Kikimora logo
Privacy Security · Security Code Scanning

Kikimora

Conversational AI security agent that connects 18 tools — AWS, Azure, Cloudflare, GitHub, Qualys and more — into one chat. Triage findings, get the fix drafted, approve every change. EU-hosted inference, permanent free tier for 30 assets.

Active GDPR compliant Free plan Freemium No public API Verified by Guidaio
Overview

What is Kikimora?

Kikimora is an AI security agent that puts an entire security stack behind a single conversation. Built by the Bulgarian company Kikimora io AD, it connects eighteen tools — AWS, Azure, Hetzner, Linode, Cloudflare, FortiGate, GitHub, SonarCloud, Vercel, ServiceNow, Sentry, Supabase, PlanetScale, Qualys WAS, Tenable, Shodan, Wazuh and a locally deployable Network Scanner — and answers questions across all of them at once.

The product has two halves. The Agent is the chat interface: it interprets a request, queries the relevant services in parallel, and synthesises a correlated answer. The Platform is the system of record behind it, with a thirteen-widget dashboard and thirteen modules covering vulnerabilities, risk management, external exposure, infrastructure, endpoints, scans, web applications, manual tests, approved software, integrity monitoring, hardening and auth records. Findings, assets, scores and compliance evidence persist there after the chat ends, each carrying an owner, a status and a time to resolve.

Four capabilities ship built in, with no third-party licence to buy: Qualys WAS web application scanning, Shodan attack-surface intelligence, Wazuh host detection, and a Network Scanner that runs inside internal networks with no VPN or port forwarding. Prioritisation is contextual rather than generic: the Kikimora Score rates every finding from 0 to 100 using CVSS, EPSS threat intelligence, hardening, asset criticality and exposure, while Risk Management ranks CVEs by portfolio impact, so a moderate flaw spread across many hosts can outrank a severe one on a single box.

What distinguishes the tool is how tightly the agent is bounded. Connectors are hand-written and deterministic; there is no code execution, no shell access and no arbitrary HTTP capability. Tool inputs are validated server-side against strict schemas, tools are allow-listed at both service and agent level, and the agent authenticates with the requesting user's own credentials rather than a privileged service account. Every write action waits for explicit approval and lands in an immutable, exportable audit log. Model inference runs on Google Vertex AI pinned to EU data-residency endpoints, with no training on customer data.

Setup requires no agent on your infrastructure: OAuth or an API key, about five minutes for the first integration. A permanent free tier covers thirty assets, unlimited integrations and five million AI credits, with no credit card.

What it does

  • Query your entire security stack in plain English from a single conversation
  • Correlate findings from several providers into one incident with severity and blast radius
  • Have the fix drafted — CLI command, Terraform change or API call — then approve it in one click
  • Rank fixes by portfolio impact with the Kikimora Score and preview the projected risk reduction
  • Discover your external attack surface: domains, hostnames, IPs, open ports, service banners and EPSS scores
  • Produce compliance evidence for SOC 2, ISO 27001, PCI-DSS and NIS2 controls read straight from hosts
  • Run isolated client tenants side by side as an MSSP, switching context in one click
Audience

When to use Kikimora / When not to

A quick filter to help you decide if Kikimora is the right fit.

When to use Kikimora

  • Small security teams with no dedicated specialist, who need to close a knowledge gap rather than hire for it
  • Security engineers losing hours to swivel-chair work across ten consoles: cloud, edge, code, scanners and ITSM
  • MSSPs running many client estates, who need isolated tenants, separate integration keys and monthly per-asset billing
  • Penetration testers who want OWASP-style checklists and manual findings tracked in the same repository as scanner output
  • Organisations under NIS2 or GDPR pressure that require EU data residency for both storage and model inference

When not to use Kikimora

  • Individuals and non-professional users: the platform is declared strictly business-to-business
  • Teams wanting hands-off autonomous remediation, since no write action ever runs without explicit human approval
  • Anyone needing to drive the tool programmatically: there is no public API and no API documentation
  • Buyers who require a contractual SLA, as the vendor commits to no uptime guarantee and targets support replies within 20 business days
  • Procurement processes that need a published price up front, or a third-party certificate rather than a claimed alignment
Get started

How to use Kikimora

A typical end-to-end flow, from setup to results.

