Want this shaped to your perimeter, or have questions? Kovanex can be tailored to your environment — and if you’d like hands-on help, the author takes on audit & refinement work ↗.
You want an AI agent building software — you can't let it roam your protected network. Kovanex resolves the tension with a boundary, not a promise. The agent, the kovanex control plane, and its CI runner run in a sandbox outside your guarded corporate perimeter. Across the boundary, in one direction, through a single narrow git port, moves only code — and it reaches your internal production only after passing your code review, under your regulations.
In an isolated sandbox outside your guarded perimeter — a dedicated VM or a segmented network. The agent, the kovanex control plane, and the CI runner all live there. None of them join your protected internal network.
Only source code, only outbound-to-inbound through a single git port. No agent process, no runtime, and no production secrets cross. The boundary carries commits, nothing else.
The sandbox pushes to your internal development repository — the code the agent and kovanex produced — over the git port. From there your existing branch protections, reviewers, and merge gates apply exactly as they do for any other contributor.
Your engineers, under your regulations. Nothing merges to internal production without passing your review. Kovanex adds its own signed audit trail on every action, so the review has a complete, tamper-evident record to work from.
Production secrets stay inside your perimeter. The sandbox holds only what it needs to build and test; secrets it does use are held in kovanex's vault, and nothing from the guarded network is exported to it.
That is your call. It can be locked down to just the git port plus a model endpoint, or run fully air-gapped with a self-hosted model. Kovanex has no cloud dependency of its own.
A VPN puts the agent inside your network. This does the opposite: the agent never gets a route to internal systems. The only thing that ever reaches you is a reviewed git push — a boundary your security team already knows how to govern.