Kimss System Architecture
Model-Agnostic Enterprise Gateway: identity, Hermis orchestration, write-only vault, and governed API calls. You hold the models; Kimss is the control plane.
EXPLORE SYSTEM
Session + Key Security
Entra OAuth, Kimss session JWT, and API key fallback with role mapping.
Dual-layer security gateway
Scoped API key first, then iam.mcp_tool_grants SSO RBAC before an internal MCP tool runs. Marketing explainer: /zero-trust-ai-architecture.
Hermis orchestration loop
Physical pause on tool_call: kill switch, in-memory Key Vault unwrap, then tenant audit_log. Not Airflow.
Web, docs & API clients
Vite SPA at /app, public landing and /docs, and SDK or REST clients call the same FastAPI surface.
FastAPI + Hermis control plane
Agent SSOT, kill switch, Guardrails, governed-request meters, and vault unwrap in memory — never a second model vendor.
Operational State
Tenant/user metadata, audit and usage rows, cache keys, and support artifacts.
Your data plane (not hosted by Kimss)
Vaulted Connected Infrastructure. APIM byo-proxy hops to your OpenAI-compatible endpoint or native Anthropic Messages. Customer MCP stays on your HTTPS URL.
06 Telemetry & Article 12 audit
Customer inference always hits APIM byo-proxy so GatewayLogs remain the immutable hop. App telemetry records governed requests (zero Kimss credits on BYO). Foundry ai-proxy is not the customer path.