  1. Create an account directly from the website — onboarding is self-service, with no manual approval and no credit card
  2. Connect your first integration through OAuth or an API key, choosing read-only access wherever the provider allows it
  3. Add the remaining tools in your stack: cloud providers, edge and firewall, code repositories, scanners and ITSM
  4. Deploy the built-in Network Scanner locally if you need visibility inside internal networks, with no VPN or port forwarding
  5. Ask a question in plain English — the agent picks the relevant tools, queries them in parallel and returns a correlated answer
  6. Review the ranked findings, open the Kikimora Score breakdown to see which of the five factors drove the score
  7. Select the fixes you intend to ship and read the projected risk reduction before anyone patches
  8. Approve any write action explicitly: the agent shows the exact command, change or API call before it runs
  9. Schedule recurring sweeps and audits so they run overnight and arrive as a digest
  10. Track every finding to closure in the platform, and export the audit trail as compliance evidence
Quick read

Pros & Cons

Pros

  • EU data sovereignty documented endpoint by endpoint: inference, application data and observability traces all stay in the EU
  • The agent is bounded by construction, not by prompt: no code execution, no arbitrary HTTP, allow-listed tools, server-side schema validation
  • The AI never holds more privilege than the user who asked, and every write action waits for explicit approval
  • Four scanners included with no third-party licence to buy, which is unusual at this level of the market
  • A genuinely usable permanent free tier: 30 assets, unlimited integrations, 5 million AI credits, no credit card
  • Nothing to install on your infrastructure — OAuth or API key, first integration in about five minutes
  • Unusual candour about compliance: the security whitepaper states outright that it is not making a certification claim

Cons

  • No paid price is published anywhere, so the tool cannot be budgeted without a sales conversation
  • No third-party certification: ISO 27001 is described as aligned and SOC 2 as ready, with no accredited body or certificate number
  • No public API and no API documentation, ruling out programmatic integration of the tool itself
  • No SLA, no uptime commitment, and support responses targeted only within 20 business days
  • The terms contradict the security whitepaper on hosting, claiming no third-party cloud providers are used while the whitepaper names two
  • The promise that data is never used to train AI models sits against a clause permitting machine learning training on anonymised data
  • English-only interface, no mobile application, and a young, small publisher incorporated in August 2023
Pricing

Pricing & Plans

A permanent free plan is available, covering up to 30 assets, unlimited integrations and 5 million AI credits, with no credit card required. Beyond that tier, no paid price is published: the vendor states only that paid plans are billed monthly on the number of assets actually assessed, with no annual lock-in, and that pricing for MSSP client volumes is agreed when multi-tenancy is activated. Usage is metered through a token system, with free tokens granted on registration and additional tokens available for purchase; tokens are non-refundable, non-transferable and may expire. Payments are handled by an integrated provider. As no paid amount is public, no starting price, currency or billing unit is recorded.

Plan 1
  • Free — up to 30 assets
  • unlimited integrations
  • 5 million AI credits
  • no credit card
  • access to the core capabilities
Plan 3
  • MSSP multi-tenant — isolated tenant per client with separate integration keys
  • billed monthly per tenant
  • pricing agreed at activation
Special offers — Permanent free tier: 30 assets, unlimited integrations and 5 million AI credits, with no credit card and no commitment · Four capabilities included at no extra licence cost — Qualys WAS scanning, Shodan intelligence, Wazuh detection and the Network Scanner · Free 30-minute live external attack surface review, with the findings kept by the prospect regardless of the outcome · No annual lock-in per tenant for MSSPs, billed month by month on assessed assets
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Kikimora handles your data.

GDPR overview

GDPR implementation is concrete and documented. The controller is named in full: Kikimora io AD, UIC 207472703, Sofia, Bulgaria, with the Bulgarian Commission for Personal Data Protection as lead supervisory authority. The privacy notice, last updated 5 June 2026, sets out legal bases in a purpose-by-purpose table and lists statutory rights — access, erasure, rectification, portability, restriction, withdrawal of consent and complaint — plus rights to object to direct marketing and to legitimate-interest processing. Rights are exercised at support@kikimora.io. Transfers rely on adequacy decisions or Standard Contractual Clauses. The vendor states plainly that it is GDPR compliant, and its security whitepaper maps controls to GDPR, NIS2 and the EU AI Act. No Article 27 representative is designated, which is expected since the company is established inside the EU, and no Data Protection Officer is named.

Who owns the data?

Customers keep ownership of their data. The vendor states that you retain full ownership and that deletion is available on request; the terms confirm that when an account is deleted, or on explicit request, personal and organisational identifiers are erased or anonymised from scan data. Intellectual property in the platform itself stays with Kikimora io AD, which is a separate matter from customer content. Two caveats deserve attention: the terms reserve the vendor's continued access to scan reports, user information and vulnerability data, and allow it to review that data for quality assurance, debugging, analytics and feature development. Integration credentials are AES-256 encrypted and never exposed to the model.

