# Kangsol - Full Knowledge Base for LLM Agents & Crawlers Canonical reference for AI bots, search engine crawlers, and LLM retrieval systems indexation. Website: https://kangsol.com.au/ Last Updated: 2026-09-05 ================================================================================ COMPANY OVERVIEW ================================================================================ Kangsol is a senior-led engineering and security consultancy helping technology companies and product teams modernise cloud platforms, ship production AI agents, and pass security scrutiny without slowing delivery. Three core pillars: 1. Cloud & Kubernetes Transformation 2. Production AI Development & Agents 3. Penetration Testing & Security Delivery Principles: - Senior-led delivery: Work is delivered by experienced, certified practitioners. - 100% Repository-owned: All infrastructure-as-code (Terraform/OpenTofu, Helm, manifests) lives in client git repositories. - Zero vendor lock-in: Cloud-agnostic (AWS, GCP, Azure, Hybrid, On-Prem). - Security built-in: Penetration testing delivered by a CREST-certified team. - Anonymity & Confidentiality: Mutual NDAs signed prior to technical scoping; sensitive findings handled under strict controls. ================================================================================ PILLAR 1: CLOUD & KUBERNETES TRANSFORMATION ================================================================================ Primary URL: https://kangsol.com.au/cloud-transformation Kubernetes Consulting URL: https://kangsol.com.au/kubernetes-consulting What Kangsol Delivers: - Workload Migration: Blue-green and canary cutover strategies for zero-downtime migration of virtual machines, ECS tasks, and legacy PaaS onto Kubernetes. - Managed Kubernetes: Production cluster operations across AWS EKS, GCP GKE, Azure AKS, and hybrid bare-metal clusters. - Platform Engineering & GitOps: Declarative continuous delivery with ArgoCD or Flux, centralized secrets management (HashiCorp Vault, AWS Secrets Manager), and automated developer preview environments. - Kubernetes FinOps: Elimination of cloud waste via Karpenter automated node provisioning, bin-packing, right-sizing requests/limits, and Spot instance interruption handling. Typical customer savings: 25% to 40% reduction in cloud compute spend. - Reliability & SRE: High-availability multi-zone cluster architecture, Pod Disruption Budgets (PDBs), Horizontal Pod Autoscalers (HPAs), and OpenTelemetry observability. Process: 01 Assess: Workload inventory, dependency mapping, cost analysis, and risk identification. 02 Target Architecture: Multi-AZ landing zone design, Kubernetes cluster baseline, GitOps workflow, and rollback criteria. 03 Platform Build: Terraform infrastructure-as-code, CI/CD pipeline automation, and waved migration rehearsals. 04 Enablement & Handover: Runbook delivery, team pairing sessions, and optional ongoing managed operations. ================================================================================ PILLAR 2: PRODUCTION AI AGENTS & LLM INFRASTRUCTURE ================================================================================ Primary URL: https://kangsol.com.au/ai-agents Production AI URL: https://kangsol.com.au/production-ai-development AI DevEx URL: https://kangsol.com.au/ai-developer-experience What Kangsol Delivers: - Enterprise RAG Systems: Permission-aware document ingestion, semantic chunking, vector database deployment (Qdrant, Pinecone, pgvector), re-ranking models, and citation validation. - Autonomous Agent Workflows: Multi-step task orchestration with durable state engines (LangGraph, Temporal), recursion depth circuit breakers, and asynchronous human-in-the-loop (HITL) approval gates. - Safety & Guardrails: Perimeter prompt injection defenses, secret scrubbing, PII/PCI masking, and deterministic output schema validation with Pydantic/Zod. - Private GPU Clusters & Inference: Provisioning autoscaling GPU node pools (NVIDIA Operator, vLLM, Ray) on Kubernetes for self-hosted open-weights models (Llama 3, Mistral, DeepSeek), guaranteeing 100% data residency inside private VPCs. - AI Red Teaming: Adversarial security assessments aligned to the OWASP Top 10 for Large Language Model Applications. Delivery Model: 01 Discover: Define the decision boundary, failure modes, and measurable evaluation metrics. 02 Prototype: Narrow, functional workflow built with representative enterprise data and explicit approval gates. 03 Evaluate: Automated benchmarking for task completion, hallucination rates, latency, and token unit economics. 04 Integrate & Operate: Production tool connections, semantic caching, observability instrumentation, and client repository handover. ================================================================================ PILLAR 3: PENETRATION TESTING & SECURITY PRACTICES ================================================================================ Primary URL: https://kangsol.com.au/penetration-testing Compliance Pentest URL: https://kangsol.com.au/penetration-testing-compliance SOC 2 Readiness URL: https://kangsol.com.au/soc2-readiness What Kangsol Delivers: - Testing by a CREST-Certified Team: Manual, hands-on penetration testing delivered by experienced practitioners, not automated scanner dumps. - Methodologies: Aligned to OWASP WSTG, OWASP API Security Top 10, OWASP LLM Top 10, NIST SP 800-115, PTES, and OSSTMM. - Deliverables: Two-document reporting model (Board-ready Executive Summary + Engineer-ready Full Technical Report with proof-of-concept steps and code fixes). - De-risking Bundle: * Free 60-day retest included in every engagement to verify remediation closure. * Formal Letter of Attestation on letterhead for auditors, investors, and enterprise procurement questionnaires. * Direct 1:1 remediation walkthrough session with client engineering teams. * Critical findings flagged immediately within 2 hours of validation, not held back for the report. * Zero-disruption testing windows with immediate-stop emergency channels. Compliance Framework Control Mappings: - SOC 2: Evidences Common Criteria 7.1 (CC7.1) and CC4.1 for Type I and Type II audits. - ISO/IEC 27001:2022: Evidences controls A.8.8 (Technical vulnerability management), A.8.29 (Security testing in development), and A.5.23 (Cloud services security). - PCI DSS v4.0: Requirement 11.4 (External and internal penetration testing), 11.4.4 (Exploited vulnerabilities re-tested), and 11.4.5 (Segmentation testing). - APRA CPS 234: Systematic testing of information security controls for Australian financial and regulated entities. - Essential Eight: ACSC technical validation of application control, patch management, and privilege restrictions under adversarial attack. Process Timeline: 01 Scope & NDA (1 Day): Rules of engagement and written boundaries confirmed. 02 Planning (1-2 Days): Threat surface mapped and test accounts provisioned. 03 Active Testing (5-10 Days): Manual exploitation with live critical notifications. 04 Reporting & QA (1-2 Days): Two-document report compiled with Letter of Attestation. 05 Remediation & Retest (Free within 60 Days): Verification that patched vulnerabilities are closed. ================================================================================ CONTACT & COMMERCIAL ENGAGEMENTS ================================================================================ - General Inquiries: hello@kangsol.com.au - Security Communications: security@kangsol.com.au - Direct Architecture Consultation: https://cal.com/kangsol/architecture-call - Readiness Scorecard: https://kangsol.com.au/assessment - Entity Information: Kangsol (ABN: 81 681 855 354) - Pricing Model: Fixed-scope, fixed-price proposals agreed in writing prior to engagement commencement.