Kindo
Internal Debrief
Kindo Internal Only
August 7, 2026 · SOC for AI Deep Dive

Meeting Debrief:
What Deloitte Told Us
(Without Saying It)

Krishna's team joined a deep dive session to evaluate whether Kindo can support a managed AI SOC offering. Here's what they signaled, what's missing, and what we do next.

Kindo

Charlie · Joana · Victor

Deloitte

Krishna (lead) · Adelina · Harsha · Ravi · Tim

Kindo's Four Pillars for SOC for AI

Pillar 1

Inference Proxy Live

Point any AI workload at Kindo as LLM gateway. Audit logging, DLP, model/access policy enforcement. Operational today.

Pillar 2

Federated MCP Gateway Live

Centralized tool access management. One MCP config → all corporate tools. Governance of which teams get which integrations. Reduces end-user friction.

Pillar 3

Telemetry Foundation Only

OpenTelemetry GenAI semantic conventions. ClickHouse foundation shipped. Product features (traces, metrics, collector API) not yet exposed. Timeline: early 2027.

Pillar 4

Policy Hooks Roadmap

Generic enforcement at tool-call/LLM boundaries. Webhook or agent-based judges. Configurable fail-open/fail-closed per hook. Not yet built.

Key Concerns From Krishna's Team

1. Scalability & Single Point of Failure

Krishna · 48:46

If Kindo proxies all AI traffic, it becomes a SPOF. Clients will demand resilience proof before signing. Charlie responded with blue-green/auto-scaling, but no concrete numbers or architecture diagram exists yet.

"There'll be tons of scrutiny from the clients on scalability, because you could become a single point of failure."

2. Cross-Session Behavioral Detection

Krishna · 42:47

Krishna wants risk scoring across multiple API calls and sessions — not just per-transaction policy. This is SOC language, not firewall language. If Kindo can do this, it's a SOC platform. If not, it's a policy gateway.

"Sometimes the risk manifests over multiple API calls over a period of — through the entire session. It's not about a single transaction, but monitoring behavior over a series of transactions."

3. Inline Prevention vs. Detection

Krishna · 50:18

Krishna drew the distinction himself: simple policies (block tool access) = inline prevention. Deep inspection = detection only, not inline. This is defense-in-depth framing — the same architecture CISOs already use for network security.

"If you have to do any deeper inspection, I don't think we can do it in an inline mode. So those things could be more detection rather than preventions."

4. Telemetry Timeline Pressure

Krishna · 33:24

Krishna immediately tested whether swimlane could be deprioritized to accelerate telemetry. Telemetry is the capability he needs to sell SOC for AI. Swimlane is an internal cost-avoidance play — it doesn't help him close deals.

"If we say, you know, maybe we park swimlane, then you could pull the timeline forward."

5. Client SIEM Preference

Adelina · 29:39

Clients may want to use their existing SIEM (Google SecOps, Splunk) rather than ClickHouse. Charlie confirmed Kindo can forward telemetry to external systems and potentially make value-added features optional. Minimum ClickHouse may still be required for system health.

6. Failover Strategy

Joana · 55:41

Fail-open is unacceptable for governance clients. Fail-closed is too risky without knowing downtime. Charlie: configurable per hook, standard HA (blue-green, zone distribution). But the operational story needs sharpening.

7. Client Prerequisites & Change Management

Tim · 51:07

Deploying AI governance requires: Kindo deployment, reconfiguring all AI workloads to route through Kindo, revoking direct API key access, and employee communication. The friction is change management, not infrastructure. MDM-assisted reconfiguration planned but not built.

What This Means for Kindo

Krishna is building a go-to-market in his head.

He wasn't asking exploratory questions. He was testing whether Kindo can support the pitch he already wants to make: Kindo as the platform for a managed AI SOC offering. The same model Deloitte uses with Splunk/Google SecOps for traditional cyber SOC — but for AI workloads.

Charlie presented four technical pillars. Krishna heard three sellable layers:

Layer 1 · Today

Prevent

Inference proxy + MCP gateway. Policy enforcement, DLP, access control. Live now.

Layer 2 · Q1 2027

Detect

Telemetry + behavioral analysis. Cross-session risk scoring. The SOC capability.

Layer 3 · Q2 2027+

Respond

Shadow AI discovery via MDM/EDR orchestration. Remediation workflows. Highest value, longest runway.

The risk: If Kindo doesn't provide the framing materials Krishna needs, Deloitte will build the narrative themselves — and may misposition Kindo's capabilities or make commitments the product can't support.

What Nobody Closed in the Meeting

1

No HA Architecture Diagram

The SPOF concern was raised but only addressed verbally. Krishna needs a one-slide diagram he can put in front of a CISO showing redundancy, failover, and zone distribution.

2

No Compliance Framework Mapping

Zero mention of SOC 2, NIST AI RMF, or ISO 42001 in a 58-minute governance conversation. Deloitte sells compliance. They need to map Kindo capabilities to framework controls.

3

Pillar 2 Unconfirmed in Current Build

Charlie was "confident" the inference proxy is in the latest build but couldn't confirm MCP gateway 100%. Needs verification before making further claims.

4

Subsidized Plans Problem Unsolved

The biggest blocker to "force everything through Kindo": employees lose their $20/mo Claude Pro access when routed through API pricing. No answer offered.

5

Local Models — No Answer

Charlie flagged that shrinking models will proliferate on endpoints, making API key control insufficient. Acknowledged as an open problem with no solution timeline.

Recommended Actions

Defense-in-Depth Framing Document

Translate 4 pillars → 3 layers (Prevent / Detect / Respond). Give Krishna the narrative he can use internally at Deloitte. One-pager, not a whitepaper.

Victor + Charlie This week

HA Architecture Diagram

One slide showing Kindo deployment with redundancy, failover, zone distribution. Doesn't need to be implemented — needs to be the target architecture a CISO can evaluate.

Charlie This week

Telemetry Demo (Scripted)

Even a canned walkthrough showing trace data flowing through ClickHouse/HyperDX. Krishna's team expected to see something — we need to deliver before next touchpoint.

Charlie + Joana Before next meeting

Confirm Pillar 2 in Current Build

Verify MCP gateway is functional in the latest Deloitte build. Binary answer needed before making further claims.

Charlie This week

Follow-Up Email to Krishna/Adelina

Summarize what was discussed, confirm commitments, share any URLs (OTel GenAI conventions, Braintrust example). Maintain momentum before the weekend.

Joana Today

Compliance Framework Mapping

Map Kindo capabilities to NIST AI RMF / SOC 2 / ISO 42001 controls. Deloitte will need this to position the offering to compliance-driven buyers.

Victor + Charlie Q3 2026