🔐 Zero Trust Security Platform

AI Security Automation.
Governed by Default.

AI-assisted security investigation and remediation with policy checks, risk scoring, approvals, and audit records around governed execution paths. Bring connected security evidence, multiple Brains, and 26 capability areas into one local control plane.

macOS package status Download for Windows View Documentation → GitHub

Required — Docker Desktop. Enkstein runs its governed services locally. Every launch checks Docker first, opens it when stopped, and waits for docker info before starting services. If it is missing, the official Docker installation flow opens and Enkstein keeps checking until the engine is ready. Allow 4 GB RAM.

Optional — Ollama. Free local Brains that work offline. Without it Enkstein still runs on your own Codex or Claude subscription, or an API key.

Current release: v0.8.4  ·  macOS 14+ Developer ID signed and notarized  ·  Windows 10/11 x64 builds are unsigned for now  ·  all downloads & checksums

26
Capability Nodes
9
Platform Engines
Zero Trust
by Design
1391
Backend Tests
Latest shipped: Plexus — governed peer messaging between Capability Nodes, with required participant identity, held-message approval, and verify/acknowledge on read. Reflexes — policy-bounded local autonomy: a Node evaluates an event against registered reflexes and acts within its bounds, with every decision recorded. Regeneration — signed Node checkpoints and governed regeneration runs, so a Capability Node can be restored from a verified checkpoint. Command — multi-channel command ingestion (Teams · Slack · webhook · email · CLI) with multi-operator approval, self-approval guards, timeline audit, bulk review, and delegation controls. Two-Way Channel Replies — Slack/Teams outbound status cards now preserve thread metadata, expose delivery state, and include approval action metadata for queued commands. Model Cortex — policy-governed AI model routing with tenant-scoped profiles, call audit, and Swarm Judge synthesis. Swarm Orchestration — parallel multi-agent investigation with SSE live stream, suspicious-identity preset, ticket handoff, and compliance rollup. Memory Cortex Review — Swarm-proposed incident memory now has approve/reject review and rollback controls before it influences future investigations. Skill Pack Lifecycle UI — governed install scan path, update preview, upgrade, and rollback controls are now available from the Skill Packs page. Execution Ring Policy — 4-tier privilege isolation (ring0 blocked → ring3 auto-allow) across exec channels and remediation. 17 Security Fixes — auth deadlock, DEBUG=false default, port binding, SSRF blocklist, JWT identity enforcement, bcrypt prehash, rate limiting, security headers. OWASP ASI Evidence Matrix — honest LLM01–LLM10 + ASI-01–ASI-10 mapping with 22 dedicated evidence tests plus per-control test anchors. Connector Provenance — SHA-256 + Ed25519 signature verification at skill pack install time.

From Evidence to Action.
Governed in One Workspace.

The Trust Fabric is Enkstein's central enforcement layer — a 6-stage pipeline that evaluates every security action before it executes.

📥
Step 1
Action Request
Any security action — scan, remediation, policy change — enters the pipeline.
🔍
Step 2
Anomaly Detection
Behavioral baselines flag unusual patterns before policies run.
📋
Step 3
Policy Evaluation
Flexible rule engine checks organizational and compliance policies.
⚖️
Step 4
Risk Scoring
Dynamic risk scores determine the required authorization level.
📝
Step 5
Audit Log
Every evaluation is immutably logged with full context and rationale.
Step 6
Decision
Allow, Deny, Escalate, or Contain — with full audit trail attached.

26 Capability Nodes + Core Control Surfaces

Each Capability Node is a self-contained security domain module with its own provider adapters, findings engine, and governance integration. Core surfaces add model routing, command control, and governed deployment release gates.