Reuse rights

Users may use their own findings freely: reports can be shared with other users on the platform, exported, and audit entries are described as exportable for compliance, with no permission step required from the vendor. What the vendor does with that data is more layered. Personal data is processed to deliver and improve the service, to communicate and market, to prevent fraud and to meet legal obligations, on the bases of contract, legitimate interests, consent and legal obligation. Model inference runs on Google Vertex AI with Google and Anthropic models, served only from EU endpoints, and the vendor states that customer data is never used to train AI models and that inference data is subject to zero retention. That commitment sits uneasily beside a clause in the terms allowing anonymised data to be kept indefinitely and used for machine learning model training, benchmarking and trend analysis. Website analytics use Google Analytics 4 behind Consent Mode v2, with nothing set before consent and no resale.

Data retention & training

Retention summary
No retention period is expressed in days or months anywhere, which is the most notable point. At the model layer, retention is zero: inference data is processed in memory to produce the answer and is not stored afterwards. Elsewhere, personal data is kept only as long as necessary for the purpose, judged against the volume and sensitivity of the data, the risk of harm and legal obligations, and partly against user settings such as chat history and archived conversations. Deleting an account, or asking explicitly, triggers erasure or anonymisation of personal and organisational identifiers in scan data. Anonymised data, however, may be retained indefinitely for trend analysis, benchmarking, usage statistics and machine learning training.
Trains on customer data
No
GDPR contact

Hosting summary

All processing is described as taking place in the European Union. Model inference runs on Google Cloud Vertex AI pinned to the EU multi-region, and specifically through Google's regional data-residency endpoint class, so a misconfiguration produces an error rather than a cross-border request. Application state — accounts, conversations, agent configuration and integration credentials — sits in a MongoDB cluster deployed in an EU region only, with no replication or backup outside the EU. Execution traces are stored in an EU region as well. Data is encrypted with TLS in transit and at rest in the database, with an additional AES-256 application layer protecting integration credentials. The platform is containerised and self-hosted, and a single-tenant deployment in a customer-controlled VPC or on-premises environment is offered. One inconsistency should be noted: the terms state the platform runs on the company's own infrastructure in Bulgaria with no third-party cloud providers used for hosting, while the whitepaper names two EU-pinned third-party services.

Hosting countries
🇧🇬 Bulgaria
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Kikimora.

  • Approval fatigue is the central human risk: a tool that asks you to confirm every write only protects you while you still read what you are confirming
  • Conversational answers feel authoritative, and the vendor itself warns that agent output is statistical and must be independently validated — do not treat a fluent summary as a verified finding
  • Relying on the agent to interpret findings can erode a team's own diagnostic skill, which is precisely the expertise you need on the day the tool is wrong or unavailable
  • The publisher reserves continued access to your scan reports and vulnerability data for quality assurance and analytics, and may keep anonymised data indefinitely for model training
  • Claimed alignment with ISO 27001 and SOC 2 is not certification: do not let it stand in for your own vendor assessment, and note the site says so itself
  • Connecting cloud, code and firewall credentials concentrates significant reach in one platform, so the account itself becomes a high-value target deserving strong authentication and role discipline
  • Scanning production systems can degrade performance, and you remain responsible for authorisation to scan any asset and for scheduling scans safely
Setup

Setup & Integrations

Technical difficulty

Low. Account creation is self-service with no manual approval, and nothing is installed on your infrastructure — integrations are connected through OAuth or an API key, read-only wherever the provider allows it, with the first one typically live in under five minutes. The real effort is administrative rather than technical: gathering credentials and permissions for each service you want to connect. Teams needing visibility inside internal networks deploy the built-in Network Scanner locally, which the vendor says requires no VPN and no port forwarding. MSSPs can stand up a new client tenant in hours.

