
Kikimora
Conversational AI security agent that connects 18 tools — AWS, Azure, Cloudflare, GitHub, Qualys and more — into one chat. Triage findings, get the fix drafted, approve every change. EU-hosted inference, permanent free tier for 30 assets.
What is Kikimora?
Kikimora is an AI security agent that puts an entire security stack behind a single conversation. Built by the Bulgarian company Kikimora io AD, it connects eighteen tools — AWS, Azure, Hetzner, Linode, Cloudflare, FortiGate, GitHub, SonarCloud, Vercel, ServiceNow, Sentry, Supabase, PlanetScale, Qualys WAS, Tenable, Shodan, Wazuh and a locally deployable Network Scanner — and answers questions across all of them at once.
The product has two halves. The Agent is the chat interface: it interprets a request, queries the relevant services in parallel, and synthesises a correlated answer. The Platform is the system of record behind it, with a thirteen-widget dashboard and thirteen modules covering vulnerabilities, risk management, external exposure, infrastructure, endpoints, scans, web applications, manual tests, approved software, integrity monitoring, hardening and auth records. Findings, assets, scores and compliance evidence persist there after the chat ends, each carrying an owner, a status and a time to resolve.
Four capabilities ship built in, with no third-party licence to buy: Qualys WAS web application scanning, Shodan attack-surface intelligence, Wazuh host detection, and a Network Scanner that runs inside internal networks with no VPN or port forwarding. Prioritisation is contextual rather than generic: the Kikimora Score rates every finding from 0 to 100 using CVSS, EPSS threat intelligence, hardening, asset criticality and exposure, while Risk Management ranks CVEs by portfolio impact, so a moderate flaw spread across many hosts can outrank a severe one on a single box.
What distinguishes the tool is how tightly the agent is bounded. Connectors are hand-written and deterministic; there is no code execution, no shell access and no arbitrary HTTP capability. Tool inputs are validated server-side against strict schemas, tools are allow-listed at both service and agent level, and the agent authenticates with the requesting user's own credentials rather than a privileged service account. Every write action waits for explicit approval and lands in an immutable, exportable audit log. Model inference runs on Google Vertex AI pinned to EU data-residency endpoints, with no training on customer data.
Setup requires no agent on your infrastructure: OAuth or an API key, about five minutes for the first integration. A permanent free tier covers thirty assets, unlimited integrations and five million AI credits, with no credit card.
What it does
- Query your entire security stack in plain English from a single conversation
- Correlate findings from several providers into one incident with severity and blast radius
- Have the fix drafted — CLI command, Terraform change or API call — then approve it in one click
- Rank fixes by portfolio impact with the Kikimora Score and preview the projected risk reduction
- Discover your external attack surface: domains, hostnames, IPs, open ports, service banners and EPSS scores
- Produce compliance evidence for SOC 2, ISO 27001, PCI-DSS and NIS2 controls read straight from hosts
- Run isolated client tenants side by side as an MSSP, switching context in one click
When to use Kikimora / When not to
A quick filter to help you decide if Kikimora is the right fit.
When to use Kikimora
- Small security teams with no dedicated specialist, who need to close a knowledge gap rather than hire for it
- Security engineers losing hours to swivel-chair work across ten consoles: cloud, edge, code, scanners and ITSM
- MSSPs running many client estates, who need isolated tenants, separate integration keys and monthly per-asset billing
- Penetration testers who want OWASP-style checklists and manual findings tracked in the same repository as scanner output
- Organisations under NIS2 or GDPR pressure that require EU data residency for both storage and model inference
When not to use Kikimora
- Individuals and non-professional users: the platform is declared strictly business-to-business
- Teams wanting hands-off autonomous remediation, since no write action ever runs without explicit human approval
- Anyone needing to drive the tool programmatically: there is no public API and no API documentation
- Buyers who require a contractual SLA, as the vendor commits to no uptime guarantee and targets support replies within 20 business days
- Procurement processes that need a published price up front, or a third-party certificate rather than a claimed alignment
How to use Kikimora
A typical end-to-end flow, from setup to results.
