Platform

Your cloud or ours, separated per client

Three ways to run the platform: a Kadre-hosted shared environment, Kadre-hosted dedicated infrastructure, or your own cloud account. In every model, agents read only what they have been granted, connections are least-privilege and revocable, and a full record is kept of what happened.

Three ways to deploy

All three are in use today. Same platform, same records, same approvals in each. The choice depends on your data rules and who you want holding the keys.

In use

Kadre-hosted, shared environment

The standard model. Kadre runs the platform. Your data, keys, records, and memory are logically separated from every other client’s.

  • Fastest to start
  • Least-privilege connections you grant and can revoke
  • Kadre owns monitoring, exceptions, and updates
In use

Kadre-hosted, dedicated

Your own instance on infrastructure Kadre runs for you alone. For data rules that require no shared runtime or storage.

  • Dedicated runtime and storage
  • Same platform, records, and approvals
  • Kadre operates it; you hold the keys you choose to
In use

Inside your own cloud account

The whole system runs in an account you own. One client runs this way today. Calls to the model provider leave that account; nothing else does.

  • Your account, your keys, your retention rules
  • Kadre operates through access you control
  • Same platform, same records, same approvals

Separated per client

In every deployment model, each agent reads only the data it has been granted, and nothing crosses between clients. What one company's agent learns stays with that company.

Separation by designNo shared records, no shared memory, and no shared learning across clients. Dedicated or own-cloud models add a separate runtime.
Grants per agentAn agent connects to the systems its workflow needs, with the scopes that workflow needs, and nothing more.
Revocable by youEvery connection is one you granted and can remove.

What is recorded

The record is the product. It is how your team approves with context, how Kadre operates, and how the weekly packet is built.

Every caseWhat the agent read, what it proposed, who decided, and what followed.
Every decisionReviewer, edit, reason, and time. Attributable to a person.
Every rule versionWhich policy a run used, so a result can be read against the rule that produced it.
Every postingThe reference in the system of record and the receipt sent.

Security controls

The controls in place on every deployment, stated plainly.

In transitTLS for every connection between the platform, your systems, and the people using it.
Credentials and tokensEncrypted at rest. Secrets are managed, not stored in configuration.
AccessLeast privilege. Each connection to a system of record carries only the scopes the workflow needs, is visible in your portal, and can be revoked in a click.
SeparationLogical separation of each client's data, keys, records, and memory in the shared environment. Dedicated infrastructure or your own cloud account when your rules require it. Nothing crosses between clients in any model.
Versioned and reversibleAgent skills, prompts, and integrations release like software, with a version history and rollback.
ContinuityDocumented data flow and retention, incident procedure, rollback procedure, and what happens if Kadre is unavailable.

Hard operating limits

Engineered in, not written in a policy document. An agent cannot exceed them, and you set them.

Spend capsA ceiling per workflow and per month. The agent stops before the budget does.
Volume and rate limitsHow many drafts, sends, or calls per hour and per day. Set per workflow, enforced by the platform.
Call duration capsFor voice workflows, a hard limit per call and a handoff rule when it is reached.
Consent and suppression firstDo-not-contact and suppression lists are checked before any outreach is drafted, not after.
Named owner for every exceptionEvery workflow and every exception has a person attached. Agents brief, people decide on price, terms, scope, and credit.

Regulated industries. Where it applies, the workflow carries the rule: state-level shipping and labeling checks, consent-based voice outreach, and a compliance review step before anything leaves.

What leaves the account

One thing does, and we say so.

Model callsPrompts and the records they include go to the model provider to produce a draft or an answer. This is the one call that leaves the account.
Nothing elseYour records do not leave your instance for training, sharing, or any other purpose.
Your choice of providerThe model provider is agreed with you at deployment, with its data terms in writing.

Questions on data handling are answered in writing before deployment, including provider terms, retention, and what your team can export at any time.

Talk through deployment for your environment

Bring your data rules. We will show which deployment fits, what connects, and what is recorded.

See how we work