Speed without understanding is a risk. Kaba is built so that you can see where data goes, what automation can touch, and which models learn from it. This page lists what the product does today and links to the detail. For the reasoning behind these choices, see Why Kaba?.
Every model call and tool step goes through a policy. In Kaba Personal the policy is yours; under fleet management it is pushed and enforced centrally. See what fleet control changes.
| Feature | Detail |
|---|
| Policies | One object decides where inference runs, which model and adapter answer, and what may execute. Machine learning |
| Deny wins | A policy’s tool ceiling cannot be re-enabled from below. Security |
| Locked policies | Prevent overriding policy settings is enforced on every request. |
| A fixed tool catalog | Tools are first-party code; data cannot add one. Projects & tool loop |
| Portable policy bundles | Export and import as .kabap. File formats |
| Feature | Detail |
|---|
| Container sandbox | File, code and build work runs in a container with a read-only root and no network by default. Security |
| gVisor first | On Linux the sandbox prefers runsc when it is installed. |
| Network is a policy decision | Off, on request, or always. |
| Command approval | Ask, auto-run for read-only commands, or off. |
| Feature | Detail |
|---|
| Per-account encryption | Memories, learning data, saved logins and passkeys. Security |
| Secret-aware recording | Terminal memory never stores typed input and redacts printed secrets. Terminal |
| Remove text from memory | Find and erase an exact string everywhere. Hippocampus |
| Feature | Detail |
|---|
| Private cluster | Join devices with single-use tickets; no third-party account, no open ports. Cluster & mesh |
| Exit nodes | Route traffic out through any peer. |
| Remote terminal and files | A shell or a file browser on any peer. |
| Remote inference and training | Use a peer’s GPU; the peer decides whether it accepts. |
| Service exposure | Publish a local service privately by token, publicly, or over Tor. Protocols |
| Feature | Detail |
|---|
| Privacy layer | Cookies, fingerprinting, trackers, HTTPS upgrade, DNS over HTTPS. Privacy |
| Per-site and per-pane control | Exceptions without loosening the default. Site panel |
| Lockdown | No scripts, uniform identity, sensors denied. |
| Ghost Mode | An in-memory pane, erased on close. |
| Tor | Built in; per pane or global. |
| Safe Browsing | A local threat database; no lookups leave the device. |
| Ad blocking | In the browser and in the proxy. |
| Passwords and passkeys | Local vault, pass or 1Password. |
| Feature | Detail |
|---|
| Memory | Pages, terminal sessions, file activity and conversations, searchable by meaning. Hippocampus |
| Curation | Boost, suppress, annotate, tag, ignore. |
| Models | Bundled small models, or import any GGUF with a chat template. Machine learning |
| Adapters | Train LoRA adapters on your memories, locally or on a peer. Models & training |
| Tool loop | Browse, read, write and run, with flows and recovery. Projects & tool loop |
| Discovery | Your own activity, summarised on your device. |
The source is available to read and build, so the binary you run can be inspected. Each tool-loop step is recorded, so a run can be reviewed afterwards. See governance & controls.