- Create an account directly from the website — onboarding is self-service, with no manual approval and no credit card
- Connect your first integration through OAuth or an API key, choosing read-only access wherever the provider allows it
- Add the remaining tools in your stack: cloud providers, edge and firewall, code repositories, scanners and ITSM
- Deploy the built-in Network Scanner locally if you need visibility inside internal networks, with no VPN or port forwarding
- Ask a question in plain English — the agent picks the relevant tools, queries them in parallel and returns a correlated answer
- Review the ranked findings, open the Kikimora Score breakdown to see which of the five factors drove the score
- Select the fixes you intend to ship and read the projected risk reduction before anyone patches
- Approve any write action explicitly: the agent shows the exact command, change or API call before it runs
- Schedule recurring sweeps and audits so they run overnight and arrive as a digest
- Track every finding to closure in the platform, and export the audit trail as compliance evidence
Pros & Cons
Pros
- EU data sovereignty documented endpoint by endpoint: inference, application data and observability traces all stay in the EU
- The agent is bounded by construction, not by prompt: no code execution, no arbitrary HTTP, allow-listed tools, server-side schema validation
- The AI never holds more privilege than the user who asked, and every write action waits for explicit approval
- Four scanners included with no third-party licence to buy, which is unusual at this level of the market
- A genuinely usable permanent free tier: 30 assets, unlimited integrations, 5 million AI credits, no credit card
- Nothing to install on your infrastructure — OAuth or API key, first integration in about five minutes
- Unusual candour about compliance: the security whitepaper states outright that it is not making a certification claim
Cons
- No paid price is published anywhere, so the tool cannot be budgeted without a sales conversation
- No third-party certification: ISO 27001 is described as aligned and SOC 2 as ready, with no accredited body or certificate number
- No public API and no API documentation, ruling out programmatic integration of the tool itself
- No SLA, no uptime commitment, and support responses targeted only within 20 business days
- The terms contradict the security whitepaper on hosting, claiming no third-party cloud providers are used while the whitepaper names two
- The promise that data is never used to train AI models sits against a clause permitting machine learning training on anonymised data
- English-only interface, no mobile application, and a young, small publisher incorporated in August 2023
Pricing & Plans
A permanent free plan is available, covering up to 30 assets, unlimited integrations and 5 million AI credits, with no credit card required. Beyond that tier, no paid price is published: the vendor states only that paid plans are billed monthly on the number of assets actually assessed, with no annual lock-in, and that pricing for MSSP client volumes is agreed when multi-tenancy is activated. Usage is metered through a token system, with free tokens granted on registration and additional tokens available for purchase; tokens are non-refundable, non-transferable and may expire. Payments are handled by an integrated provider. As no paid amount is public, no starting price, currency or billing unit is recorded.
- Free — up to 30 assets
- unlimited integrations
- 5 million AI credits
- no credit card
- access to the core capabilities
- Paid (unnamed) — billed monthly on assessed assets
- no annual lock-in
- amount not published
- MSSP multi-tenant — isolated tenant per client with separate integration keys
- billed monthly per tenant
- pricing agreed at activation
Data, GDPR & hosting
A consolidated view of how Kikimora handles your data.
GDPR overview
GDPR implementation is concrete and documented. The controller is named in full: Kikimora io AD, UIC 207472703, Sofia, Bulgaria, with the Bulgarian Commission for Personal Data Protection as lead supervisory authority. The privacy notice, last updated 5 June 2026, sets out legal bases in a purpose-by-purpose table and lists statutory rights — access, erasure, rectification, portability, restriction, withdrawal of consent and complaint — plus rights to object to direct marketing and to legitimate-interest processing. Rights are exercised at support@kikimora.io. Transfers rely on adequacy decisions or Standard Contractual Clauses. The vendor states plainly that it is GDPR compliant, and its security whitepaper maps controls to GDPR, NIS2 and the EU AI Act. No Article 27 representative is designated, which is expected since the company is established inside the EU, and no Data Protection Officer is named.
Who owns the data?
Customers keep ownership of their data. The vendor states that you retain full ownership and that deletion is available on request; the terms confirm that when an account is deleted, or on explicit request, personal and organisational identifiers are erased or anonymised from scan data. Intellectual property in the platform itself stays with Kikimora io AD, which is a separate matter from customer content. Two caveats deserve attention: the terms reserve the vendor's continued access to scan reports, user information and vulnerability data, and allow it to review that data for quality assurance, debugging, analytics and feature development. Integration credentials are AES-256 encrypted and never exposed to the model.
Reuse rights
Users may use their own findings freely: reports can be shared with other users on the platform, exported, and audit entries are described as exportable for compliance, with no permission step required from the vendor. What the vendor does with that data is more layered. Personal data is processed to deliver and improve the service, to communicate and market, to prevent fraud and to meet legal obligations, on the bases of contract, legitimate interests, consent and legal obligation. Model inference runs on Google Vertex AI with Google and Anthropic models, served only from EU endpoints, and the vendor states that customer data is never used to train AI models and that inference data is subject to zero retention. That commitment sits uneasily beside a clause in the terms allowing anonymised data to be kept indefinitely and used for machine learning model training, benchmarking and trend analysis. Website analytics use Google Analytics 4 behind Consent Mode v2, with nothing set before consent and no resale.
