Skip to content

KAIDAN: start here

KAIDAN is the Briard-AI security add-on for AI and large language model (LLM) incident response. It helps an authorized response team collect approved metadata, connect related events, investigate what the available evidence supports, and export a custody-verifiable case package.

Open the KAIDAN application at briard-ai.app/Kaidan. KAIDAN is free for every signed-in Briard-AI workspace from August 13, 2026 at 00:00 UTC until August 13, 2027 at 00:00 UTC. Briard-AI records the required organization agreement before enabling the add-on; no paid Briard-AI subscription is required for KAIDAN during this window.

You do not need to be technical to use this guide. Each page tells you:

  • who needs to participate;
  • what you need before you start;
  • what you can do yourself;
  • when to hand a step to a technical operator;
  • what proof to keep; and
  • when to stop instead of guessing.

IMPORTANT

Briard-AI remains your governance and subscription portal. KAIDAN remains the authority for security evidence, cases, connector receipts, findings, and custody verification. Accepting KAIDAN access in Briard-AI does not deploy KAIDAN or connect a source.

Choose your starting point

Your situationStart here
You want to understand the product firstWhat KAIDAN does
You are a Briard-AI owner or administratorAccess and agreement
You are responsible for installing softwareSetup and deployment
You own cloud, security, observability, or AI toolsConnect sources
You are responding to an AI incidentUser guide
Something is not workingTroubleshooting
You need the privacy and evidence rulesSecurity and data boundaries

What KAIDAN does

KAIDAN brings together approved event metadata from sources such as:

  • AI and LLM runtimes;
  • agents and tool calls;
  • guardrails and AI security products;
  • cloud audit services;
  • vector databases;
  • OpenTelemetry and observability platforms; and
  • SIEM and other security systems.

It then helps responders:

  1. place related events on a common timeline;
  2. see where each statement came from;
  3. separate observed facts from source claims, detector inferences, and human conclusions;
  4. record missing evidence and contradictions;
  5. collaborate in a tenant-scoped case; and
  6. export a package whose custody and integrity can be checked.

What KAIDAN does not do

KAIDAN does not:

  • silently block or control an AI system;
  • decide whether an incident legally occurred;
  • prove intent or causation when the evidence does not;
  • turn an alert into a confirmed fact;
  • make missing provider receipts appear present;
  • replace counsel, an incident-response professional, an assessor, or an executive decision maker; or
  • require raw prompts, model responses, files, credentials, secrets, or regulated content through normal intake.

Content-bearing restricted forensic capture is a separate mode. It is disabled by default and must not be enabled through the normal setup path.

The complete customer journey

Phase 1: authorize

A signed-in Briard-AI workspace opens KAIDAN in the sidebar during the fixed free launch-year window. An owner or administrator reads the agreement, checks the authorization box, and accepts. Briard records the agreement version and hash, user, role, workspace, method, request identifier, and timestamp. The free window does not convert automatically into a paid plan.

Phase 2: plan

Assign business, security, platform, identity, and data owners. Decide where KAIDAN will run, which sources are allowed, and which areas are excluded.

Phase 3: deploy

A technical operator uses the signed KAIDAN setup bundle to render a customer-specific plan. The plan must pass preflight and receive five separate approvals before it can be applied.

Phase 4: connect

Each source owner creates a least-privilege credential or workload identity, stores it in the approved secret manager, tests the source, and records the receipt. A source is not “connected” merely because a form was filled out.

Phase 5: validate

Run a fictional metadata-only incident. Confirm events arrive, evidence remains tenant-scoped, unknowns stay visible, and both an online and offline package pass the trusted verifier.

Phase 6: operate

Open cases, investigate, record conclusions, export evidence, monitor source health, rotate credentials, rehearse rollback, and review access on a schedule.

People you may need

One person can hold several roles in a small organization, but the approval record must still show who made each decision.

RolePlain-language responsibility
Workspace owner or administratorAccepts the KAIDAN add-on agreement in Briard-AI
Security ownerOwns incident-response policy and case decisions
Platform operatorDeploys, upgrades, validates, and rolls back KAIDAN
Identity ownerConfigures sign-in, roles, MFA, and service identities
Source ownerApproves and tests each connected data source
Data/privacy ownerApproves metadata fields, retention, region, and exclusions
Reviewer or auditorReads reports and verifies packages without changing setup

Safe first exercise

Do not begin with a real incident. Use fictional names and metadata:

  • incident: “Fictional assistant tool-call anomaly”;
  • system: “Sample Support Assistant”;
  • user: a pseudonymous identifier;
  • source: a test connector or approved synthetic package;
  • content: no real prompt, response, customer file, credential, or regulated data.

The exercise is complete only when you can trace an event to its source, identify at least one known gap, record a human conclusion, export the case, and verify the export independently.

Get help

For product and onboarding help, contact support@briard-ai.app. For a suspected security issue involving Briard-AI or KAIDAN, contact security@briard-ai.app.

Never email credentials, tokens, raw prompts, model responses, customer files, or incident evidence.

Governance documentation and review support. Not legal advice or certification.