Kindo
SOC for AI · Strategic Framework
Kindo × Deloitte · August 17, 2026

SOC for AI

How Kindo positions within SOC for AI — not feature parity with Prisma AIRS, but the operational control plane that makes CDA sellable.

👥 Krishna 🎯 CDA Sales Enablement 📅 Monday, August 17
Transformation Platform, Not Point Solution
Kindo is not another tool to help humans do security a little faster. It is a transformation platform.
Inside → Out

Kindo works from inside the customer's environment outward. On-prem, air-gapped, local models, local data. The customer's infrastructure is the foundation — Kindo builds on top of what they already control.

Outside → In

Palo Alto, CrowdStrike, Microsoft work from outside the perimeter inward. Network intercept, cloud scanning, endpoint monitoring. The vendor's infrastructure is the foundation — the customer routes through them.

Deloitte's Strategic Autonomy

With Kindo, Deloitte can run whatever partner fits best, whatever makes the most money, whatever the customer wants — and Deloitte stays in control. They don't turn it over to Palo Alto or anyone else. Kindo is the control plane that Deloitte operates — partners plug in below.

Hard Moat · Soft Moat
Hard moat = competitors don't have it. Soft moat = switching costs protect even with partial overlap. Red = concede to the big players.
Hard Moat — Unique to Kindo
Differentiator #1
On-Prem / Air-Gapped
Full K8s Helm charts, no internet required. Local models, local compute, local data. AIRS has partial network intercept only.
● Live
Unique Capability
Agent Execution Engine
Action Bots, Action Chat, triggers, code gen, RAG, memory, human-in-the-loop. No competitor builds and runs agents.
● Live
Security + Economics
Turbo Mode
Compile validated agent patterns into deterministic code. No hallucination, no prompt injection surface, no model drift. Cost → near-zero.
● Live
Isolated Compute
VMI Sandbox
SQL, Object Store, Vector DB, local files, DeepHat model — fully isolated execution environment per agent.
● Live
Partnership Lock-In
Deloitte-Specific Customization (CDA)
Features built to Deloitte specs, CDA-native. Forward Deployed Engineering model — T&C owns, maintains, and supports everything built on-prem.
● Live
Soft Moat — Advantage with Switching Costs
Live
MCP Gateway
Federated MCP with RBAC, 200+ tools. Agent context makes tool selection smarter than competitors.
● Live
Live
Inference Proxy
LLM proxy, DLP, audit logging, 26+ models. Model-agnostic vs vendor lock-in.
● Live
Live
Governance Layer
Policy, DLP, audit logs, Secrets Mgr, Admin Portal. Table stakes across vendors.
● Live
Live
Session Context
Full session history. Cross-session patterns. CrowdStrike has this within Falcon.
● Live
Soft Moat In Development — Krishna’s Sales Motion
The Demo
Anomaly Detection
Baseline per agent, drift detection. The execution layer catches rogue behavior a gateway can't see.
Oct
Aug Build
Audit Trail → SIEM
OTel export to Google SecOps, Splunk, Datadog. Every agent action in the client's audit log.
Aug
Sep Build
Governance Dashboard
Active agents, cost, tools in use, compliance. Single-pane operator view.
Sep
Sep Build
FinOps / Cost Controls
Token tracking, budgets, cost attribution. Model-agnostic vs M365-only.
Sep
Concede — Not Our Arena
Concede
Shadow AI Discovery
Network-layer discovery of unsanctioned AI. Requires DPI — Kindo is app-layer.
Do Not Build
Concede
AI Model Scanning
Model vulnerability scanning, supply chain analysis. Requires massive ML security investment.
Do Not Build
Concede
Automated Red Teaming
Adversarial testing of AI models and agents at scale. Prisma AIRS and Microsoft invest heavily here — not viable at Kindo’s scale.
Do Not Build
6 Features — What CDA Needs
Each feature answers a specific CISO question. 2 live, 4 to build. Mapped to the four-pillar strategy.
01
AI Inference Gateway
All CDA agent traffic routes through Kindo. Model access control, DLP, audit logging.
● LiveP1
"Who controls which models our agents use?"
02
Tool Access Control (RBAC)
MCP gateway with Cerbos RBAC. Which agents get which tools is policy, not code.
● LiveP2
"Can an agent access systems it shouldn't?"
03
Client-Configurable Policies
Per-client policy rules. "Analysts can query prod but not export." Configurable by operators.
AugP4a · Critical Path
"Can we set our own governance rules?"
04
Audit Trail to Client SIEM
OTel telemetry export to Google SecOps, Splunk, Datadog. GenAI semantic conventions.
AugP3
"Can we audit every AI decision in our SIEM?"
05
Governance Dashboard
Single-pane: active agents, cost, tools in use, policy compliance status.
SepP1+P2+P3
"Show me what our AI agents are doing right now."
06
Behavioral Anomaly Detection
Agent A normally calls 3 tools. It just called 47. Only the execution layer catches this.
OctP4b · The Demo
"What if an agent goes rogue?"
What Krishna Can Sell
Quarterly delivery mapped to CDA capabilities. Each milestone adds sellable features.
Now
Sellable Today
✦ AI Inference Gateway
✦ Tool Access Control (RBAC)
✦ On-prem / air-gapped
✦ Agent execution
✦ Turbo Mode
Why it matters: CISO can answer “who controls our AI?” today. Air-gapped = no data leaves the building. Turbo Mode = validated agents become deterministic code — zero hallucination risk.
Sep
Sprint 1
→ Client-configurable policies
→ Audit trail to SIEM
Why it matters: Clients set their own governance rules without code changes. Every AI decision lands in their existing SIEM (Google SecOps, Splunk, Datadog) — audit-ready from day one.
Oct
Sprint 2
→ Governance dashboard
→ FinOps / cost controls
Why it matters: Single-pane view across all agents, tools, models, and cost. Model-agnostic — unlike Microsoft’s Agent 365 which only covers M365 workloads. Budget controls prevent runaway LLM spend.
Nov
Sprint 3
→ Behavioral anomaly detection
→ Full SOC for AI live
Why it matters: The demo. Agent A normally calls 3 tools — it just called 47. Only the execution layer catches this because it knows the baseline. A gateway can’t. This is the rogue-agent story that sells.
The Demand Signal Is Here
The market shifted in 12 months. Enterprises are moving from “what is this?” to “who do I buy from?”
Aug ’25
Black Hat — Last Year
Nobody at the booth. SOC for AI was a concept, not a budget line.
Aug ’26
Black Hat — This Year
Lines 4–5 people deep at all four demo stations. 500+ deep conversations.

In six months, enterprises will have a plan and be ready to buy. The window to establish CDA as the answer is now.

Kishor's 5 SOC for AI Objectives
Each objective maps to Kindo capabilities — native and partner.
1
Detect new agent deployment
● Live
2
Detect new tool / data source connections
● Live
3
Detect behavioral drift in agent actions
Oct
4
Detect guardrail / policy changes
Oct
5
Multi-tenant data contamination
Scoping

Previous Sessions

📊 Portfolio Meeting · Aug 10 📋 Program Meeting · Aug 4 🎨 Design Session · Jul 30 📋 Program Meeting · Jul 22

Supporting Materials

📅 Meeting Cadence 🏗️ IK Approach 📋 Sprint 2 Review 📋 Sprint 1 Review 📐 Gantt Timeline