Trust is a configuration.

Not a promise. Widen agent authority only as the track record earns it.

SECURITY POSTURE

Trust is a configuration, not a promise.

0 creds in promptsServer-side OAuth. Credentials never touch model context.
RBAC-scoped memoryAgents see only their authorized silos.
Isolated sandboxesDisposable environments. No residue on your machine.
Read-only by defaultNo merges, no pushes, no deletes — until the track record earns it.
EVERY RUN ENDS IN GIT TRUTH

Agents make claims. Kiwi Code checks them.

Agent narrative is untrusted input. Every run ends in a handoff — branch, SHA, PR — reconciled against the worktree, not the model’s word.

CLAIM
Structured handoffs, every run

What changed, where it landed, what was explicitly not done.

TRUTH
Read from the repo, never the model

HEAD, dirty state, PR status — read mechanically. Agents never grade their own homework.

RECORD
Confidence with a track record

Stated confidence vs. how that band actually held up. Recomputed from merge outcomes, not vibes.

Run handoff — verified
final branch30F11-Recovered-Web-Invite-Convergence
final commit8f506b1eee71fadd…
pull request#14 · opened
worktreeclean · ahead 0 · behind 0
claims vs repomatch ✓
scope1 file · intended change only
No merge. No deploy. No scope widening.
stated 88% · this agent's 85–90% band holds 91% across 240 logged decisions
EARNED AUTHORITY

Agents don't get trust. They accumulate it.

Authority widens one rung at a time, per agent, per repo — and every rung is a setting your admins control, not a default we chose for you.

Observe

Read-only. The agent maps the codebase, builds memory, proposes nothing.

Suggest

Diffs and plans for human review. Nothing lands without a person saying so.

Write in lane

Commits to its own branch only. The lane's git truth is reconciled every run.

Merge with gates

PRs that pass tests, checks, and your gate policy. Deploy stays human unless you flip it.

AUDIT SURFACE

Everything is attributable.

Decision traces

Why the agent chose what it chose — recorded at decision time, not reconstructed after.

Structured handoffs

Every run ends with what changed, where it landed (branch · SHA · PR), and what was explicitly not done.

Run history

Every session pinned to its run id and lane — replayable, reviewable, exportable.

Do credentials ever enter model context?

No. OAuth is fully server-side — tokens live in the connector vault and API calls are made on the agent's behalf. Prompts contain intent, never secrets.

Can an agent merge to main?

Not by default. Agents start read-only and earn write access one rung at a time; merges require your gate policy to pass, and deploys stay human unless you decide otherwise.

What does bring-your-own-model mean for my code?

Kiwi’s default model is included in your plan. If you bring your own keys (OpenAI, Anthropic, and more), model traffic goes to your provider under the data agreement you already trust — Kiwi Code only orchestrates the run.

Where does execution happen?

In isolated, disposable sandboxes — created per run, destroyed after, no residue on your machine and no cross-run contamination.

Stop feeding the context window.
Start shipping verified work.

Kiwi Code is onboarding enterprise teams now.

Contact Us
or ask us anything — abhishek@meetkiwi.co