Skip to content

ZHASK docs

Documentation

Install, configure and operate kaveo, aegis and Vectasec. Each product has a quick start, the concepts behind it, task guides and a complete reference.

Products

  • Cloud Security Posture Management

    kaveo

    kaveo is a self-hosted cloud security platform: read-only collection, deterministic detection, evidence-backed findings and grounded AI that cites its sources.

  • MCP Gateway Security

    aegis

    aegis is a security gateway for MCP: it authenticates, authorizes, threat-scans and audits every agent tool call without changing your servers or clients.

  • Middleware Security

    Vectasec

    Vectasec is read-only security posture for the integration layer: brokers, gateways, meshes and MCP servers, with evidence-backed findings.

Security model

Every product collects with least privilege and backs what it reports with stored evidence. Where each one runs:

kaveo

A self-hosted Docker Compose stack in your environment. Scans use a read-only role, and out of the box it makes no outbound calls beyond the cloud APIs it scans. kaveo security model

aegis

A single gateway you deploy in front of your MCP servers, with Docker Compose or Helm. Your servers and clients stay unchanged. aegis security model

Vectasec

Collection is read-only. The control plane is hosted on Supabase, outside your network; the Collector runs inside your network so credentials and raw configuration stay there. The self-hosted stack is in preview. Vectasec security model

Common tasks

Evaluating for your team?

We will walk through deployment inside your environment and answer security review questions.

Book a demo