Skip to content
NewKubeOn AI: a managed LLM gateway with cost per 1M tokens for every model

Trust center

Read-only by design, not by setting

KubeOn never needs write access to your clusters or cloud accounts. We publish every permission it uses, so your security team can review them before anything is installed.

Read-only agent

get, list and watch only. No write verbs, no Secrets, no ConfigMaps.

Outbound only

The hub never calls into your clusters. Agents push snapshots out over HTTPS.

Data stays in your account

Self-hosted hubs query billing in place and store snapshots in your bucket.

Encryption with your keys

A customer-managed KMS key covers the database, cache, buckets, secrets and logs.

Least-privilege IAM

Billing roles read the export and write only query results. Agent roles can only add snapshots.

SSO and team scope

SAML 2.0 or OIDC sign-in, four roles, and team leads limited to their teams.

Audit log

Every mapping, policy, integration and proposal decision, with who and when.

Scanned supply chain

Images scanned on every build; high and critical findings block a release.

Published permissions

Every permission, in the open

These are the exact rules the agent's ClusterRole and the AWS billing role contain. Azure and Google Cloud use the equivalent read-only roles listed in the docs.

Agent ClusterRole
apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:  name: kubeon-agent-readerrules:  - apiGroups: [""]    resources: [nodes, pods, namespaces, persistentvolumes,                persistentvolumeclaims, services, resourcequotas, limitranges]    verbs: [get, list, watch]  - apiGroups: [apps]    resources: [deployments, statefulsets, daemonsets, replicasets]    verbs: [get, list, watch]  - apiGroups: [batch]    resources: [jobs, cronjobs]    verbs: [get, list, watch]  - apiGroups: [storage.k8s.io]    resources: [storageclasses]    verbs: [get, list, watch]  - apiGroups: [metrics.k8s.io]    resources: [nodes, pods]    verbs: [get, list]
AWS billing role policy
{  "Version": "2012-10-17",  "Statement": [    {      "Sid": "AthenaQuery",      "Effect": "Allow",      "Action": [        "athena:StartQueryExecution", "athena:GetQueryExecution",        "athena:GetQueryResults", "athena:StopQueryExecution", "athena:GetWorkGroup"      ],      "Resource": "arn:aws:athena:us-east-1:111122223333:workgroup/primary"    },    {      "Sid": "GlueCatalogRead",      "Effect": "Allow",      "Action": [        "glue:GetDatabase", "glue:GetDatabases", "glue:GetTable",        "glue:GetTables", "glue:GetPartition", "glue:GetPartitions"      ],      "Resource": [        "arn:aws:glue:us-east-1:111122223333:catalog",        "arn:aws:glue:us-east-1:111122223333:database/cur_database",        "arn:aws:glue:us-east-1:111122223333:table/cur_database/*"      ]    },    {      "Sid": "CurBucketRead",      "Effect": "Allow",      "Action": ["s3:GetObject", "s3:ListBucket", "s3:GetBucketLocation"],      "Resource": ["arn:aws:s3:::acme-cur-exports", "arn:aws:s3:::acme-cur-exports/*"]    },    {      "Sid": "AthenaResultsReadWrite",      "Effect": "Allow",      "Action": [        "s3:GetObject", "s3:PutObject", "s3:AbortMultipartUpload",        "s3:ListBucket", "s3:GetBucketLocation"      ],      "Resource": ["arn:aws:s3:::acme-athena-results", "arn:aws:s3:::acme-athena-results/*"]    },    {      "Sid": "STSAccess",      "Effect": "Allow",      "Action": "sts:GetCallerIdentity",      "Resource": "*"    }  ]}

Data

What KubeOn reads, and what it never touches

Collected

  • Node names, instance types, capacity, zones and provider IDs
  • Namespace, workload and pod names, labels and owner references
  • CPU and memory requests and measured usage per pod
  • PersistentVolume and PVC sizes, classes and status
  • Service types and load balancer hostnames
  • Billing line items from your export: cost, usage type, resource ID

Never collected

  • Secrets, ConfigMaps or environment variables
  • Container images, logs or application data
  • Request payloads or network packet contents
  • Credentials of any kind from your clusters
  • Personal data about your customers

KubeOn AI gateway

Model traffic, handled with care

The gateway sits in the path of your prompts, so it records as little as it can and keeps credentials out of your applications.

Metadata by default

Tokens, route, latency, cost and status are recorded. Prompt and response bodies are not, unless you enable logging for a route.

PII redaction

Email addresses, phone numbers and card numbers are masked before a request leaves the gateway.

Credentials in your vault

Provider keys come from your secrets manager or from workload identity, never from app code or gateway keys.

Region pinning

Routes can be held to US or EU providers and regions, and the self-hosted gateway keeps traffic in your network.

Retention

How long data is kept

Defaults for a self-hosted hub. KubeOn Cloud uses the same defaults; each can be changed for your workspace.

Data retention defaults
Agent snapshots in object storage14 days, then deleted by a lifecycle rule
Billing rows in the hub90 days by default, configurable
Allocated costs and reportsKept for the life of the workspace
Usage and assistant ledger365 days
Athena query results (AWS)14 days
KubeOn AI gateway request metadata90 days by default; prompts are not stored unless logging is on for a route

Controls

How the hub is hardened

Network

  • Internal load balancer by default, with an allow-list of private ranges
  • TLS 1.3 policy on the load balancer, HTTP redirected to HTTPS
  • Optional CloudFront with AWS WAF: IP allow-list, managed rules, rate limits

Application

  • The hub refuses to start without a signing secret, or without KMS outside development
  • Short-lived access tokens; lockout after 5 failed sign-ins for 15 minutes
  • Strict security headers on every response

Secrets

  • Secrets in your secrets manager, never in task definitions
  • Database password generated and rotated by the cloud provider
  • Integration credentials encrypted at rest

Build and release

  • Trivy image scans, gitleaks secret scanning, dependency audits
  • Checkov and tflint on every Terraform change
  • Non-root images, pinned chart versions

Compliance

Inside your compliance boundary

A self-hosted hub runs in your account or data center, under the controls you already audit. For every deployment we provide the architecture, data flow, permission lists and answers to your security questionnaire during evaluation.

Responsible disclosure

Report a vulnerability

Email security@kubeon.io with the details. We acknowledge reports within two business days and keep you updated until the issue is fixed.

Bring your security team to the demo.

We walk through the agent's permissions, the data flow and the hub's controls on your architecture.