
One agent for everything that recurs in your environment.
From developer teams to auditors, from invoice checks to executive search. Anything that runs by hand today can be handled by an agent. It runs inside your network, may only do what you approve, and records every step.

What only a gateway with a flight recorder can deliver.
One access point to all language models, permissions and budgets per workplace, every decision recorded before it is executed. Eight cases where exactly that makes the difference.
Developer teams with Claude Code, Cursor and SDKs
One virtual key per workplace, one budget per team. No provider key leaves the vault.
Evidence: consumption per workplace and team, reconciled with the provider invoice.
Confidential data stays local
The data class "strict" automatically routes to the model inside your own network or in the BrainQubes data center. Plain text never reaches an external provider.
Evidence: rule and target provider are recorded with every entry in the trail.
Audit and regulation
Banks, insurers, GxP: export one day or one job, the verifier runs offline at the auditor. eIDAS timestamps, WORM anchors against recomputation.
Evidence: auditable evidence for the AI Act, DORA and GDPR.
Approval of sensitive requests
An ask rule holds the request. Owners receive a message and decide with role and right.
Evidence: who approved or rejected what and when, for every run.
Cost control per workplace and cost center
Settlement in micro-euros, reservation before the call prevents overspending. Reconciliation with the provider invoice finds foreign calls.
Evidence: sum of settlements equals consumption, per period.
Agents and automations
n8n, your own agents, nightly jobs: every run with its subtasks is traceable, the run receipt is the signed proof per job.
Evidence: one receipt per job, independently verifiable.
Controlling tools (MCP)
A forbidden tool call is rejected and recorded before execution. A permitted one runs in the sandbox.
Evidence: an "enforced" entry with tool, rule and result.
Data protection with probative value
Contents are not stored by default, only metadata and hashes. Pseudonyms, disclosure only under the four-eyes principle, deletion by destroying the key.
Evidence: the chain stays intact, the content is gone.
Six agents search. Four gates decide. The human remains the consultant.
PilotA mandate does not read "find a CIO". It reads, for example: "Not replacing the CIO, but repositioning IT as an international business and transformation driver." That is exactly where the agents' work begins, and exactly how it ends: with a human who decides.
All people, companies and mandates in the case study are fictional. They come from our clickable demo, which we show in the conversation.
Mandate
The mandate agent reads briefing and stakeholders and names contradictions. The skill agent builds the criteria model with weights and an anti-discrimination note. Gate 1: the consultant approves the mandate profile.
Search
The research agent develops search hypotheses and target companies, the matching agent scores profiles across six dimensions. Gate 2: the consultant approves the outreach list.
Dialogue
The outreach agent drafts every message, nothing is sent before approval. Only the human writes the interview assessment. Gate 3: qualification.
Closing
The dossier agent assembles shortlist and dossier. Gate 4: the consultant approves the recommendation. Client interviews and negotiation are handled by the human only.
Aftercare
Placement, checkpoints, lessons for the next mandate. The talent pool stays company wide, with deadlines for disclosure and deletion.
Four gates, no autopilot
Mandate profile, outreach list, qualification, recommendation: nothing passes these points without approval. Every message is presented before sending. Assessment and negotiation stay with the human. Close and Esc always mean no.
A fit model that admits what it does not know
Six dimensions: skill, experience, leadership, industry, transformation, context. Every field knows four states, and "unknown" is not "no". Below 60 percent coverage the agent gives no verdict.
Duties are checkboxes before the button
Anti-discrimination note on the criteria, Art. 14 GDPR information attached to every outreach, data protection deadlines in the talent pool. Only when the boxes are ticked is "sent" recorded.
The start view shows only what is waiting for a human. Amber means: your turn. Blue was prepared by the agent, violet is evidence and data protection.
Technology: one file, no framework, zero network requests on load, language model local, every step in the trail.
What a plugin can take over in your environment.
Examples of plugins your IT or business department builds with the sepp mini SDK. Each one gets only the rights it needs for its single task: the invoice check sees the receipts folder, nothing else.
