THE KANGL PLATFORM

The operating layer for enterprise AppSec.

Unify provider operations, Azure DevOps build-pipeline controls, normalized posture, policy, and audit without replacing the security tools you trust.

THE COMMAND CENTER

Control the full security operating model.

Move from scattered vendor portals and project-by-project settings to a consistent view across the estate.

Kangl platform command center

CORE CAPABILITIES

One platform. Clear operating boundaries.

Security Providers

Connect and manage security platforms through a single provider-neutral control plane.

Repository Posture

Normalize security findings into fast, consistent repository-level posture.

Managed Pipelines

Enable, synchronize, and enforce controls across Azure DevOps build pipelines.

Policies & Audit

Apply backend-authoritative policy and retain durable operational history.

Projects

Map provider organizations and maintain project provisioning state.

Operations

Coordinate validation, synchronization, repair, and bulk control.

Audit

Retain durable history for provider, credential, pipeline, and policy changes.

Multi-Tenant Control

Preserve tenant configuration and provider isolation under centralized ownership.

OPERATING GUARANTEES

Designed for the failure modes real estates have.

These are behaviors of the platform, not aspirations: how Kangl acts when providers lag, targets vanish, runs collide, or two workspaces meet one Azure DevOps organization.

Canonical identity

Enrollment establishes the exact provider organization and repository target — and every later assessment, refresh, and repair follows that identity. Name matching survives only for repositories that were never bound, and every such fallback is logged.

Self-healing enrollment

A vanished provider target on a healthy connection re-enters the enrollment lifecycle automatically. Historical successes never suppress a fresh reconciliation, and concurrent observers converge on exactly one repair — never duplicate imports, never phantom runs.

Bounded, truthful convergence

Initial assessments defer with backoff inside a bounded window while the provider indexes. An exhausted window pauses as retryable instead of failing the repository; a retry restarts a fresh window. Progress is monotonic — a late exception never un-completes finished stages.

Attention without noise

Attention items are deduplicated by canonical condition and always carry the exact remediation — repair the connection, restore the organization, choose a mapping. System-retryable states pause and retry; they never masquerade as customer actions.

One controller per Azure organization

Azure configuration writes require an explicit control claim, and exactly one workspace holds it per organization. Every other workspace runs observe-only, live Azure mutations fence release, and migration readiness makes workspace cutover an explicit, auditable step.

Stable completion

A finished setup is a durable result, not a transient screen: reloads and polls return the same completed state with the same run identity. Only an explicit “Modify setup” opens a new editing pass — a passive read never resets your progress.

ENTERPRISE ARCHITECTURE

One platform. Every security estate.

Operate multiple customers or business tenants, multiple Azure DevOps organizations, and isolated provider configurations through one normalized control model.

  • Tenant-specific configuration
  • Provider isolation
  • Centralized owner control
  • Normalized security posture
Kangl multi-tenant architecture

SECURITY OPERATIONS, UNIFIED

Bring your security tools.
Kangl makes them one platform.

Start with seven days of full plan access — or see it live with our team first.