Kavach (कवच, "armor") is a containment layer for customer-facing AI agents. The model is not the security boundary. Our demo: a refund agent reads a support ticket with a hidden prompt injection telling it to POST the customer's card number to an attacker. Uncontained, it leaks the card and the API key. Inside Kavach, it never sees them.
How it works: the agent runs in a sandbox whose only route out is a Kavach gateway (mitmproxy + our add-on). The gateway tokenizes card numbers before the agent sees them and swaps the token back to the real card only on the call to the payment processor. Stand-in API keys are swapped for the real key only on the matching provider's host. A kernel eBPF guard kills any process that tries a raw socket around the gateway. Every request is recorded in a wire log showing what the agent sent versus what left the sandbox, with cards and keys masked.
NVIDIA OpenShell as a second sandbox backend (kavach openshell compile turns the same policy into an OpenShell policy, and OpenShell's own audit events join the wire log), and Kyverno-inspired policy features: audit vs. enforce mode, expiring exceptions, PolicyReport export and CI lint. Verified live on OpenShell 0.1.3, with Qwen3-30B running through the same path.
Evidence: kavach eval replays 10 attacks (10/10 clean, refunds still succeed), 40 unit tests, and a 17-check end-to-end suite on a homelab VM.