kirya.
Infrastructure for the era of infinite software

Let your team build with AI without losing the map of your company.

Building got easy. Governing didn't.

kirya maps your company's infrastructure and brings that map, rules included, to the AI tools your team uses.

The shift

Your company's next app will be born outside IT.

An analyst needs a churn-and-revenue dashboard by region. She opens Cursor, Claude or Lovable and starts building.

No waiting for the development queue. But she is still using the company's data and infrastructure.

When everyone can build, the mess scales too.

The problem

Infrastructure sprawl.

The trouble starts when those apps enter the operation without entering IT's map.

  • 01Personal data flows through tools nobody approved.
  • 02Cloud and AI bills with no budget and no control.
  • 03Copies of data stay alive after access to the source was cut.
  • 04Duplicate apps, with no owner.

By the time IT finds out, the company already depends on them.

The numbers

Shadow AI rose from 20% to 43% of AI-related breaches worldwide (IBM Cost of a Data Breach 2026). An Amazon team described the same pattern in an internal memo in February 2026: AI was creating duplicate tools faster than the company could remove them (Business Insider, Apr 2026).

The solution

kirya prepares the ground to build on.

kirya connects to repositories, cloud, databases and work tools and builds a living map: systems, data and the relationships between them.

That map reaches Cursor, Claude Code, Lovable and Copilot through MCP, with access and usage rules already applied.

Whoever builds knows what already exists, which source to use and when approval is needed. What is born is registered, with an owner and a history.

Map. Ontology. Policy. Construction. Registry.

Connectors today: GitHub, Azure, PostgreSQL, Google Workspace and Asana — continuously expanding.

The experience

“I need a dashboard that crosses revenue and churn by region.”

kirya takes that request and walks the whole path: finds what already exists, prepares access, helps build and registers what is born.

01

The request

Someone in the company wants to solve a problem.

02

What already exists

kirya shows what already exists and can be reused.

03

The rules

Official source, sensitive data masked, permissions and approvals — all before use.

04

The build

The app is born inside the rules, in kirya or in the tool the team already uses.

05

The registry

It comes out catalogued, with an owner and a history.

Governance before construction — without creating a new queue.

The CTO console

Infrastructure, owners and costs in one view.

What exists

Systems, data and apps, with owners and pending approvals. And what is being built right now.

The living map

Built by the connectors, reviewed by people: relationships, owners, dependencies, activity.

What it costs

Cloud and AI by area, project and app, on your key and your account. Budgets, alerts and limits: rolling out.

You choose the AI providers. The bill stays yours.

Guarantees

The rules apply when things run, not just on paper.

01 · CISO

Access limited to the task

The agent gets only what the approved task needs, inside the project. Never the infrastructure credentials. What isn't on the map doesn't exist for the model.

You want the team building with AI. You also know what comes next if nobody holds the line: rework, duplication and a liability nobody mapped. kirya shows what exists, what is being built right now and who is responsible for each piece. And it puts company rules on the path of construction, not in a queue before it. The team speeds up. You can see.

02 · CTO

Inference doesn't become truth on its own

Every model inference enters as pending and only becomes fact when someone responsible confirms it.

The risk is not AI. It is AI reading what it shouldn't and acting where it shouldn't. In kirya, what is not mapped does not exist for the model. The agent gets only the capability the approved task needs, never infrastructure credentials. Sensitive data is classified at ingestion and masked on every use. Every call is recorded: who asked, which rule applied, which source was used, who approved.

03 · DPO

Everything is born with a trail, an owner and a policy

Who asked, which rule applied, which source was used, who approved — the trail data-protection law expects.

Data-protection law expects you to know where personal data flows, and to be able to show it. When software creation spreads across the company, that map gets lost. kirya rebuilds the map without touching content: it classifies identifiers by data structure, masks before use and keeps the processing trail regulators expect, by application, by person, by decision.

Under the hood

Four principles.

Reads metadata, not data.

Schemas, repositories, configuration and cloud resources. Never production rows; never write access.

Your key, your account.

AI models run on the customer's own key. kirya doesn't sell tokens or sit in the billing path.

Closed by default.

Default deny: what isn't on the map doesn't exist for the model. The agent gets what the approved task needs, never credentials.

AI proposes. Someone confirms.

Every inference enters as pending. It only becomes truth by a responsible person's decision.

See the architecture

FAQ

What people usually ask.

We already have an AI gateway, Purview and a usage policy. Why kirya?

Because they do different things. Gateways and allow-lists control where AI traffic goes. Written policy depends on people remembering it. kirya governs what AI sees and what it can do, from a map of your infrastructure that maintains itself, and records what is born from it. The three coexist. kirya is the layer the other two don't have.

Does kirya see my data?

To build the map, no. It reads metadata, never production rows. When someone queries data through kirya, it happens inside an explicit profile and permission, with sensitive columns masked, and it is recorded.

Does my team have to change tools?

No. Context reaches Cursor, Claude Code, Lovable and Copilot through MCP. Technical people stay where they are. Non-technical people use the kirya interface.

What if the AI gets the map wrong?

It will, sometimes. That is why every inference enters as pending and only becomes truth when a responsible person confirms it. Automation is in discovery. Authority stays human.

What does it cost?

An annual subscription, sized by what kirya governs: domains, assets and identities consuming the endpoint. Not per user. AI model consumption stays on your account. The number comes out of a thirty-minute conversation.

Next step

Bring a request that takes days today.

In 30 minutes we show how it would go through kirya: what already exists, which source is official, what gets masked, and the app being born on the map.

If it makes sense, the next step is an initial project on your infrastructure, with authorised access and clear criteria: delivery time, engineering hours, what got reused.

The invitation is for the CTO. Bring the CISO and the DPO: the guarantees were made for all three.

About

kirya is a Kognita platform.

kirya was born from a problem of our own. We started building software with AI faster than we could govern it, and found no tool that would map what existed without someone filling in a spreadsheet. So we built it. We are the first customer.

São Paulo, Brazil · letsgo@kirya.ai · Manifesto · Architecture