AI Agent Platform for Production Applications - Kodeus
Platform

Everything under the agent, so you can build what is above it

An agent in a product needs more than a model loop. It needs a place to run that survives restarts, an identity per user, credentials that never cross users, memory that stays affordable, policy that can refuse, and a record that holds up later. Kodeus is those parts, already running, on your infrastructure or ours.

Read the docsSee how Warren uses it
Your applicationThe product your users pay for. You build this.
Where it runsLocal · Your cloud · Kodeus Cloud · Airgapped. Models are yours or ours.
Components{{ s.label }}
Execution

A runtime that keeps working when things go wrong

Agents on Kodeus run as long lived, isolated processes. Work resumes after a restart. Failures recover. Turns are scheduled per user, so one busy user cannot stall everyone else. Background routines, retries and scheduled runs are part of the runtime, not something you bolt on.

runtime log · restartlive
02:14:07runtime SIGTERM received · draining 3 active turns
02:14:07runtime checkpoint saved · user_4821 · turn 88 · step 4/7
02:14:09runtime restarted · pid 2214
02:14:09runtime resumed 3 turns from checkpoint · 0 lost
02:14:10sched nightly-digest · user_0977 · queued · share 1/3
02:14:31retry crm.lookup failed 2x · backoff 8s · recovered

Survives restarts

Long running work picks up where it stopped. State needed to continue is persisted, not held in a process.

Per-user concurrency

Each user gets a bounded share. A runaway session is contained to the person who started it.

Background work

Scheduled and event triggered runs, with the same policy and traces as an interactive turn.

Identity

Every user is their own tenant

Identity on Kodeus is derived from a verified credential, never from the request body. Each user’s connected accounts live in their own encrypted store, and one user’s session cannot reach another’s. This is the part that breaks first when a product goes from one user to two, and it is the part we test hardest.

credential stores · per userlive
usertenantvaultstoresrotated
user_4821acme-westvlt_9f2a…32d ago
user_0977acme-westvlt_c71d…36h ago
user_1130northwindvlt_02be…219d ago
probeuser_0977 → read vlt_9f2a… denied · cross-tenant · logged
suiteisolation 6/6 pass · AES-256-GCM · release 0.9.4

Per-user identity and tenancy

Orgs, users, databases and secrets are separated at the runtime, not in application code.

Three credential stores

Encrypted per user with AES-256-GCM. Key issuance, rotation and revocation are runtime operations.

Tested, not assumed

A six part adversarial isolation suite runs against every release. Ask for the report.

Memory

Memory that does not cost more every week

Short term and long term memory per user, with context compaction and eviction, so an agent that has been running for six months does not carry six months of context into every turn. Knowledge is stored durably and scoped to the user or the organisation that owns it.

Context per turn, month 1 to 6without compactionKodeus
m1m2m3m4m5m6

Compaction and eviction keep the per-turn context flat, so cost per turn in month six looks like month one.

Control

Policy that can say no

45 guardrails across six policy families, applied at five checkpoints in every turn. Before the turn, after planning, before any tool call, after the tool call, and before the reply. A rule can monitor, redact, block, escalate or hold the action for a named person. If a rule cannot be evaluated the action does not happen. Spend limits and loop detection are enforced here too, because a prompt cannot enforce a budget.

One turn · five checkpoints
{{ c.label }}
tool call · refunds.create
verdict spend.cap · $640 over the $500 per-turn cap
action hold · waiting for m.chen · tool did not run
fallbackno verdict means no action

Fail closed

No verdict means no action. The turn goes to a person.

Human approval

Name the actions that wait. The record shows who approved, when, and what they changed.

Spend and loops

Caps per agent and per user. An agent retrying a failing tool overnight is stopped, not billed.

Evidence

A record you can hand to someone

Every turn produces an OpenTelemetry trace with the rule verdicts, latency and cost of each call. Approval records carry the approver and the time. Execution history is retrievable later, which is the difference between “the agent said it did this” and “here is what it did”.

trace · turn_88live
span turn_88 · support-agent · user_4821
step 3 tool refunds.create · 412ms · $0.0009
verdict claims.no_unverified_guarantee pass · spend.cap pass
step 4 model claude-sonnet · 1,912 tok · cache 61% · 1.1s
approvalm.chen · 14:02:11 · draft → edited (1 line)
export otel://collector.acme · retained 400d

Traces

OpenTelemetry, with rule verdicts per step, per-call latency, token and cache usage.

Approval records

Approver, time, original draft and edited version.

Behaviour as tests

A correct run is saved and replayed after a prompt or model change, so drift shows up before users see it.

Intelligence

Any model, swapped per agent

Models are chosen per agent and changed in a line of config. OpenAI, DeepSeek and Claude run today. Bring your own keys and pay the provider directly, or let Kodeus route. Any MCP server can be attached, and an agent can be exposed as an MCP server itself or talk to other agents over agent to agent transports.

one line to change the modellive
# kodeus.yaml
model:
provider: openai → anthropic
name: gpt-5 → claude-sonnet-4
keys: own # pay the provider directly
mcp:
- github
- postgres
expose:
as: mcp_server

The model should be replaceable. The operating layer should not be.

Where it runs

Same runtime in all four

Local

Runs on your laptop against the same runtime and the same policies, with no account needed.

Your cloud

Inside your VPC on AWS, GCP or Azure, against your own database. The only outbound traffic is to the model provider you choose.

Kodeus Cloud

We run it for you. Per-tenant isolation, metering and the Console out of the box.

Airgapped

No outbound network at all. Models hosted inside the perimeter. For sites where the cable is pulled.

Same runtime in all four. Nothing calls Kodeus at serve time.

FAQ

Questions about the platform

{{ f.a }}

Private preview

Stop building the platform. Start shipping the product.

Tell us what you are building and we will get you into the preview as soon as we can support your use case properly.

Request early access →Book a call