Kosmoy
by Kosmoy
A self-hosted AI control plane: inventory, gateway, observability and agent sandboxing
Kosmoy is a self-hosted AI management platform that gives enterprises one control plane over every model, application, agent and MCP server they run. It combines an AI inventory, an OpenAI-compatible gateway with guardrails and budgets, observability with cost tracking, and Kubernetes-native sandboxes for autonomous agents — aimed at CIOs who need EU AI Act, ISO 42001 and NIST AI RMF evidence without sending data to a vendor's cloud.
Kosmoy, founded in 2024 and headquartered in Milan with a fully remote team across New York, Buenos Aires, Belgrade, Dubai and Singapore, sells an AI management platform structured as four concentric layers of control. AI Inventory maintains registries of AI systems, models, agents and MCP servers with ownership and risk classification, and pulls agents automatically from Azure AI Foundry, AWS Bedrock, Google Vertex, Salesforce and ServiceNow. Monitoring and Observability tracks cost and usage per model, application and user with budgets that warn and then block, plus roughly twenty evaluators and red teaming. Governance centres on an AI Gateway exposed through an OpenAI-compatible API that authenticates requests, inspects traffic, applies guardrails, routes to approved models, enforces rate limits and logs every decision. AI Action Control adds Action Capsules — Kubernetes-native containers with in-container sandboxing that hold autonomous agents accessing systems of record — supervised by Mission Control with pre-flight authorisation, just-in-time credentials and a kill switch; an Agent Access Control registry giving each agent a distinct identity with approve, review and block states shipped in June 2026. The platform is deliberately not SaaS: it installs via Helm charts into the customer's own Kubernetes on Azure, AWS, GCP or on-premises, is single-tenant by default, air-gap capable and model-agnostic across OpenAI, Anthropic, Google, Meta, Mistral, Hugging Face and private fine-tuned models. It is built to produce the evidence the EU AI Act (Articles 9, 11, 12, 14, 17 and 50), ISO/IEC 42001 and the NIST AI Risk Management Framework require. Kosmoy says it runs in production at Banca d'Italia and Leonardo, and was named a Representative Vendor in Gartner's February 2026 Market Guide for AI Gateways.
A CIO or head of AI platform at a European regulated enterprise running AI across several clouds who needs one auditable control plane — and cannot route prompts through a vendor's shared SaaS to get it.
Every model, agent and MCP call passes one policy-enforcing gateway inside your own Kubernetes, producing the inventory, logs and evidence the EU AI Act, ISO 42001 and NIST AI RMF ask for.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Subscription
- Target Market
- CIOs, CTOs, Heads of AI Platform, Chief Risk Officers, Enterprise Architects
- Deployment
- Self-hosted, Multi-cloud, Hybrid
- Founded
- 2024
- Headquarters
- Milan, Italy
Key Features
- ✓OpenAI-compatible AI Gateway
Authenticates, inspects, guardrails, routes, rate-limits and logs every LLM, MCP and agent-to-agent call through one enforcement point.
- ✓AI inventory and agent registry
Registers models, agents and MCP servers with ownership and risk class, pulling agents automatically from Bedrock, Vertex, Foundry, Salesforce and ServiceNow.
- ✓Action Capsules
Kubernetes-native containers with in-container sandboxing that isolate autonomous agents touching systems of record, using just-in-time credentials.
- ✓Mission Control kill switch
Supervises the agent fleet with pre-flight authorisation and an immediate kill switch, which is the control auditors ask for on autonomous agents.
- ✓AI FinOps budgets
Tracks cost and usage per model, application and user, with budgets that first warn and then hard-block further spend.
- ✓Compliance evidence generation
Produces the artefacts the EU AI Act Articles 9, 11, 12, 14, 17 and 50, ISO/IEC 42001 and NIST AI RMF require from deployers.
- ✓RAG-in-a-Box
Prebuilt ingestion pipelines into SharePoint, Confluence and object stores with hybrid retrieval and re-ranking, so retrieval is governed too.
Capabilities
Use Cases
- •Multi-cloud AI governance
An enterprise running models on Azure, AWS and Vertex enforces one guardrail, routing and logging policy across all three from a single control plane.
- •EU AI Act audit readiness
Risk classification, conversation logging and system inventory produce the deployer evidence Articles 9 through 50 require, without a manual documentation project.
