SecKav // application · api · agent · access

Read every request.
Score every actor.
Decide in real time.

One security layer across your applications, APIs, AI agents, and private access — inspected at the edge in under two milliseconds, governed by intent, never trusted by default. When something does get through, every engine’s signals are correlated into one triaged incident you can contain in a single click.

< 2 ms
edge decision
43
inspection modules
0–100
trust, per request
1
DNS change to deploy
fabric · live topology3 systems
applications · agents · infrastructure
edge · live verdict streamlive

Four systems. One fabric. Every request judged the same way.

// the life of a request

Every request runs a gauntlet — and carries a verdict out the other side.

The first request costs about 2 ms while the tenant’s policy is cached at the edge. The next ten thousand are decided in under a tenth of a millisecond, without touching a database.

Trace the full pipeline
req 0x7af3 · GET /account/orders/8813ALLOW · 1.4ms
1resolveDNS → SecKav edgeROUTE
2penalty boxbanned IP? O(1) ValkeyPASS
3normalizedecode · strip evasionCLEAN
4inspectWAF · bot · API shieldSCORE 12
5trustactor score 0–100TRUST 88
6originforward to hidden originPROXY
7responsemask Aadhaar / PAN in RAMMASK

// one request · four decisions

verdict

01 / 04 · SecKav Shield

The attack stops here.

Every web and API request is normalized, inspected, and decided at the edge—before it can reach your application.

edge verdictlive

Incoming request

POST/v1/payments
card=4242&query=1' OR '1'='1

SQL injection · confidence 99%

origin never contacted

Blocked

02 / 04 · NEXUS Intelligence

Agents get intent, not unlimited access.

SecKav verifies the agent, understands the task, and permits only the tools and data that task requires.

agent decisionlive

Verified agent

finance-analyst-prod

92

trust

Declared intent

Create weekly summary

Requested tool

export_customer_data

Read access allowed. Export and write permissions removed.

Scoped

03 / 04 · NEXUS Connect

Private access stays private.

Identity, device posture, route policy, and post-quantum key confirmation establish one narrow path to one resource.

private sessionlive

User

maya@acme.com

Private app

payroll.internal

Identity

Verified

Device

Healthy

PQC key

Confirmed

One user. One application. No network exposure.

Connected

04 / 04 · SecKav XDR

Many signals become one response.

XDR joins edge, identity, agent, and access evidence into one incident—then contains the actor where enforcement already lives.

incident responselive

Incident XDR-0184

Credential attack progressed to protected-data probing.

Critical · 94
18 signals3 engines1 actor

Recon → Access → Collection

Contained

How the four SecKav security systems work together

SecKav Shield protects applications and APIs with WAF, bot management, Layer 7 DDoS defense, API Shield, active deception, and India DLP.

NEXUS Intelligence gives AI agents verified identity, intent authorization, tool governance, prompt-injection protection, RAG provenance, and living trust.

NEXUS Connect provides identity-aware private access for people and machines using posture, least-privilege routes, private DNS, and hybrid post-quantum key confirmation.

SecKav XDR correlates signals by entity, maps attack chains to MITRE ATT&CK, prioritizes incidents, explains the evidence, runs response playbooks, and contains threats.

// the surface, in full

Roughly a hundred and thirty controls, grouped by what they defend.

Applications & APIs

  • WAF — SQLi · XSS · LFI · RCE · zero-day
  • Bot & AI-crawler management
  • L7 DDoS penalty box · 0 ms drop
  • API shield — SSRF · BOLA · GraphQL · JWT
  • India DLP — Aadhaar · PAN in memory
  • Supply-chain & script firewall
Open applications

AI agents

  • Agent identity registry & rotation
  • Living trust score, every request
  • Intent-based access control
  • MCP shield & tool-call inspection
  • Shadow-agent discovery
  • AI-generated least-privilege policy
Open ai

Access & governance

  • Device posture — pass · restricted · fail
  • Hybrid post-quantum handshake
  • Guest & contractor time-boxed links
  • Magic DNS — private addressing
  • Compliance across 8 frameworks
  • Signed audit & attestation exports
Open access

Detection & response

  • Signals correlated per entity into incidents
  • AI triage with a plain-English why-trail
  • MITRE ATT&CK stage & technique mapping
  • One-click containment on the edge
  • SOAR-lite playbooks — recommend or auto
  • Connectors for external EDR · cloud · IDP
Open detection

// governance

Evidence, not adjectives.

Coverage across eight frameworks, with signed exports, breach register, RoPA, config versioning, and content-hash-verified attestations.

GET /v1/compliance/attestation200 · verified
DPDPCERT-InRBINIST-PQCSEBI CSCRFISO 27001SOC 2GDPR
sig=hmac-sha256 · contentHash=3f9a…c21 · signed_at=2026-07-19T

Browser SDK

The bridge from the browser to the platform.

A single publishable key wires consent, data-rights, and passive bot telemetry into any page — feeding the edge without ever exposing a secret in the browser.

  • Consent banner — DPDP §6, 22 Indian languages
  • Age gate — children’s-data rule
  • Data-rights widget — access · correct · erase
  • Bot telemetry — mouse · canvas · WebDriver
  • Script-blocking interceptor — hold 3rd-party until consent
  • Consent sync + server-side verify helper
Not yet published to npm / CDN
index.html
<script src="https://cdn.seckav.tech/sdk.js"></script>
<script>
  SecKav.init({ apiKey: 'pk_live_…' })   // publishable, write-only
  // consent, age-gate & rights portal render automatically
</script>

Point your nameservers. Watch it decide.

No agent to install, no code to change. Every request starts running the gauntlet the moment your DNS resolves.

edge · live verdict streamlive