Scale AI coding without losing control.
Govern every user, model, dollar, and data boundary from one enforcement layer, inside your cloud or ours.
Your cloud. Your data. Your rules.
Open models run inside your AWS, GCP, or Azure account. Prompts, completions, and code never leave your cloud.
Other AI vendors
Your code, their cloud.
Closed APIs send every prompt, file, and secret to infrastructure you do not control and jurisdictions you may not be allowed to use.
Kimchi Enterprise
Your code, your perimeter.
Every approved model runs inside your VPC. You decide what crosses the boundary; the default is nothing.
Built for regulated teams.
Identity, audit, and compliance controls sit on top of a VPC-native architecture, with proof for every policy.
Identity
Identity & access
SSO, SAML, OIDC, group-based RBAC, and SCIM-ready provisioning tied to your identity provider.
Audit
Every request traceable
Record every prompt, completion, and tool call. Ship logs to your SIEM and retain an immutable audit trail.
Secrets
Credentials stay isolated
Agents request scoped credentials at runtime from your secrets manager and never see raw keys.
Data
No training on your data
No customer prompts, code, or outputs are used for model training in serverless or self-hosted modes.
Compliance
Enterprise-ready posture
SOC 2 Type II, ISO 27001, and PCI DSS AOC, with HIPAA-ready architecture and BAA on request.
Providers
Explicit external routing
Use your own provider keys with clear data flows and policy approval for every external model request.
No rogue merges. No leaked secrets. No runaway spend.
Every coding agent routes through one policy layer before a request reaches a model.
Kimchi enforcement
Policy and control layer
Kimchi web app
Reports and insights
See exactly where your AI spend is going.
Track spend by developer, team, model, and tag in real time. Forecast before scaling and enforce limits before the invoice arrives.
Use the right model for every task.
Route planning and execution by complexity, sensitivity, quality, and team policy. Sensitive work defaults to approved models in your VPC.
Kimchi Auto
Model orchestration
Each request is classified before a model is selected.
Complex reasoning
~12% of requestsPolicy-approved planning models
Architecture, debugging, and long-context analysis route to an approved planning model when policy allows.
Self-hosted execution
~88% of requestsOpen models in your VPC
Generation, refactors, tests, and embeddings run on your GPUs at a lower unit cost.
One command. Keep your existing workflow.
Kimchi setup detects Windsurf, Cline, OpenCode, and VS Code, then updates compatible endpoints automatically. Start serverless and move to self-hosted when compliance or cost demands it.
Connect the tools your engineers already use.
Bring approved context, persistent memory, and spec-driven workflows into one governed coding platform.
GitHub Enterprise
PRs, diffs, comments, and scoped status checks.
GitLab
Merge requests and pipelines, including self-managed instances.
Jira
Read tickets, link commits, and create issues from findings.
Confluence
Specs, runbooks, and ADRs available during planning.
Slack
Notifications and channel triggers with team routing rules.
Linear
Issues, cycles, and projects connected bidirectionally.
Postgres / MySQL
Scoped queries for retrieval and analysis.
Cloud storage
S3, GCS, and Azure document and artifact storage.
Okta · SAML / OIDC
SSO and RBAC mapped to identity-provider groups.
Vault / Secrets Manager
Credential isolation without exposing raw secrets.
Datadog · Splunk
Send prompts, completions, and tool calls to your SIEM.
Custom MCP
Turn an approved HTTP endpoint into a typed tool.
The questions enterprises ask.
Bring governed AI coding inside your perimeter.
We’ll model your break-even, review the architecture, and build a deployment plan around your requirements.