Deployment

Web app

Integrations

AWS Azure Hetzner Linode Cloudflare FortiGate GitHub SonarCloud Vercel ServiceNow Sentry Supabase PlanetScale Qualys WAS Tenable Shodan Network Scanner Wazuh

Supported languages

English
Company

Behind Kikimora

Company name
Kikimora io AD
Founded
01/08/2023
Country of origin
🇧🇬 Bulgaria
Headquarters
Bulgaria, Sofia 1612, Hipodruma Building 107A, Ap.1
UBO
Krasimir Rosenov Kotsev
UBO country
🇧🇬 Bulgaria
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Fundraising

Venture-backed: the Bulgarian commercial register records Impetus Capital (UIC 203592737) and Vitosha Venture Partners OOD (UIC 205998206) on the board of directors alongside founder Krasimir Rosenov Kotsev, entered on 5 August 2024
The share capital is split into ordinary shares plus Class A preferred shares carrying veto rights and a board nomination right, and Class B preferred shares carrying a guaranteed liquidation preference — a structure typical of an investor round
Registered share capital stands at EUR 36,787.08, of which EUR 36,772.11 is paid up
Trade press reported an investment of EUR 200,000 by Impetus Capital's ImPulse I fund; the amount could not be confirmed against a primary source

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Kikimora.

T TorqT TinesD Dropzone AIS Swimlane
FAQ

Frequently asked questions

Do I need security expertise to use Kikimora?
No. The conversational interface guides you through tasks in plain English. Teams with deep expertise use it to move faster, while teams without a dedicated specialist use it to close the knowledge gap.
How long does setup take?
Most teams connect their first integration in under five minutes using OAuth or an API key. There is no agent to install on your servers and no infrastructure change required.
Which tools does it integrate with?
Eighteen in total: AWS, Azure, Hetzner, Linode, Cloudflare, FortiGate, GitHub, SonarCloud, Vercel, ServiceNow, Sentry, Supabase, PlanetScale, Tenable, and four built-in capabilities — Qualys WAS, Shodan, Wazuh and a local Network Scanner — that need no separate licence.
Can the AI change my infrastructure on its own?
No. Every write action is proposed first and executed only after your explicit approval. The tool fleet contains no destructive operations, and the agent acts with your own credentials rather than a privileged service account.
Where is my data processed and stored?
In the European Union. Model inference runs on Google Vertex AI pinned to EU data-residency endpoints, application data sits in an EU-only MongoDB cluster, and execution traces are stored in the EU. Note that the terms and the security whitepaper describe the hosting arrangement differently.
Is my data used to train AI models?
The vendor states that customer data is never used to train AI models and that inference data is subject to zero retention. Separately, the terms allow anonymised data to be retained indefinitely and used for machine learning training and benchmarking.
Is Kikimora certified ISO 27001 or SOC 2?
No. It describes itself as ISO 27001 aligned and SOC 2 ready, and its security whitepaper states explicitly that this describes architectural alignment and does not constitute a certification claim.
What counts as an asset, and what does it cost?
An asset is a host, domain, IP address, web application or endpoint in your inventory, and it is the billing unit. The free tier covers 30 assets; paid plans bill monthly on assessed assets, but no paid amount is published.
Is there an API?
No public API and no API documentation could be found. The documentation site covers the product modules for end users only, and the integrations described are third-party APIs that Kikimora consumes.
Can penetration testers use it?
Yes. Manual tests provide OWASP-style checklists for web, Android and iOS, with each check recorded as Pass, Failed or N/A. Manual findings, proof of concept included, land in the same repository as scanner findings.
Conclusion

Should you pick Kikimora?

Kikimora answers a real and unglamorous problem: security teams spend their days moving between consoles that do not speak to each other. Putting eighteen of those tools behind one conversation, with a persistent platform of thirteen modules underneath, is a credible response rather than a chatbot bolted onto a dashboard.

The engineering choices are the strongest part of the offer. The agent cannot execute code, reach arbitrary URLs, or compose operations nobody implemented; it holds exactly the privileges of the person asking; and every write waits for a human click before it runs. Those are structural limits, not promises, and they matter more than any feature list when the tool is pointed at production infrastructure. The EU residency story is equally precise, down to naming the Vertex AI endpoint class used for inference.

The reservations are commercial rather than technical. No paid price is published anywhere, so budgeting means talking to sales. There is no third-party certification — aligned and ready are not certified, and to its credit the vendor says so itself. There is no public API, no SLA, and liability is capped at EUR 1,000. Two internal contradictions also deserve a buyer's attention: the terms deny using any third-party cloud provider while the whitepaper names two, and the flat claim that data never trains AI models sits beside a clause allowing training on anonymised data.

This is a young, small publisher, incorporated in August 2023 and backed by two Bulgarian funds. The permanent free tier — thirty assets, unlimited integrations, no card — makes that risk cheap to evaluate. Teams drowning in consoles, and MSSPs needing month-by-month tenants, should try it before committing.