHash=3f9a…c21 · signed_at=2026-07-19T

Browser SDK

The bridge from the browser to the platform.

A single publishable key wires consent, data-rights, and passive bot telemetry into any page — feeding the edge without ever exposing a secret in the browser.

  • Consent banner — DPDP §6, 22 Indian languages
  • Age gate — children’s-data rule
  • Data-rights widget — access · correct · erase
  • Bot telemetry — mouse · canvas · WebDriver
  • Script-blocking interceptor — hold 3rd-party until consent
  • Consent sync + server-side verify helper
Not yet published to npm / CDN
index.html
<script src="https://cdn.seckav.tech/sdk.js"></script>
<script>
  SecKav.init({ apiKey: 'pk_live_…' })   // publishable, write-only
  // consent, age-gate & rights portal render automatically
</script>

Point your nameservers. Watch it decide.

No agent to install, no code to change. Every request starts running the gauntlet the moment your DNS resolves.

edge · live verdict streamlive