Skip to content

Features

Speed without understanding is a risk. Kaba is built so that you can see where data goes, what automation can touch, and which models learn from it. This page lists what the product does today and links to the detail. For the reasoning behind these choices, see Why Kaba?.

Every model call and tool step goes through a policy. In Kaba Personal the policy is yours; under fleet management it is pushed and enforced centrally. See what fleet control changes.

FeatureDetail
PoliciesOne object decides where inference runs, which model and adapter answer, and what may execute. Machine learning
Deny winsA policy’s tool ceiling cannot be re-enabled from below. Security
Locked policiesPrevent overriding policy settings is enforced on every request.
A fixed tool catalogTools are first-party code; data cannot add one. Projects & tool loop
Portable policy bundlesExport and import as .kabap. File formats
FeatureDetail
Container sandboxFile, code and build work runs in a container with a read-only root and no network by default. Security
gVisor firstOn Linux the sandbox prefers runsc when it is installed.
Network is a policy decisionOff, on request, or always.
Command approvalAsk, auto-run for read-only commands, or off.
FeatureDetail
Per-account encryptionMemories, learning data, saved logins and passkeys. Security
Secret-aware recordingTerminal memory never stores typed input and redacts printed secrets. Terminal
Remove text from memoryFind and erase an exact string everywhere. Hippocampus
FeatureDetail
Private clusterJoin devices with single-use tickets; no third-party account, no open ports. Cluster & mesh
Exit nodesRoute traffic out through any peer.
Remote terminal and filesA shell or a file browser on any peer.
Remote inference and trainingUse a peer’s GPU; the peer decides whether it accepts.
Service exposurePublish a local service privately by token, publicly, or over Tor. Protocols
FeatureDetail
Privacy layerCookies, fingerprinting, trackers, HTTPS upgrade, DNS over HTTPS. Privacy
Per-site and per-pane controlExceptions without loosening the default. Site panel
LockdownNo scripts, uniform identity, sensors denied.
Ghost ModeAn in-memory pane, erased on close.
TorBuilt in; per pane or global.
Safe BrowsingA local threat database; no lookups leave the device.
Ad blockingIn the browser and in the proxy.
Passwords and passkeysLocal vault, pass or 1Password.
FeatureDetail
Frames and tiling panesUI layout, tiling windows
Omnibar with slash commandsOmnibar
TerminalLocal, peer or container; shell integration; session restore. Terminal
File explorerLocal or peer; previews; trash; sync. File explorer
Desktop widgetsDesktop
Memory SaverFrees memory from idle panes. Settings
Rebindable shortcuts, i3 modeKeyboard shortcuts
FeatureDetail
MemoryPages, terminal sessions, file activity and conversations, searchable by meaning. Hippocampus
CurationBoost, suppress, annotate, tag, ignore.
ModelsBundled small models, or import any GGUF with a chat template. Machine learning
AdaptersTrain LoRA adapters on your memories, locally or on a peer. Models & training
Tool loopBrowse, read, write and run, with flows and recovery. Projects & tool loop
DiscoveryYour own activity, summarised on your device.
FeatureDetail
DesktopLinux as a first-class citizen, with macOS and Windows support. Platform support
HeadlessThe same engine as a service. Local
Containers and KubernetesDocker, Kubernetes
Isolated deploymentkaba-enclave
No cloud dependencyWhen data leaves your device

The source is available to read and build, so the binary you run can be inspected. Each tool-loop step is recorded, so a run can be reviewed afterwards. See governance & controls.