Transparent by default
The full source is on GitHub under AGPL v3. Your security team reads it, audits it, or forks it. Nothing is hidden behind proprietary binaries.
Governance-grade controls from day one. The same platform runs on our cloud and on your own servers, with the same isolation, access control, auditability, and governance over what agents may do.
KANAP is designed for IT departments that handle sensitive data. We treat your data the way we want IT vendors to treat ours, transparent, isolated, and within reach when you need it.
The full source is on GitHub under AGPL v3. Your security team reads it, audits it, or forks it. Nothing is hidden behind proprietary binaries.
Row-level security in the database itself enforces tenant isolation on every query the application runs.
Your data is yours. CSV export on the main lists, document export to PDF, DOCX and ODT. No extraction tax.
KANAP is multi-tenant at the database level. Every row in every shared table carries a `tenant_id`, and PostgreSQL Row-Level Security policies enforce the filter on every read and write. The policy is part of the database schema, so it applies to every query the application runs.
Standard practices, applied rigorously. Strong password hashing, encrypted secrets, hashed tokens, and HTTPS on every cloud connection.
Fine-grained permissions per module, per role. Every feature gate and every entity query honours the same RBAC matrix, including Plaid and MCP.
Every meaningful change is recorded. Who changed what, when, with before and after snapshots. Activity is visible in the app.
Agents act under the same controls as everything else, plus limits specific to autonomous work. Every agent action is recorded and scoped to what you allowed, and you can stop an agent at any moment. Every agent starts with each type of action waiting for your approval. You choose when a type runs automatically, with the agent's track record (reviewed proposals, acceptance rate, days of activity) shown beside the choice.
Cloud deployments run on Linux hosts in Germany, in the European Union, with Cloudflare in front. Self-hosted deployments run wherever you choose. Both ship with the same security model.
We're happy to share architecture details and walk through a threat model with your security team.