Vannus / Catalog / Kiro

Kiro B- Durable

Graded B- on resilience. In Vannus's assessment it has not disclosed which model it runs — resilient — owns model IP or routes across providers.

Agentic IDE built by AWS, using an "Auto" agent that mixes frontier and specialized models, with user selection across Sonnet 4.5 and 4.6, Haiku 4.5, and Opus 4.5, 4.6 and 4.7. Team plans add SAML/SCIM SSO via AWS IAM Identity Center, an organizational management dashboard, consolidated billing and usage analytics. Integrates with AWS IAM Identity Center, AWS Builder ID and Amazon Q Developer.

coding, AI, agents
Model provenance

Not disclosed. Kiro does not publish which model it runs, so this criterion is excluded and the grade rests on what we could verify. We say so rather than guess.

Who controls it
Verified Domestic Infrastructure
OriginUSA
Data jurisdictionUS
Within U.S. CLOUD Act reachYes
Trains on your dataYes, unless you opt out

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This measures who can compel your data. A tool can score modestly on one and strongly on the other, and many do.

Signals on file
Origin
United States
US legal control
Yes — exposed to US CLOUD Act / CFIUS
Training on your data
Trains on your data unless you opt out

The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.

How this grade is set

Vannus grades Kiro against nine dimensions of trust — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Kiro ↗ Grade your whole stack →