Skip to content

KAIDAN: start here ​

KAIDAN is the Briard-AI security add-on for AI and large language model (LLM) incident detection and response. It turns approved metadata into explainable real-time alerts, helps responders connect related activity, and carries the work into an evidence-cited investigation and custody-verifiable case package.

KAIDAN and Briard-AI are products of Unfettered Minds LLC.

Watch a video demo of KAIDAN — an 11-minute, 47-second narrated walkthrough of alerts in Briard, governed case-access choices, evidence review, and the return to policy review. Includes captions, chapters, and a transcript. No sign-in needed.

Open the KAIDAN application at briard-ai.app/Kaidan. KAIDAN is free for every signed-in Briard-AI workspace from August 13, 2026 at 00:00 UTC until August 13, 2027 at 00:00 UTC. Briard-AI records the required organization agreement before enabling the add-on; no paid Briard-AI subscription is required for KAIDAN during this window.

KAIDAN does not automatically convert to a paid plan. For organizations that separately elect to continue after the free window, the KAIDAN platform fee will not exceed $399 USD per organization per month through August 12, 2028. Customer-selected infrastructure, source products, taxes, custom deployment work, and optional professional services are separate.

You do not need to be technical to use this guide. Each page tells you:

  • who needs to participate;
  • what you need before you start;
  • what you can do yourself;
  • when to hand a step to a technical operator;
  • what proof to keep; and
  • when to stop instead of guessing.

IMPORTANT

Briard-AI remains your governance and subscription portal. KAIDAN remains the authority for alerts, situations, security evidence, cases, connector receipts, findings, and custody verification. Accepting KAIDAN access in Briard-AI does not deploy KAIDAN or connect a source.

IMPORTANT

KAIDAN retains platform evidence records and immutable evidence-package objects for 365 days by default. Active legal holds may delay disposition, and customer-controlled external copies follow their own retention controls. Review the full access and agreement notice before enabling KAIDAN.

Choose your starting point ​

Your situationStart here
You want to understand the product firstWhat KAIDAN does
You want to see the workflow in actionWatch the KAIDAN video demo
You are a Briard-AI owner or administratorAccess and agreement
You are responsible for installing softwareSetup and deployment
You own cloud, security, observability, or AI toolsConnect sources
You need to understand or work the alert queueAlerts and real-time response
You need a closer case investigationChoose what KAIDAN can access
You are responding to an AI incidentUser guide
You need continuity, support, or exit detailsContinuity and customer exit
Something is not workingTroubleshooting
You need the privacy and evidence rulesSecurity and data boundaries

What KAIDAN does ​

KAIDAN brings together approved event metadata from sources such as:

  • AI and LLM runtimes;
  • agents and tool calls;
  • guardrails and AI security products;
  • cloud audit services;
  • vector databases;
  • OpenTelemetry and observability platforms; and
  • SIEM and other security systems.

It then helps responders:

  1. categorize and prioritize meaningful activity as P1–P4 alerts;
  2. understand the score, confidence, source, and visibility boundary;
  3. connect related alerts into a situation and common timeline;
  4. separate observed facts from source claims, detector inferences, and human conclusions;
  5. acknowledge, assign, hand off, investigate, suppress, or resolve with a reason;
  6. promote warranted work into a tenant-scoped case; and
  7. export a package whose custody and integrity can be checked.

What KAIDAN does not do ​

KAIDAN does not:

  • silently block or control an AI system;
  • decide whether an incident legally occurred;
  • prove intent or causation when the evidence does not;
  • turn an alert into a confirmed fact;
  • make missing provider receipts appear present;
  • replace counsel, an incident-response professional, an assessor, or an executive decision maker; or
  • require raw prompts, model responses, files, credentials, secrets, or regulated content through normal intake.

Case-specific content access is separate from metadata-only normal intake, disabled by default, and must not be enabled through the normal setup path. See the two governed choices before requesting a closer investigation.

The complete customer journey ​

Phase 1: authorize ​

A signed-in Briard-AI workspace opens KAIDAN in the sidebar during the fixed free launch-year window. An owner or administrator reads the agreement, checks the authorization box, and accepts. Briard records the agreement version and hash, user, role, workspace, method, request identifier, and timestamp. The free window does not convert automatically into a paid plan.

Phase 2: plan ​

Assign business, security, platform, identity, and data owners. Decide where KAIDAN will run, which sources are allowed, and which areas are excluded.

Phase 3: deploy ​

A technical operator uses the signed KAIDAN setup bundle to render a customer-specific plan. The plan must pass preflight and receive five separate approvals before it can be applied.

Phase 4: connect ​

Each source owner creates a least-privilege credential or workload identity, stores it in the approved secret manager, tests the source, and records the receipt. A source is not “connected” merely because a form was filled out.

Phase 5: validate ​

Run fictional metadata-only observations across all four alert categories. Confirm P1–P4 counts, alert deep links, live updates, evidence scope, tenant isolation, response handoffs, and both an online and offline package through the trusted verifier.

Phase 6: operate ​

Triage alerts, monitor situations, open cases, record response handoffs and conclusions, export evidence, monitor source health, rotate credentials, rehearse rollback, and review access on a schedule.

People you may need ​

One person can hold several roles in a small organization, but the approval record must still show who made each decision.

RolePlain-language responsibility
Workspace owner or administratorAccepts the KAIDAN add-on agreement in Briard-AI
Security ownerOwns incident-response policy and case decisions
Platform operatorDeploys, upgrades, validates, and rolls back KAIDAN
Identity ownerConfigures sign-in, roles, MFA, and service identities
Source ownerApproves and tests each connected data source
Data/privacy ownerApproves metadata fields, retention, region, and exclusions
Reviewer or auditorReads reports and verifies packages without changing setup

Safe first exercise ​

Do not begin with a real incident. Use fictional names and metadata:

  • alert: “Fictional assistant tool-call anomaly”;
  • system: “Sample Support Assistant”;
  • user: a pseudonymous identifier;
  • source: a test connector or approved synthetic package;
  • content: no real prompt, response, customer file, credential, or regulated data.

The exercise is complete only when you can generate and acknowledge an alert, explain its priority and category, trace an event to its source, identify at least one known gap, promote warranted work to a case, record a human conclusion, export the case, and verify the export independently.

Get help ​

For product and onboarding help, contact support@briard-ai.app. For a suspected security issue involving Briard-AI or KAIDAN, contact security@briard-ai.app.

Never email credentials, tokens, raw prompts, model responses, customer files, or incident evidence.

Briard-AI and KAIDAN are products of Unfettered Minds LLC. Governance documentation and review support. Not legal advice or certification.