• About the project Be sure to write what inspired you, what you learned, how you built your project, and the challenges you faced. Format your story in Markdown, with LaTeX support for math.

Inspiration

Modern enterprise software teams face an overwhelming volume of cybersecurity vulnerabilities, configuration drift, and accessibility compliance gaps. Developers are frequently buried under thousands of static analysis warnings, leading to alert fatigue rather than concrete fixes.

Traditional AI solutions remain reactive—they wait passively for human developers to write prompts in isolated chat loops. We asked: What if an autonomous enterprise fleet could continuously inspect code repositories in the background, identify security and architectural vulnerabilities, evaluate them against strict zero-trust guardrails, and generate verifiable, merge-ready pull request diffs without human prompting?

We engineered KAYAN AI Agent as an autonomous, production-grade SecOps and remediation fleet built on Gemini 3.5 Flash, the Google Agent Development Kit (ADK), and Google Cloud (Cloud Run, Firestorm, Vertex AI ADC).


What It Does

KAYAN AI Agent operates as an autonomous enterprise multi-agent fleet structured into specialized functional nodes:

  • Sentinel Agent (SecOps Scanner): Scans codebases for hardcoded credentials, SQL/XSS injection vulnerabilities, and permissive CORS policies, automatically generating bindings to Google Cloud Secret Manager.
  • Auditor Agent: Analyzes component structures, Dockerfile definitions, and architectural configurations to detect privilege escalations and unpinned dependencies.
  • Remediation Agent: Employs the Google Agent Development Kit (ADK) to synthesize zero-hallucination code diffs and patch scripts ready for CI/CD pipelines.
  • Model Armor Gate: Serves as an inline defense policy engine, filtering out prompt injection attacks, indirect context poisoning, and hazardous commands (e.g., rm -rf, DROP DATABASE) before any patch reaches production.
  • Firestore Memory Bank: Persists compliance incident logs and post-mortems across deployment cycles, allowing the fleet to reference historical resolutions and improve future triage accuracy.

How We Built It

The fleet architecture is decoupled across enterprise-tier Google Cloud infrastructure:

  • Reasoning Engine: Powered by Gemini 3.5 Flash on Vertex AI, authenticated via enterprise Application Default Credentials (ADC) in Google Cloud project sincere-venture-499208-q5 (Region: northamerica-northeast1).
  • Agent Framework: Built using the Google Agent Development Kit (ADK) to manage asynchronous inter-agent delegation and state transitions.
  • Serverless Compute: Deployed as a containerized service on Google Cloud Run, configured to scale to zero when idle.
  • Persistent State: Managed via Google Cloud Firestore to preserve cross-session incident context and telemetry.
  • Observability Cockpit: An accessible, WCAG 2.2 AAA-compliant dashboard featuring dual Dark and Light mode tokenization with real-time Server-Sent Events (SSE) streaming of agent reasoning chains.

Mathematical & Safety Verification Models

To guarantee patch safety, the Model Armor Gate evaluates candidate code diffs against a composite safety index:

$$S_{\text{compliance}} = \prod_{i=1}^{n} \mathbb{I}(\text{risk}_i < \tau)$$

Where $\mathbb{I}$ represents an indicator function ensuring that all individual risk parameters remain strictly below the enterprise safety threshold $\tau$.

Furthermore, our interface ensures visual accessibility across theme switches by dynamically enforcing the WCAG AAA luminance contrast formula:

$$\text{Contrast Ratio} = \frac{L_1 + 0.05}{L_2 + 0.05} \ge 7.0$$


Challenges We Faced

  1. Zero-Trust Enterprise IAM & Domain Restrictions: Configuring Cloud Run deployments within a security-hardened Google Workspace domain (twinvault.ca) required navigating domain-restricted sharing policies while maintaining secure invoker access.
  2. Preventing Agent Hallucinations in Code Diffs: Large language models can occasionally invent non-existent import paths or libraries. We enforced rigid structural JSON schemas and ADK tool validations to ensure that all generated diffs are syntactically sound and reproducible.
  3. Low-Latency Streaming Telemetry: Bridging asynchronous multi-agent reasoning steps into a real-time Server-Sent Events (SSE) stream required decoupling long-running background tasks from the immediate HTTP request cycle.

What We Learned

  • Autonomous Background Fleets Outperform Chatbots: Decoupling agents into dedicated roles (Sentinel, Auditor, Remediation) eliminates context dilution and produces far more reliable code modifications than monolithic prompts.
  • Cross-Session Memory is Vital: Integrating Firestore as a persistent memory bank allows agents to remember previously resolved edge cases across deployment pipelines rather than starting from zero on every scan.
  • Guardrails Must Be Inline: Model Armor inline validation is essential for enterprise security, guaranteeing that untrusted repository files cannot trick the agent into executing destructive operations.

Accomplishments We're Proud Of

  • Executed end-to-end repository security triage, vulnerability discovery, and patch synthesis in under 3.5 seconds.
  • Fully connected Google Cloud Vertex AI ADC, Cloud Run serverless deployment, and Firestore Memory Bank into a cohesive enterprise fleet.
  • Designed an accessible, production-ready cockpit with instant Dark/Light mode switching and interactive modal inspectors.

What's Next for KAYAN AI Agent

  • Automated Pull Request Webhooks: Direct integration with GitHub and GitLab webhooks to trigger autonomous scans on every push.
  • Air-Gapped Gemma 2 Engine: Adding local, on-premise execution with open-weights Gemma models for sensitive enterprise repositories operating in zero-internet environments.
  • Automated Cloud Armor Policy Updates: Enabling the fleet to automatically update perimeter firewall rules when new injection attacks are detected.

Built With

  • ai-agent
  • cloud-run
  • cybersecurity
  • devops
  • docker
  • fastapi
  • firestore
  • gemini-3.5-flash
  • gemma-2
  • google-adk
  • javascript
  • model-armor
  • next.js
  • opentelemetry
  • pub/sub
  • python
  • secops
  • tailwind-css
  • typescript
  • vertex-ai
Share this project:

Updates

Submission history