Connecting your systems
CRM lookup
Customers, contacts, history
Ticket system
Create and close tickets
Company API
Your own REST API, permitted addresses only
Read a database
Analysis without exporting data
File storage
Search a network drive selectively
Appointments and rooms
Check availability
Building
Light, heating, access in the environment
Machinery
Query plants and drives
Calculating and checking
Units and tolerances
Check technical values
Quote calculation
Prices by your rules
Currency conversion
With today's rate
Freight costs
Tariffs and zones
Discounts and deadlines
Calculate payment terms
Explode a bill of materials
Demand per component
Key figures
From the monthly close
ERP query
Read orders and stock
Documents and knowledge
Read PDF and Word
Character exact, without a language model
Invoice check
Mandatory details under § 14 UStG
Find clauses
Deadlines, liability, termination
Your own manual
Knowledge base without any rights
Knowledge search (RAG)
Answer with the source from your documents
Fill in forms
Fields from master data
Tables from scans
Numbers instead of images
Translate
With the glossary of your environment
Security and evidence
Check permissions
Who may access what
Find secrets
Credentials in source code
Report vulnerabilities
Match dependencies
Redact personal data
Before passing on
Analyse logs
Name anomalies
Verify signatures
Files from suppliers
Operations and routine
Check a build plan
Before every assembly
Test reports
Summarised on one page
Trigger a delivery
After a passed check
Query monitoring
State of the services
Generate reports
Finished spreadsheets
Reconcile master data
Two systems, one truth
A plugin is ordinary code. It is executed locked in.
Written with the SDK in a language of your choice. It becomes a single building block that the agent executes the same way on every machine: only with the rights that have been approved. The boundary is drawn by the operating system, not by the program. Every access is recorded and stays readable.
- Any language, SDK included
- Plugins as building blocks, platform independent
- Execution only with approved rights
- The same module everywhere
Interface
Value: control. The history is visible on screen, sensitive steps are asked before, abort at any time.
One call
Value: automation. One question, one answer, the result goes to the next program. Recurring work runs unattended.
Embedded
Value: integration. Requests in, answers out, line by line. The agent sits inside your own application.
A signed catalogue of the packages approved at your company.
A package bundles skills, templates, rules, plugins and settings into a single signed file. The catalogue lives on your own web space inside the company network and needs neither an account nor an external operator.
Authors in your environment
Business departments and IT bundle packages and sign them with their own key.
Your directory
A signed catalogue on your web space. It names packages, it grants nothing.
Workplaces
Search by name and install. The stored key must match the package.
Sovereign
Catalogue and packages stay with you. No external operator, no dependency.
Works without internet
A folder behind your own web server is enough.
Controlled
Only what is in the catalogue is found by name. The operator key is fixed.
Revocable
Trust in a publisher can be withdrawn at any time, packages removed.
Unsigned: rejected
No unpacking, no copy, no right. The same applies to files altered afterwards.
The agent does not think by itself, it asks a model. Which one is up to you.
Large model from outside
When performance matters. The access key comes from the environment and never ends up in an output.
On your server
A self-hosted model inside the company network, for example through LM Studio, Ollama or vLLM. Contents never leave the environment.
On the workplace
On Apple machines the model runs through MLX directly on the processor. No key, no configuration.
Compute from a European data center, controlled per workplace.
Confidential work stays on your own server or in the partner's data center, heavy work may go outside, everyday work runs at the desk. Switching is one setting at start, not a rebuild. No provider locks you in.
To KIONOVA gatewayWhat prospects ask first.
What does a pilot cost?
The price depends on scope and number of workplaces and is agreed in the conversation. There is no account with an external service and no cost that scales with your usage.
How does the rollout work?
As a pilot on one of your processes: we set it up together, your staff work with it, then you decide. We measure processing time per case, agreement between agent and human, and the number of exceptions. For sepp mini a single file is technically enough: copy, make executable, start.
Is a cloud provider required?
No. You decide which language model answers: a model on your machine or server, a provider of your choice, the data center of our partner BrainQubes, or a combination per task.
Does it run offline?
Yes. With a local model sepp mini works entirely without a network connection, on a notebook, a server on site or from a USB stick.
Where is the data?
With you. There is no KIONOVA service that sees your documents. Whatever the agent reads or writes stays in your environment, and every access is in the audit trail.
What may the agent do, and what not?
Only what has been approved beforehand. It sees the current project, nothing else on the machine, no internet and no access to sensitive data without permission. The boundary is drawn by the operating system, not by the program.