Buyer review pack · updated 23 August 2026

Understand KrevoPilot before the first security meeting.

Four concise, versioned resources explain what the product does, what the agent can access, what data leaves a cluster and what our published evidence proves.

4 Review-ready resources
14/14 Controlled diagnoses
0 Mutation verbs in the published collector role
01

90-second product walkthrough

See the path from cluster overview to exact application context, evidence-backed investigation, review-first fix and optimization.

Start the walkthrough →
02

Published benchmark

Read the dated scenario corpus, scoring method, exact versions, result and explicit limitations behind the accuracy claim.

Review benchmark evidence →
03

Security architecture one-pager

A printable answer to installation, connectivity, data handling, authentication, tenant access, audit and retention questions.

Download one-page PDF →
04

Agent and RBAC reference

Inspect installed Kubernetes objects, exact resources and verbs, conditional collectors, Secret handling and runtime hardening.

Review agent permissions →
Fast answers

What a platform or security lead usually asks

Full security documentation →

What gets installed?

An in-cluster Deployment, dedicated ServiceAccount, read-only ClusterRole/Binding, connection Secret and optional egress NetworkPolicy.

Can it modify the cluster?

No. The published collection role contains no create, update, patch or delete verbs. Remediation is review-first.

What data leaves the cluster?

Bounded health/state, metrics, selected events, configured manifest summaries and optional limited log evidence.

How are Secrets handled?

Secret values are never transmitted. When manifest collection is enabled, existence, type and key names are summarized so broken references can be diagnosed without exposing values.

How do users authenticate?

Password sign-in and workspace OIDC/SSO are supported. Roles, teams and cluster assignment control access.

Can activity be audited?

Security-sensitive and administrative actions retain actor attribution for workspace audit review.

Claim boundary

The benchmark is a bounded controlled-corpus result—not a universal accuracy guarantee. This package describes implemented technical controls, not a certification or contractual DPA.

Read the full trust report →