Logo by Bullitt
Sycophant deploys AI agents on Kubernetes. Each workspace pod runs a transponder (message router) and workspace-tools (local MCP server) with no network egress and no mounted secrets. A shared tightbeam controller proxies LLM calls via ephemeral Jobs. A shared airlock controller executes tools in isolated chambers with scoped credentials and network egress. Secrets are projected only into ephemeral Jobs — the long-lived pods never mount them.
