-
Notifications
You must be signed in to change notification settings - Fork 0
Home
Act at the right moment. Secure from the first line.
Kairo is a TypeScript web framework where security is the substrate, not a feature. Every request passes through seven purpose-built security layers automatically. You write your application code exactly as you normally would — Kairo wraps protection around it without asking you to change how you think or build.
Most frameworks give you zero security by default. You bolt on middleware, configure rate limiters, remember to sanitize inputs, install a helmet package, and hope you got it all. Security is always playing catch-up with the code.
Kairo inverts this. Security is not applied to your routes — it forms around them. An endpoint that handles payments gets different, deeper protection than one serving static content. Automatically. Without configuration.
And when your application comes under attack, Kairo tightens elastically — without blocking or degrading the experience for legitimate users.
Kairo never says no to the developer. It says "yes, and here is how I made that safe."
You can disable any security layer for any route. You can use any database, any auth system, any response shape. When you make a deliberate trade-off, Kairo records it in the audit log and moves on.
| Page | What it covers |
|---|---|
| Architecture | The seven-layer pipeline every request passes through |
| Request Lifecycle | End-to-end walkthrough of a single request |
| Trust Lattice | Relationship-based authorization and temporal tokens |
| Data Shield | Field encryption, contextual redaction, poison pills |
| Runtime Sentinel | Taint tracking, canary frames, hot-patch bus |
| Hardening Mode | Elastic rate limiting, shadow execution, stealth deflection |
| Developer Experience | Coaching, audit mode, dashboard, override recording |
| CLI Reference | All kairo commands |
| MCP Integration | Connecting Kairo to Claude Code and AI tooling |
| Flexibility & Overrides | How to bypass any layer, and what happens when you do |
| Performance | Benchmarks and why security layers cost almost nothing |
| Roadmap | What is coming in v1.1, v1.2, and v2.0 |
| Glossary | Definitions for Kairo-specific terms |
If you are new to Kairo, read these three pages in order:
- Architecture — understand the seven layers and how they relate to each other
- Request Lifecycle — see exactly what happens to a request from arrival to response
- Trust Lattice — understand the authorization model, which is the most novel part of the system
Version: 0.1.0-design · Status: Pre-implementation specification