Governed chat

Kavros Chat gives employees productive access to LLM providers through the same governance plane that watches your agents: approved models, DLP on prompts and responses, per-team budgets, and retention you control. Providers are yours (BYOK) — Kavros routes and governs, and your provider keys never leave your deployment.

Providers and routing

DLP on prompts and responses

Every chat message and completion passes the same DLP inspection the egress path uses. Rules are org-configurable; matches are blocked or flagged with the rule name recorded, and hit counts feed each team's risk view. PII patterns, custom regexes, and secret patterns all work the same way as agent-side DLP.

Quotas, budgets, and visibility

Privacy and retention

Chat retention is configurable — keep everything, keep a window, or keep summaries. Privacy lanes control what is stored versus inspected-and-discarded, and the configuration is part of the deployment's governed settings, not a per-user toggle.

Access and identity

Chat respects your identity stack: SSO for login, team and org structure for quotas and visibility, and admin-configurable auto-approval policies for low-risk actions. Employee chat and agent governance share one audit story — the same export, the same hash chain.