Vannus / Catalog / Kiro

Kiro

Vannus records that this vendor routes across several model providers — not captured by one. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Agentic IDE built by AWS, using an "Auto" agent that mixes frontier and specialized models, with user selection across Sonnet 4.5 and 4.6, Haiku 4.5, and Opus 4.5, 4.6 and 4.7.

coding, AI, agents
What the vendor's own documentation says
You can also choose a specific model, including OpenAI’s GPT-5.6 (Sol, Terra, and Luna), Anthropic’s Claude models
kiro.dev ↗ Vendor-sourcedQuote re-checked 14 Sep 2026
Who controls it
US corporate controlNot established — our catalogue recorded US control for this vendor, but we hold no document naming a US entity, so the claim is withdrawn until we do. This is a gap in our sourcing, not a finding about this vendor.
Trains on your dataYes, unless you opt out — on the vendor's default plan

Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Kiro ↗ Grade your whole stack →