Data retention & training
Hosting summary
All processing is described as taking place in the European Union. Model inference runs on Google Cloud Vertex AI pinned to the EU multi-region, and specifically through Google's regional data-residency endpoint class, so a misconfiguration produces an error rather than a cross-border request. Application state — accounts, conversations, agent configuration and integration credentials — sits in a MongoDB cluster deployed in an EU region only, with no replication or backup outside the EU. Execution traces are stored in an EU region as well. Data is encrypted with TLS in transit and at rest in the database, with an additional AES-256 application layer protecting integration credentials. The platform is containerised and self-hosted, and a single-tenant deployment in a customer-controlled VPC or on-premises environment is offered. One inconsistency should be noted: the terms state the platform runs on the company's own infrastructure in Bulgaria with no third-party cloud providers used for hosting, while the whitepaper names two EU-pinned third-party services.
Things to keep in mind
Risks and trade-offs to weigh before adopting Kikimora.
- Approval fatigue is the central human risk: a tool that asks you to confirm every write only protects you while you still read what you are confirming
- Conversational answers feel authoritative, and the vendor itself warns that agent output is statistical and must be independently validated — do not treat a fluent summary as a verified finding
- Relying on the agent to interpret findings can erode a team's own diagnostic skill, which is precisely the expertise you need on the day the tool is wrong or unavailable
- The publisher reserves continued access to your scan reports and vulnerability data for quality assurance and analytics, and may keep anonymised data indefinitely for model training
- Claimed alignment with ISO 27001 and SOC 2 is not certification: do not let it stand in for your own vendor assessment, and note the site says so itself
- Connecting cloud, code and firewall credentials concentrates significant reach in one platform, so the account itself becomes a high-value target deserving strong authentication and role discipline
- Scanning production systems can degrade performance, and you remain responsible for authorisation to scan any asset and for scheduling scans safely
Setup & Integrations
Technical difficulty
Low. Account creation is self-service with no manual approval, and nothing is installed on your infrastructure — integrations are connected through OAuth or an API key, read-only wherever the provider allows it, with the first one typically live in under five minutes. The real effort is administrative rather than technical: gathering credentials and permissions for each service you want to connect. Teams needing visibility inside internal networks deploy the built-in Network Scanner locally, which the vendor says requires no VPN and no port forwarding. MSSPs can stand up a new client tenant in hours.
Deployment
Integrations
Supported languages
Behind Kikimora
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Kikimora.
Frequently asked questions
Do I need security expertise to use Kikimora?
How long does setup take?
Which tools does it integrate with?
Can the AI change my infrastructure on its own?
Where is my data processed and stored?
Is my data used to train AI models?
Is Kikimora certified ISO 27001 or SOC 2?
What counts as an asset, and what does it cost?
Is there an API?
Can penetration testers use it?
Should you pick Kikimora?
Kikimora answers a real and unglamorous problem: security teams spend their days moving between consoles that do not speak to each other. Putting eighteen of those tools behind one conversation, with a persistent platform of thirteen modules underneath, is a credible response rather than a chatbot bolted onto a dashboard.
The engineering choices are the strongest part of the offer. The agent cannot execute code, reach arbitrary URLs, or compose operations nobody implemented; it holds exactly the privileges of the person asking; and every write waits for a human click before it runs. Those are structural limits, not promises, and they matter more than any feature list when the tool is pointed at production infrastructure. The EU residency story is equally precise, down to naming the Vertex AI endpoint class used for inference.
The reservations are commercial rather than technical. No paid price is published anywhere, so budgeting means talking to sales. There is no third-party certification — aligned and ready are not certified, and to its credit the vendor says so itself. There is no public API, no SLA, and liability is capped at EUR 1,000. Two internal contradictions also deserve a buyer's attention: the terms deny using any third-party cloud provider while the whitepaper names two, and the flat claim that data never trains AI models sits beside a clause allowing training on anonymised data.
This is a young, small publisher, incorporated in August 2023 and backed by two Bulgarian funds. The permanent free tier — thirty assets, unlimited integrations, no card — makes that risk cheap to evaluate. Teams drowning in consoles, and MSSPs needing month-by-month tenants, should try it before committing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.