Skip to content

Enterprise

Intelligence your company controls, end to end. Kaba Enterprise puts models to work on your own infrastructure, with your people, policies and expertise in every loop.

This page separates two things clearly: the building blocks that are in the product you can deploy today, and the fleet features that are part of Kaba Enterprise.

Kaba Personal is all local. Your account, your keys, your policies, your devices and your settings live on hardware you own and answer only to you. Unless a page says otherwise, that is what the rest of this site describes.

Kaba Enterprise with fleet management is centrally controlled. Authentication, policy, enrolment and updates move from the individual to the organisation. If your device is fleet-managed, read the Personal pages with this table in mind.

AreaKaba PersonalKaba Enterprise with fleet management
Accounts and sign-inA local account on your device. No sign-up and no account server.Authentication is centralized. Your organisation issues and controls identities.
Keys and recoveryOnly you hold the key that encrypts your data. A forgotten password cannot be reset.The organisation can revoke keys and data on a device remotely.
DevicesYou invite and evict your own devices with join tickets.Devices are enrolled into the fleet and grouped by team, site or business unit. Removal is central.
PoliciesYou create, choose and lock your own policies.Policies are pushed to each group and enforced in the engine. Users cannot loosen them.
Models and adaptersYou download, import and train what you like.Models and adapters are pushed per group.
SettingsEvery switch is yours.Settings can be enforced by policy: allowed models, ad blocking, default search engines, themes and branding, proxy and comms, local versus remote inference.
UpdatesYou decide when to update.Updates are pushed centrally.
Sensitive actionsYou approve commands yourself.Named approvers sign off before sensitive actions run.
VisibilityNobody else can see your data or activity.Audit trails and metering by team, project and model. Fleet search runs where the data lives and returns only what policy allows the requester to see.
RetentionYou decide what to keep and what to delete.Residency and retention are set centrally.
ComputeYour devices and your peers.A shared pool of GPU machines, with budgets enforced by policy.

In both cases data, prompts and weights stay on systems the owner controls: yours in Personal, your organisation’s in Enterprise. Kaba Labs is not in the path.

[todo: confirm each row of this table against the Enterprise product, and document the specifics: how centralized sign-in works, account and key recovery, and exactly what an administrator can and cannot see on a device.]

Everything in this table is in Kaba 0.146 and kabactl 0.87.

NeedWhat provides itDocs
Data, prompts and weights stay on systems you ownLocal storage and inference; no vendor service in the pathPrivacy
Policy inside every callPolicies with deny-wins tool ceilings, command and network modesMachine learning
Policies people cannot loosenPrevent overriding policy settings, enforced per requestSecurity
Sandboxed toolsContainers, gVisor preferred, network off by defaultSecurity
A record of what automation didEach tool-loop step recorded as a trajectoryGovernance & controls
Device enrolment and removalJoin tickets, eviction, tombstonesCluster & mesh
Private networking with no open portsThe mesh, with your own relayProtocols
Shared GPU capacityRemote inference and training on designated peersModels & training
Company expertise as adaptersLoRA training on curated memories; adapters with manifestsMachine learning
Distributing a standard policy.kabap bundlesFile formats
Deploys on your platformsystemd, containers, HelmDeployment
Air-gapped operationIsolated configurationkaba-enclave
Encryption at restPer-account keys for memories and credentialsSecurity

A small deployment that uses only the above:

  1. GPU nodes. One or more headless kabactl nodes with models, on Kubernetes or systemd. They accept remote inference and training.
  2. A relay you host, set in every node’s cluster_options.
  3. Workstations running the client, joined to the cluster. Their policy names a GPU node as the inference target, so laptops stay light.
  4. A standard policy, exported as .kabap and imported on each workstation, with Prevent overriding policy settings on.
  5. Firewall rules blocking the API and proxy ports from outside each host.

These are the fleet-scale capabilities described for Kaba Enterprise. They are not part of the release documented on this site.

CapabilityDescription
Fleet managementEnrol devices and group them by team, site or business unit. Push policies, models and adapters to each group. See health, versions and GPU capacity for every peer in one view.
Fleet searchSearch memories, documents, trajectories and adapters across devices without copying data into a central index. Queries run where the data lives and return only what policy allows.
Fleet trainingSchedule jobs across idle GPUs. Distil, tune and evaluate candidates before they ship.
ApprovalsPeople sign off on sensitive actions before they run.
Ontology rulesThe entities, relationships and rules of your business, respected at every step.
Metering and budgetsEvery run attributed by team, project and model; limits enforced by policy.
Remote revocationRevoke keys and data on a device centrally.
Company mixture of expertsA router across team-trained adapters that improves with use.

[todo: confirm which Enterprise capabilities are generally available, and link each to its own documentation as it is published.]

Two foundations for these already exist in the engine: device groups, and a tool-loop knowledge graph that records each step’s tool, phase and outcome and can be queried.

Virtual desktop infrastructure keeps data safe by running every desktop in a data center and streaming the screen. Model-driven work makes thousands of small decisions, and a round trip for each one is too slow.

Kaba takes the other route: central control, distributed compute. Work runs natively on each device or the nearest peer. Policy travels with the workload. Data stays where it was created, encrypted.

Kaba provides controls you can map to your own program. See governance & controls.

For a self-hosted pilot on your infrastructure, with your policies and approvers in place from day one, get in touch through kaba.ai.