Kikimora is an AI security agent that connects AWS, Azure, Cloudflare, GitHub, Qualys, Tenable, FortiGate (18 integrations in all) into one conversational interface. Triage findings, get the fix drafted, approve every change. No tab switching.
Your tools don't talk to each other. Kikimora listens to all of them and answers as one. One AI security agent across your whole stack, with no swivel-chair between consoles.


4 critical findings across 3 providers - correlated into one incident.
Remediation proposed. Awaiting your approval.


4 critical findings across 3 providers - correlated into one incident.
Remediation proposed. Awaiting your approval.
One command fans out across every connected service at once.
Raw signals are fused into incidents with severity and blast radius.
Recurring sweeps and audits run while you sleep. Digest at dawn.
Six things teams ask Kikimora every day, from threat triage to compliance automation, and what comes back.

Three items need you, ranked by severity:
The agent is how you talk to it. The platform is where everything lives: findings, assets, scans, scores and compliance evidence persist there, the agent reads and writes to it, and you can open any of it whenever you want the full picture.
Ranked by portfolio impact, not by generic severity.
Each finding carries portfolio points across every affected asset, so a moderate flaw on many hosts can outrank a severe one on a single box. Select the fixes you plan to ship and read the projected risk reduction before anyone patches.
Read about this moduleBubble size = affected assets. Hover to view details.
| CVE | Finding | Avg. Kikimora Score | CVSS Score | Affected Assets | Portfolio Score | ||
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | Apache Log4j2 RCE (Log4Shell) | 91.30 | 10.0 | 9 | 7,412 pts | ||
| CVE-2017-0144 | SMBv1 RCE (EternalBlue) | 69.80 | 8.1 | 60 | 6,186 pts | ||
| CVE-2014-0160 | OpenSSL Heartbleed | 65.70 | 7.5 | 48 | 4,652 pts | ||
| CVE-2023-44487 | HTTP/2 Rapid Reset DoS | 65.90 | 7.5 | 38 | 3,654 pts | ||
| CVE-2021-34527 | Windows Print Spooler RCE (PrintNightmare) | 72.30 | 8.8 | 20 | 2,110 pts | ||
| CVE-2019-0708 | Remote Desktop Services RCE (BlueKeep) | 78.40 | 9.8 | 12 | 1,376 pts | ||
| CVE-2018-11776 | Apache Struts 2 RCE | 72.20 | 8.1 | 13 | 1,290 pts |
Three steps between you and a fully orchestrated security response.
Link AWS, Azure, GitHub, Cloudflare, Qualys, FortiGate, and the rest of your 18-tool stack in minutes. OAuth and API key setup - no agents to install, zero footprint on your infrastructure.
OAuth & API key auth · 5 min average · Read-only where possible
Describe a risk, a task, or a question in plain English. The Agent understands context, queries the right services in parallel, and synthesizes a complete, correlated answer.
Natural language · Multi-tool parallel queries · Session memory
Review every proposed action before anything runs. Confirm with one click. Every execution is logged with a full audit trail - immutable and exportable for compliance - and every finding is tracked to closure in the platform: owner, status, time to resolve.
Human-in-the-loop · Immutable audit log · Rollback on request
Stop context-switching between dashboards. Kikimora connects your entire security stack (cloud, AppSec, pentest, ITSM) and lets you query, remediate, and automate across all of it in plain English. One conversational interface for CSPM, vulnerability management, and compliance.
Security Hub findings, GuardDuty threats, IAM auditing, S3 policies, EC2, Inspector, and CloudTrail event monitoring.
Defender recommendations, security alerts, RBAC auditing, NSG rules, and vulnerability assessments across all subscriptions.
Firewall rule management, DNS monitoring, WAF configuration, and zone security settings - create, update, and delete rules via conversation.
Give each client its own tenant: separate integration keys, fully isolated, no cross-contamination. Switch context between clients in a click. Bill month by month on the assets you actually assess per tenant, with no annual lock-in to carry on anyone's behalf.
Distinct integration credentials for every client environment. Server-side isolation, no cross-tenant contamination.
Move between client environments in one click. No re-auth, no console juggling, no context lost.
Pay month by month on assessed assets per tenant. No annual lock-in to carry on a client's behalf.
Stand up a new client environment in hours, not weeks. Scale each tenant up or down as their load changes.
Every action runs in its own workspace context. No cross-tenant contamination, by design.
AES-256 at rest, TLS 1.3 in transit. Credentials never touch plaintext - not even in logs.
Never used to train AI models. The models Kikimora uses come from Google and Anthropic, served only from Vertex AI endpoints in the EU. Full ownership, deletion on request.

Two write actions, both approved by m.malinov:
Every read and write is logged and exportable. Reads stayed read-only - 14 queries, 0 mutations.
GDPR · SOC 2 ready · ISO 27001 aligned · NIS2 · read-only by default
No credit card. No commitment. Full access to Kikimora's core capabilities with real integrations from day one.
An asset is a host, domain, IP address, web application or endpoint in your inventory.
[ faq ]
Everything you need to know about Kikimora.

Yours now watches your stack.
Start Free