-
Notifications
You must be signed in to change notification settings - Fork 0
Roadmap
Kairo follows a phased release plan. Each phase builds on the last without breaking the developer experience established in the previous one.
The complete security substrate. Everything required for a production API with full protection.
Layers shipped:
- Request Membrane (entropy scoring, ghost routes, signed envelopes, behavioral fingerprinting)
- Runtime Sentinel (taint tracking, canary frames, memory pressure alarms)
- Trust Lattice (relationship-graph authorization, temporal tokens, step-up auth)
- Data Shield (field encryption, contextual redaction, poison pills, query injection analysis)
- Developer Experience Layer (inline coaching, audit mode, override recording)
CLI: kairo new, kairo generate, kairo audit
Database adapters: Prisma, Drizzle, raw pg / mysql2
MCP: @kairo/mcp with kairo_surface, kairo_audit, kairo_explain tools
The Intent Engine and behavioral contract validation. The layer that catches supply chain compromises and insider threats.
New capabilities:
- Intent Engine — intent declarations as runtime contracts, behavioral drift detection
- Intent Graph — zero-trust service mesh, automatic graph construction during development
- Semantic route guards — natural language authorization requirements resolved by the Lattice
- Behavioral biometrics — browser client SDK, session anomaly detection
-
kairo dashboard— live security budget UI - Hot-patch bus v1 — signed patch channel,
autoApplysupport
The adaptive defense layer. Everything that activates when the application is under attack.
New capabilities:
- Hardening Mode — elastic rate limiting, shadow execution, stealth deflection
- Circuit breaker mesh — behavioral circuit breakers on service-to-service calls
- Differential privacy on aggregate queries
-
kairo fuzzCLI command — built-in fuzzer -
kairo surfaceCLI command — attack surface map in terminal
Integration, compliance, and edge runtime support.
New capabilities:
- Mutation drift detection — behavioral comparison between deploys
- Zero-knowledge proof authentication (optional, tree-shaken when unused)
- Full
@kairo/mcptool suite — all eight tools - OpenTelemetry native integration
- Security policy export for compliance mapping (SOC 2, ISO 27001)
- Edge runtime support — Cloudflare Workers, Deno Deploy
A few things that will not be added regardless of demand, because they would violate the core principle:
Mandatory security patterns. Kairo will never require developers to write code in a specific way to get protection. Security forms around code; code does not form around security.
Silent behavior changes in patches. Hot patches modify framework behavior, not application behavior. A patch will never change what a handler returns or how a model is stored.
Telemetry to Kairo infrastructure. Security event data stays in the application. No events, entropy scores, or behavioral data are transmitted to Kairo's servers.
← MCP Integration · Glossary →