🤖
AI Security
AI & LLM Security with Microsoft AGT PromptDefenseEvaluator integration
🪪
Identity Security
Identity Governance & Non-Human Identity (NHI) management
☁️
Cloud Security
Cloud Security Posture Management across multi-cloud environments
🌐
Exposure Management
External Attack Surface Management & continuous exposure monitoring
🛡️
Endpoint Security
Endpoint Detection & Response with behavioral threat correlation
🔍
Threat Analysis
Threat Intelligence & Detection — correlate IOCs across all capability nodes
📋
Security Telemetry
Log Management & SIEM integration for centralized security telemetry
🌐
Network Security
Network Security monitoring, segmentation, and traffic analysis
🔑
Privileged Access
Access Control & IAM policy enforcement across systems and services
🗂️
Data Security
Data Loss Prevention — classify, monitor, and protect sensitive data flows
📱
Application Security
Application Security testing, SAST/DAST, and runtime protection
☁️
SaaS Security
SaaS Security Posture Management — OAuth, shadow IT, and misconfiguration detection
⚙️
Configuration Security
Configuration Compliance — drift detection and remediation across infrastructure
Compliance Assurance
Compliance Frameworks — SOC 2, ISO 27001, NIST, CIS, and custom controls
🔒
Privacy Governance
Privacy & GDPR enforcement — consent, data subject rights, and PII tracking
🏢
Vendor Risk
Third-Party Risk Management — vendor assessments and supply chain security
👤
User Risk
User Behavior Analytics — anomaly detection for insider risk indicators
🔎
Insider Risk
Insider Threat Detection with contextual risk signals and case management
Security Automation
Automation Security — govern scripts, pipelines, and automated processes
🗺️
Attack Path Analysis
Attack Path Analysis — visualize lateral movement and blast radius
💻
Developer Security
DevSecOps & CI/CD security — secrets scanning, SBOM, and pipeline governance
🧱
Terraform Governance
Terraform & IaC governance — build modules from plain English, review HCL, analyze plans, and map controls
🧠
Threat Intelligence
Threat Intelligence Feeds — ingest, normalize, and operationalize external intel
🔄
Recovery Readiness
Incident Recovery — playbooks, runbooks, and recovery validation workflows
🔌
Custom Capability
Custom REST Integrations — extend Enkstein to any security tool or API
🧩
Model Cortex
AI Model Governance — policy-governed model routing, tenant-scoped profiles, call audit, and Swarm Judge synthesis
Command
Multi-channel command ingestion (Teams · Slack · webhook · email · CLI) with multi-operator approval, timeline audit, and bulk review
🚀
Release Governance
Zero Trust deployment preflight for CI/CD, GitOps, cloud SDK/CLI, script, full-stack, and AI-stack release gates

Always-On Intelligence. Built In.

Beyond the 26 capability areas and core control surfaces, these engines provide policy, orchestration, and evidence services to the workflows wired through them.

🛡️
Trust Fabric
Central zero-trust enforcement for governed security actions: policy evaluation, risk scoring, anomaly detection, and attributable audit records.
🔄
Swarm Orchestration
Parallel multi-agent investigation with planner, dispatcher, judge synthesis, SSE live stream, suspicious-identity presets, and ticket handoff to Jira/PagerDuty.
🚀
Release Governance
Deployment request → Release Governance preflight → Trust Fabric decision → approval/execute handoff → SHA-256 evidence bundle.
🚨
Autonomous Remediation
Finding → playbook matching → action execution → human approval gate → one-click rollback. 5 built-in playbooks, Okta/Entra/AWS/CrowdStrike integrations.
💍
Execution Ring Policy
4-tier privilege isolation: ring0 (blocked), ring1 (2 approvals), ring2 (trust-gated), ring3 (auto-allow). Deterministic execution_ring_violation deny reason on all violations.
📡
Channel Gateway
Normalizes Teams, Slack, webhook, email, and CLI commands into a single policy-governed Command contract. Multi-operator approval, bulk review, timeline audit.
🏥
SRE Policy Engine
Circuit breaker, error budget enforcement, and SLO primitives for all governed modules. Cascading failure prevention tested against OWASP ASI-08.
🔐
Connector Provenance
SHA-256 content hash + Ed25519 signature verification at skill pack install time. Unsigned community packages warn; tampered manifests are blocked.
🌐
External Agent Control
Remote agent registration, heartbeat, tenant-scoped dispatch, allowed-intent enforcement, and kill-switch. Every agent has a cryptographic identity via Ed25519 signing.

