ZHASK docs
Documentation
Install, configure and operate kaveo, aegis and Vectasec. Each product has a quick start, the concepts behind it, task guides and a complete reference.
Products
Cloud Security Posture Management
kaveo
kaveo is a self-hosted cloud security platform: read-only collection, deterministic detection, evidence-backed findings and grounded AI that cites its sources.
MCP Gateway Security
aegis
aegis is a security gateway for MCP: it authenticates, authorizes, threat-scans and audits every agent tool call without changing your servers or clients.
Middleware Security
Vectasec
Vectasec is read-only security posture for the integration layer: brokers, gateways, meshes and MCP servers, with evidence-backed findings.
Security model
Every product collects with least privilege and backs what it reports with stored evidence. Where each one runs:
kaveo
A self-hosted Docker Compose stack in your environment. Scans use a read-only role, and out of the box it makes no outbound calls beyond the cloud APIs it scans. kaveo security model
aegis
A single gateway you deploy in front of your MCP servers, with Docker Compose or Helm. Your servers and clients stay unchanged. aegis security model
Vectasec
Collection is read-only. The control plane is hosted on Supabase, outside your network; the Collector runs inside your network so credentials and raw configuration stay there. The self-hosted stack is in preview. Vectasec security model
Common tasks
Evaluating for your team?
We will walk through deployment inside your environment and answer security review questions.