- •Containing autonomous agents
Agents reaching into SAP, Salesforce or ServiceNow run inside Action Capsules with scoped just-in-time credentials and a supervisor kill switch.
- •Controlling runaway AI spend
Per-model and per-user budgets warn then block, and the gateway routes cheaper workloads to smaller models to cut cost.
- •Air-gapped AI deployment
Defence and central-banking environments run the full control plane single-tenant inside their own Kubernetes with no external dependency.
Ideal For
Best For
- ✓Centralising governance over AI already sprawling across Azure AI Foundry, AWS Bedrock, Vertex AI, Salesforce and ServiceNow
- ✓Producing audit evidence for the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework
- ✓Containing autonomous agents that touch systems of record, using Kubernetes sandboxes with just-in-time credentials and a kill switch
- ✓AI FinOps: tracking spend per model, application and user with budgets that warn and then block
- ✓Air-gapped or data-sovereign environments where a SaaS AI gateway is not an option
Not Ideal For
- ✗Teams that want a managed SaaS gateway — Kosmoy is self-hosted only and you must run and operate the Kubernetes cluster it installs into
- ✗Buyers who require independent validation before purchase: there are zero user reviews on public directories and no Hacker News or Reddit discussion of the product at all
- ✗Small teams or single-model shops, where a control plane of this scope is far more governance machinery than the estate justifies
Deployment
Market Analysis
Pros
- ✓Named a Representative Vendor in Gartner's February 2026 Market Guide for AI Gateways, and S&P Global 451 Research initiated analyst coverage in March 2026
- ✓Genuinely self-hosted and air-gap capable, single-tenant in the customer's own Kubernetes — a real differentiator against SaaS-only gateway rivals
- ✓Scope reaches beyond the gateway into agent containment, with Action Capsules, just-in-time credentials and a Mission Control kill switch
- ✓Compliance mapping is specific rather than aspirational, naming EU AI Act Articles 9, 11, 12, 14, 17 and 50 alongside ISO/IEC 42001 and NIST AI RMF
Cons
- ✗No practitioner evidence exists anywhere: zero user reviews on SourceForge and Slashdot, and a Hacker News search returns no results for the product at all
- ✗Founded only in 2024 with no disclosed funding, so financial durability cannot be assessed by a buyer signing a multi-year governance contract
- ✗The flagship references — Banca d'Italia and Leonardo — are vendor-asserted and could not be independently confirmed in any third-party source
- ✗Self-hosted only means you carry the Kubernetes operations burden; there is no managed option for teams without platform engineering capacity
- ✗No published pricing and no free version, with a five-step sales process ending in a proof of concept before any number appears
- ✗Competes for the same gateway budget as Kong, TrueFoundry, NeuralTrust and Portkey, several of which are larger and better capitalised
Pricing
Enterprise annual licence
Contact for pricing
- ✓AI inventory and registries
- ✓OpenAI-compatible AI Gateway with guardrails and RBAC
- ✓Observability, evaluators and AI FinOps
- ✓Action Capsules and Mission Control agent containment
- ✓Deployed into the customer's own Kubernetes
Kosmoy publishes no price. It sells an annual enterprise licence quoted against four explicit variables — which control layers you take (inventory, observability, gateway policy, agent containment), workload scope, deployment boundary (Azure, AWS, GCP, on-premises or air-gapped) and implementation support — after a five-step cycle ending in a proof of concept. Third-party directories list a free trial but no free version; budget separately for the Kubernetes infrastructure it runs on.
Security & Compliance
Connect
Sources
This page was written from 5 sources, 2 on domains other than kosmoy.com.
- 1.kosmoy.com — platformvendor
- 2.kosmoy.com — companyvendor
- 3.kosmoy.com — pricingvendor
- 4.sourceforge.net — Kosmoy
- 5.slashdot.org — Kosmoy
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
SCALR AI
A licence-free multi-agent SOC workbench that runs in your own Azure tenant
RadarFirst
Compliance agents that prepare the work — people still make every regulatory decision
Lema
Agentic third-party risk management — treat vendor risk as a security problem, not a checklist
AIR Security
A context firewall that vets every skill, plugin and MCP server an AI agent touches