Built for Scale. Designed for Security.

A modern, containerized stack with security principles baked into every layer.

Backend

FastAPI
Async REST API with OpenAPI docs
SQLAlchemy 2.0
Async ORM with Alembic migrations
PostgreSQL
Primary data store with row-level security
Redis
Caching, pub/sub, and session state
Python 3.12
Type-safe async throughout

Frontend

Next.js 14
App Router with server components
TypeScript
End-to-end type safety
Tailwind CSS
Utility-first dark-themed UI
Recharts
Security metrics dashboards
ShadCN UI
Accessible component primitives

Governance & Security

Trust Fabric Engine
6-stage pipeline: anomaly → policy → risk → audit → decision
Execution Ring Policy
ring0 blocked → ring3 auto-allow, 4-tier privilege isolation
Ed25519 Inter-Agent Signing
Cryptographic identity for every agent envelope
PyJWT + Rate Limiting
Short-lived tokens, 10 req/min brute-force guard
SRE Engine
Circuit breaker + error budget for all governed modules
Attributable Audit Records
Policy decisions, approvals, and recorded outcomes with actor context

Six Pillars of Governed Security

Enkstein operationalizes zero trust beyond network segmentation — enforcing governance at every layer of the security stack.

🪪
Every component has identity
Agents, capability nodes, workflows, and service accounts are first-class identity principals. Non-human identities are governed alongside human ones.
🔐
Governed actions are authorized
No security action executes without passing policy evaluation, risk scoring, and (when required) human approval via the Trust Fabric pipeline.
👁️
Every runtime is monitored
Behavioral baselines for all capability nodes and agents surface anomalies in real time, before policies are even invoked.
🧾
Every workflow is attributable
Audit records capture the available decision chain — who triggered the action, which policies matched, what risk score was assigned, and the recorded outcome.
🚧
Every risk is containable
Emergency mode provides instant containment actions. Each claw can isolate its scope without requiring full platform access.
⚙️
Every module is governed
Capability areas and control surfaces use shared policy services where wired. The maturity matrix identifies legacy and in-progress paths that have not reached the same assurance level.

Install and Start Locally

Use a native macOS .pkg or Windows setup.exe when that asset is present on the release, or use the portable bundle. The launcher creates unique secrets and starts the backend API, production Next.js frontend, PostgreSQL, and Redis through Docker Desktop.

The launcher tries versioned backend and frontend images first. If either image is unavailable, it builds both from the bundled source; the backend build can take many minutes while Prowler and its dependencies install. The universal macOS app waits for the Cortex and UI to become healthy before loading Enkstein in its native desktop window.

The control plane is self-hosted. Connector credentials are encrypted in the local secret volume and are sent only to the provider endpoints those connectors authenticate against. Prompts leave the device only when you select a cloud, subscription, or browser Brain, subject to the active policy and redaction decision.

Security: Never commit backend/.secrets/ to git. This folder holds your encryption key and is gitignored by default. Each deployment generates its own isolated key on first run.

How to add your credentials →
🐚 bash
# Download a GitHub Release bundle
tar -xzf enkstein-VERSION.tar.gz
cd enkstein-VERSION
./install.sh

# Open the platform
# Dashboard: http://localhost:3000
# API Docs:  http://localhost:8000/docs

# Add your own credentials
# → Go to Connectors → click any connector
# → Enter your API key/token — encrypted at rest
# → Capability Node switches from demo data to your real environment