Kaer
For Enterprise

AI agents that fit
your security envelope.

Operator v1 for the enterprise. SSO/SAML, region-pinned deploys, SOC 2 Type II in flight, and a dedicated solutions engineer from the first call.

Schedule a callRead security overview
the four pillars

Built for trust.
Verified end-to-end.

isolation

Hardware-virtualized microVMs.

Every Operator task runs in its own Firecracker microVM — separate kernel, separate root filesystem, separate network namespace. A misbehaving sub-task can't see your host or any other tenant's data.

identity

Maps to your IdP, not ours.

SSO via SAML 2.0, OIDC, or SCIM provisioning. Per-task action audit log exportable for compliance review. Service-account API keys with scoped permissions, granular role-based controls.

data

Encrypted, region-pinned, yours.

TLS 1.3 in transit, AES-256-GCM at rest with per-tenant keys derived via HKDF. Region-pinned deploys for residency. Customer secrets sit in a salted vault — decrypted only inside the microVM that needs them.

scale

Built for the org chart you actually have.

Custom seat limits, dedicated compute pools, BYOK encryption, on-prem and air-gapped deploys available. A solutions engineer assigned from week one — not month six.

included with enterprise

Everything you'd expect.
And what you wouldn't.

  • SSO via SAML 2.0, OIDC, or SCIM provisioning
  • Custom seat limits & per-team usage controls
  • Dedicated solutions engineer from week one
  • Region-pinned deploys (US, EU, UK, AU)
  • BYOK encryption & on-prem available
  • Per-task audit log, exportable for compliance
  • Custom integrations + private API access
  • 24/7 priority support with SLA-backed uptime
schedule

Pick a time. We'll bring the agenda.

30 minutes with our solutions team. We'll walk through your use case, the security model, and design a deploy plan you can take back to procurement.

May 2026
Mon
Tue
Wed
Thu
Fri
Sat
Sun
Checking availability...

Times shown in UTC.

By scheduling, you agree to our Privacy Policy. We'll only use your information to prepare for the call.

common questions

Asked & answered.

Where do I get the DPA?

Email [email protected] with your company name and we'll send the standard DPA + subprocessor list within one business day. Custom redlines are welcome.

Can you deploy in our VPC / on-prem?

Yes. We support single-tenant deploys on AWS, GCP, Azure, and air-gapped on-prem with a dedicated container registry. The microVM substrate is the same Firecracker stack we run on the public cloud.

How does pricing work for enterprise?

Custom — typically a per-seat license + a usage tier for tasks, with volume discounts above 100 seats. Annual contracts only at this level. We design the plan together on the call.

What's the SOC 2 status?

Type II audit is in flight, expected to complete in Q3 2026. Type I report and our security questionnaire are available under NDA today.