
Constitutional Core
Five inviolable axioms, SHA-256 sealed at boot. All-or-nothing: if one fails, the task is rejected — no override, no profile, no exception.
Kovrin sits between your AI agents and the real world — enforcing constitutional limits, routing risk deterministically, pausing for human approval, and recording every decision in a tamper-evident audit trail. It wraps LangGraph, CrewAI, or any agent stack.
Drops into LangGraph · CrewAI · your own agents
Kovrin is not a chatbot framework, and not an all-in-one runtime. It's safety infrastructure — like a seatbelt, not the car. Your agents keep their autonomy; Kovrin makes sure they can't cross a line they shouldn't.
No side doors. Every request — from a human or an agent — is parsed, judged by independent critics, checked against the constitution, routed by risk, executed, and sealed into the audit chain.

Five inviolable axioms, SHA-256 sealed at boot. All-or-nothing: if one fails, the task is rejected — no override, no profile, no exception.

Every action is scored and routed by a fixed matrix. CRITICAL risk always routes to a human — hardcoded, not configurable.

An append-only Merkle hash chain. Every decision traces back to the original intent — and any tampering is detectable.

Eight TLA+ specifications, ten invariants. The safety properties are mathematically proven, not just tested.

Plans decompose into a DAG and run in parallel — always inside the safety envelope, never around it.

Irreversible or high-risk actions pause for explicit approval. Autonomy is opt-in per capability — never assumed.
Designed for the regulated world.
Aligned with EU AI Act · Articles 9 · 12 · 14 · 15
Tell us about your agent stack and what you need to keep under control. We'll show you how Kovrin plugs in.
hello@kovrin.dev