GCP-native architecture
Deployed entirely on Google Cloud — Cloud Run, Cloud SQL (PostgreSQL), Google Cloud Storage, DuckDB, and Vertex AI. No third-party infrastructure exposure.
Machines propose.
Humans confirm.
Auditors verify.
Kosmos surfaces hidden relationships across your infrastructure, deployments, and data. AI proposes. Humans verify. Every decision is explainable, auditable, and built for enterprise security.
Go to Trust Center →Kosmos runs on managed GCP services end-to-end. Fewer surfaces to harden, fewer surfaces to breach — with CSRF, rate limiting, and PII redaction enforced at the app layer.
Deployed entirely on Google Cloud — Cloud Run, Cloud SQL (PostgreSQL), Google Cloud Storage, DuckDB, and Vertex AI. No third-party infrastructure exposure.
Firebase Auth for user sessions. Backend validates tokens on every API call. Service-to-service auth via GCP IAM service accounts.
State token validation on all OAuth flows. Double-submit cookie pattern enforced on all state-changing requests. IP-based rate limits on all endpoints.
TLS 1.2 and above for data in transit. OAuth tokens encrypted at the application layer. Secrets in GCP Secret Manager with version control.
Defense-in-depth isolation at the application layer. Each organization’s data is scoped by org identifier across all storage systems.
Auth events, integration activity, and RCA generation are logged to a structured audit trail. Emails and credentials are redacted before emission.
Deployed entirely on Google Cloud — Cloud Run, Cloud SQL (PostgreSQL), Google Cloud Storage, DuckDB, and Vertex AI. No third-party infrastructure exposure.
Firebase Auth for user sessions. Backend validates tokens on every API call. Service-to-service auth via GCP IAM service accounts.
State token validation on all OAuth flows. Double-submit cookie pattern enforced on all state-changing requests. IP-based rate limits on all endpoints.
TLS 1.2 and above for data in transit. OAuth tokens encrypted at the application layer. Secrets in GCP Secret Manager with version control.
Defense-in-depth isolation at the application layer. Each organization’s data is scoped by org identifier across all storage systems.
Auth events, integration activity, and RCA generation are logged to a structured audit trail. Emails and credentials are redacted before emission.
We read what we need to correlate signals, store what we need to learn from them, and delete everything on your word. No shadow copies, no surprises.
Signal metadata from connected systems — issues, tickets, commits, messages, and traces. Minimum required scopes, read-only. Sources include Jira, Salesforce, ServiceNow, Zendesk, GitHub, Bitbucket, Slack, Linear, Pylon, and OpenTelemetry.
Signal metadata and correlation results only — no duplication of raw source data beyond what correlation requires. Stored in Cloud SQL (PostgreSQL), Google Cloud Storage, and DuckDB.
On contract termination, all customer data is deleted within 30 days. Hard-delete is available on written request to security@kosmoslabs.ai
Kosmos processes data on Google Cloud Platform (compute, storage, networking), Vertex AI (Gemini 2.5 Flash for RCA generation and text embeddings), and Firebase Auth (user authentication). A complete subprocessor list including notification providers is available on request.
All security and compliance documents are reviewed quarterly. Questionnaires and DPA requests are routed to a dedicated security alias with a five-business-day SLA.
Connect your Salesforce and Jira in one call. In 14 days, we will show you 90 days of patterns your team has been chasing manually.
Request a 14-Day Trial