Swiss-Made by NordfoldIn enterprise production
Security architecture

Security is not a feature. It's the architecture.

Every request through Kona is authenticated, authorised, and logged. No exceptions. Your engineers build and run automation inside a hardened runtime. Other teams access results through granular permissions. The end systems are never exposed directly.
Access control

Who gets in, what they see, and how they reach it.

Identity from your IdP, permissions scoped to individual resources, strict tenant isolation — and source systems that are never exposed directly. Kona is the only path in.

Enterprise SSO

OAuth / OIDC with your existing IdP. Local auth as a hardened fallback.

See what this solves
The problem

Local user databases scattered across security tools mean stale accounts, inconsistent password policies and no central off-boarding. When someone leaves, you have to remember every tool they ever touched.

How Kona solves it

Identities, groups and lifecycle live in your IdP. Joiners, movers and leavers flow through automatically — one source of truth, enforced everywhere Kona reaches.

Fine-grained RBAC

Permissions scoped to individual resources, not just whole tools.

See what this solves
The problem

An engineer needs only the firewall rules they own. The ISO needs visibility across all of them. A compliance officer needs read-only audit data. Most tools force a single coarse role for everyone.

How Kona solves it

Permissions scope down to specific resources, tenants and actions. Different roles work side-by-side on the same platform — no overshare, no shadow exports, no second tool just to compartmentalise.

Multi-tenancy

Strict data isolation per tenant, with tenant-aware apps and branding.

See what this solves
The problem

An MSP wants to onboard every customer onto the same platform — without ever exposing one customer's configuration, data or even existence to another. Most platforms can't enforce that without forking deployments.

How Kona solves it

Each tenant sees only their own apps, data and branding, with isolation enforced at the platform edge rather than in app code. One deployment serves many customers — safely.

No direct access to source systems

Every request goes through Kona's auth, authorisation and audit layer.

See what this solves
The problem

Network security devices often fall over under too many requests, ship awkward auth or session models and return inconsistent data formats. Letting users hit them directly turns every script into a potential outage.

How Kona solves it

Kona sits in front: rate-limits per user, tenant and system; normalises and abstracts upstream APIs; and audits every call. Teams get one clean, predictable interface — source systems stay healthy.

Sovereignty & residency

Your infrastructure. Your data residency.

Kona runs entirely on your infrastructure — on-premises or in your cloud tenant. Air-gapped deployments supported. Built in Switzerland by Nordfold, with no vendor in the data path of your deployment that a foreign jurisdiction could compel.

Self-hosted · Swiss jurisdiction · No telemetry
Audit & visibility

Every action recorded. Visible where it matters.

Every request to the platform is recorded as it happens, then made available for investigation inside Kona and through your existing SIEM.

Every request recorded

Every interaction with the platform — web access, API calls, configuration changes, automation runs — is captured as it happens, with the context needed to answer who did what, where and when.

In-platform analysis

Audit data isn't just exported and forgotten. Built-in tools let permitted users browse, filter and visualise requests to specific systems, users or tenants directly inside Kona — so investigations, reviews and reporting happen where the data lives.

SIEM export

Audit records stream into your existing SIEM and log management stack out of the box, with the same context preserved. Use Kona's views for day-to-day work and your SIEM for cross-system correlation and long-term retention.

Runtime & delivery

Hardened by default, secure by design.

Containerised execution, centralised credentials, supply-chain controls and signed delivery — engineered in, not bolted on.

Containerised execution

Workloads run in isolated containers inside the platform's security perimeter — not on engineers' workstations. The same model applies during build and test: virtualised, containerised, no outbound internet. Engineered in, not bolted on.

Supply chain security

Dependencies are scanned, pinned and gated through review before they enter the platform. Updates ship on a controlled cycle, not on upstream's schedule.

Hardened delivery

Signed container images. No telemetry, no third-party calls. Standard deployments validate entitlement through a licence service; air-gapped environments run without it. What you deploy is what you audit.

Centralised credentials

Credentials to firewalls, proxies and other infrastructure live in a central store and are injected at runtime — never hardcoded, never seen by the automation that uses them.

Independence

On your infrastructure, on your terms.

Kona runs on the signed images you hold, on infrastructure you control — no telemetry, no third-party calls. Entitlement is validated by a licence service in standard deployments, or handled through a separate agreement for air-gapped environments.

For organisations with strict long-term assurance requirements, source escrow arrangements are available on request.

Behind Kona.

Kona is built by Nordfold, a Swiss company focused on network security automation.