> For the complete documentation index, see [llms.txt](https://docs.kyvvu.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.kyvvu.com/readme.md).

# Introduction

**The Agent Security Kernel (ASK) for AI Agents. Every agent has to ASK before it acts.**

Kyvvu is an Agent Security Kernel (ASK): an in-process security layer that evaluates each action against the agent's full task path — before the step runs — to stop data leakage and destructive actions. Runtime governance follows. It decides **allow**, **warn**, or **block** in sub-millisecond time, directly inside your agent process. No proxy. No gateway. No perceptible latency.

***

## The first 5 minutes

```bash
pip install kyvvu

kyvvu try
```

That is the whole first minute. `kyvvu try` evaluates a three-step demo agent against the [frozen baseline](/policy-authoring/bundled-baseline.md) bundled inside the package and blocks its ungated code execution — **no account, no API key, nothing on the network**. Everything below is what an account adds on top.

```bash
kyvvu auth
# → logs in via a device code; prints a code + URL to approve in your browser

# then, get an API key: open the dashboard, go to Workspace → API Keys

kyvvu init my-agent
# → scaffolds a demo agent project

cd my-agent
pip install -r requirements.txt
export KV_API_KEY=KvKey-...
python agent.py
```

The demo agent runs three decorated steps (a model call, a resource read, and a code execution) — and it is governed from the first one. **Registering an agent applies Kyvvu's bundled baseline automatically**: 15 policies, OWASP Top 10 for Agentic Applications plus EU AI Act minimal risk, with nothing to assign and no repository to connect.

So the OWASP policy "Code execution requires a preceding gate" blocks the `step.exec` on the very first run:

```
Policy blocked this step: ...
   Risk score: 1.00
   Action:     block
   * Code execution requires a preceding gate (critical)
```

That's runtime policy enforcement — evaluated against the full task history, before the step runs rather than after.

To layer more on top, assign a manifest that does not overlap the baseline. The public library is already connected to every new workspace, so there is nothing to set up first:

```bash
kyvvu list-manifests
kyvvu assign-manifest --agent-id <id> --repo-id <id> \
    --manifest manifests/security/data-exfiltration-guard.yaml
```

Assigning `manifests/security/owasp-agentic-default.yaml` instead returns 409: the baseline already holds those policy names, which is the platform telling you that you have them.

For why this architecture matters, see the blog post: [The Hot Path Tax](https://kyvvu.com/blog/2026/04/29/hot-path-tax/).

***

## Architecture

```
Your Agent Code
  |  @kv.step / LangChain handler / REST API
  v
kyvvu SDK (translates events -> Behaviors)
  |  template.match() -> deep_merge -> Behavior
  v
kyvvu-engine (in-process, sub-ms policy evaluation)
  |  evaluate() -> allow / warn / block
  |  record() -> append to task history
  |  end_task() -> queue the behavioral trace for delivery
  v
Kyvvu Platform API (platform.kyvvu.com)
  |  policy storage, incident management, audit trail
  v
Dashboard (platform.kyvvu.com)
  |  manifest assignment, incident triage, reports
```

The engine runs **in your process**. Policy evaluation is pure CPU - no network calls, no database queries, no I/O. Policies are fetched in the background and cached. Trace delivery happens asynchronously in a background worker after the task ends.

***

## What Kyvvu does

1. **Registration enforcement** - agents declare their name, purpose, owner and risk classification when they register. Policies validate these declarations at startup, and the tools an agent declares are what the allowlist policy checks each step against.
2. **Runtime policy evaluation** — every atomic step your agent takes is evaluated against loaded policies *before* execution. Decisions depend on the full ordered history of the current task ("policies on paths").
3. **Behavioral trace logging** - completed steps are recorded into an audit trail, queued for delivery to the platform API when the task ends. The trace is a structured JSON record of everything the agent did.
4. **Incident management** - policy violations generate incidents that surface in the dashboard for triage and resolution. An incident is created for each step that violates a policy.

***

## Quick links

| Resource      | URL                                                                                     |
| ------------- | --------------------------------------------------------------------------------------- |
| Documentation | [docs.kyvvu.com](https://docs.kyvvu.com)                                                |
| Platform      | [platform.kyvvu.com](https://platform.kyvvu.com)                                        |
| GitHub        | [github.com/Kyvvu/platform](https://github.com/Kyvvu/platform)                          |
| PyPI          | [pypi.org/project/kyvvu](https://pypi.org/project/kyvvu)                                |
| Paper         | [Runtime Governance for AI Agents: Policies on Paths](https://arxiv.org/abs/2603.16586) |
| Jobs          | [kyvvu.com/join](https://kyvvu.com/join/)                                               |

***

## Next steps

* [Installation](/getting-started/installation.md) — install the SDK and set up your account
* [Your First Agent](/getting-started/first-agent.md) — walk through `kyvvu init` step by step
* [Architecture](/core-concepts/architecture.md) — understand the three-package split and why the engine is in-process
* [Creating Policies](/policy-authoring/creating.md) — author your first custom policy
