[ capabilities ]

Everything a security team does,
now conversational.

More than a chatbot. Kikimora is an AI security analyst: CSPM, vulnerability management, and compliance, all in one conversation. The agent runs on the Kikimora Platform, where findings, assets, scans, scores and compliance evidence persist after the chat ends.

See the platform behind it

Centralized Security Hub

One conversation across your entire security operation.

Instead of logging into ten consoles, fetch, correlate and analyze findings across every connected platform with a single request. The answers are not lost when the chat ends: the Kikimora Platform dashboard rolls them into 13 widgets, each one a door into the module that owns the detail.

Attack Surface Management

Identify external assets you didn't know existed.

Exposure continuously discovers the domains, hostnames and IP addresses tied to your organization, then records the open ports, service banners and EPSS exploit probability of every CVE it finds. Shodan and the locally deployable Network Scanner are built in, so the outside view and the inside view land in the same table.

Vulnerability Management

Catch risks before they become incidents.

Every finding lands in one repository, whether a Qualys WAS scan, the endpoint agent, exposure discovery or a pentester found it, and a rescan updates the entry instead of duplicating it. Each carries a lifecycle, an owner, a Time to Resolve for SLA tracking, an activity log and a proof-of-concept viewer.

Contextual Risk Scoring

A score about your environment, not a generic severity table.

The Kikimora Score rates every finding from 0 to 100 using five factors: CVSS, EPSS threat intelligence, hardening, asset criticality and exposure, and the breakdown panel shows the points each one contributed. Risk Management then ranks CVEs by portfolio impact and previews the risk reduction of the fixes you select.

Automated Remediation

Fix issues at machine speed, on your say-so.

Don't just find problems. Kikimora drafts the CLI command, the Terraform change or the direct API call, shows it to you, and applies it only after your approval, with every execution logged and exportable.

Incident Response

Streamline your reaction to threats.

When a critical finding lands, Kikimora retrieves the affected resource details, drafts a ServiceNow incident and assigns it to the right team from one prompt, after you approve. Back in the platform, the finding keeps its owner, status and activity log, so the incident and the vulnerability record never drift apart.

Endpoint Security and Compliance

The controls auditors ask about, measured on every host.

The built-in endpoint agent (Wazuh under the hood) runs CIS benchmark hardening checks, tracks file and Windows Registry integrity, and flags software outside your allow-list, per host. Together they are evidence for ISO 27001, SOC 2, PCI-DSS and NIS2 controls, read straight from the hosts.

Manual Pentest Management

Human-driven testing, tracked next to the scanners.

Each engagement becomes a manual test with an OWASP-style checklist for Web, Android or iOS, and every check is marked Pass, Failed or N/A as the tester works. Findings are recorded with technical scope, owners and proof of concept, and flow into the same central repository as scanned ones.

DevSecOps Integration

Shift security left.

Integrate directly with GitHub and SonarCloud to catch code-level vulnerabilities, leaked secrets and security hotspots during development, before insecure code reaches production. Ask across every repository and project at once instead of tab-hopping between them.

Complex workflows, made simple.

Kikimora handles multi-step logic so you don't have to.

01. WEB SECURITY ASSESSMENT
Assess 'example.com': Find public assets, check GitHub for code alerts, and list active Qualys scans.

Combines ASM, SAST, and DAST into one report.

02. INCIDENT ESCALATION
Find critical AWS findings. For each EC2 instance affected, create a ServiceNow incident assigned to SecOps.

Automates ticket creation and context gathering.

03. DB SECURITY AUDIT
Review Supabase security advisors and check auth logs for unusual patterns in the last 24h.

Merges config review with log analysis.

Start Free

30 assets · unlimited integrations · 5 million AI credits · no credit card